fosrl/pangolin
Modern networking and security platform providing secure access and connectivity to apps, infrastructure, and AI workloads. Connect and protect your users.
What it solves
Pangolin is an open-source SASE (Secure Access Service Edge) platform that unifies networking and security. It replaces legacy, heavyweight VPNs and closed cloud stacks by providing a self-hostable, zero-trust system for connecting users to private resources and AI models without exposing the entire network to the internet.
How it works
Built on WireGuard, Pangolin uses a lightweight user-space connector to create outbound tunnels and employ intelligent NAT traversal to punch through firewalls without requiring public IPs or open ports. It integrates identity providers for Role-Based Access Control (RBAC), ensuring access is granted per resource rather than per network. It also provides a browser-based reverse proxy for HTTPS, VNC, RDP, and SSH access, and a dedicated client for private resource access.
Who it’s for
It is designed for administrators and organizations that need a secure, auditable, and self-hostable alternative to platforms like Cloudflare One or Zscaler, as well as teams managing access to both cloud-based and self-hosted AI model servers.
Highlights
- Identity-Aware AI Gateway: A single URL for cloud models (OpenAI, Anthropic) and self-hosted servers (vLLM, Ollama) with budget controls, session history, and keyless access via the desktop client.
- Zero-Trust Access: Granular, resource-level access control instead of full network exposure.
- Browser-Based Access: In-browser SSH, VNC, and RDP terminals without requiring a client installation.
- NAT Traversal: Connects remote networks behind restrictive firewalls without needing public IPs.
- Unified Policy Model: One identity and policy system shared across the VPN, reverse proxy, and AI gateway.
Related
- Project
- Project
- Project
- Project