fosrl/pangolin

Modern networking and security platform providing secure access and connectivity to apps, infrastructure, and AI workloads. Connect and protect your users.

What it solves

Pangolin is an open-source SASE (Secure Access Service Edge) platform that unifies networking and security. It replaces legacy, heavyweight VPNs and closed cloud stacks by providing a self-hostable, zero-trust system for connecting users to private resources and AI models without exposing the entire network to the internet.

How it works

Built on WireGuard, Pangolin uses a lightweight user-space connector to create outbound tunnels and employ intelligent NAT traversal to punch through firewalls without requiring public IPs or open ports. It integrates identity providers for Role-Based Access Control (RBAC), ensuring access is granted per resource rather than per network. It also provides a browser-based reverse proxy for HTTPS, VNC, RDP, and SSH access, and a dedicated client for private resource access.

Who it’s for

It is designed for administrators and organizations that need a secure, auditable, and self-hostable alternative to platforms like Cloudflare One or Zscaler, as well as teams managing access to both cloud-based and self-hosted AI model servers.

Highlights

  • Identity-Aware AI Gateway: A single URL for cloud models (OpenAI, Anthropic) and self-hosted servers (vLLM, Ollama) with budget controls, session history, and keyless access via the desktop client.
  • Zero-Trust Access: Granular, resource-level access control instead of full network exposure.
  • Browser-Based Access: In-browser SSH, VNC, and RDP terminals without requiring a client installation.
  • NAT Traversal: Connects remote networks behind restrictive firewalls without needing public IPs.
  • Unified Policy Model: One identity and policy system shared across the VPN, reverse proxy, and AI gateway.

Related

  • Project
  • Project
  • Project
  • Project