Pangolin is an open-source, self-hosted tunneled reverse proxy server that brings identity-aware access control and dashboard management to exposing private services securely. It allows you to connect applications and resources behind firewalls or NATs to a central hub, using encrypted tunnels rather than opening public ports or relying entirely on VPNs. With Pangolin you can route traffic from across distributed networks, enforce contextual access rules (such as SSO, geolocation, time of day, IP restrictions), and manage all of your exposed resources in one dashboard. It supports multi-site deployments and highly-available node architectures, enabling you to own your infrastructure yet still get orchestration and control benefits. Pangolin works well for individuals, teams or organizations that need to expose internal web apps, APIs, or services, while maintaining strong authentication, auditing and governance.
Features
- Identity and context-aware access controls (OIDC/SSO, geolocation, IP rules)
- Encrypted tunnels to expose private resources across firewalls without open ports
- Unified dashboard for monitoring and managing all exposed services
- Multi-site, highly available deployment architecture for redundancy and scalability
- Self-hosted foundation with option for enterprise licensing for advanced use
- Support for routing, load balancing, health checks and resource target management