Pangolin is a self-hosted reverse proxy management server that combines Traefik, WireGuard tunnels, and built-in authentication into a single solution for home lab remote access. Unlike traditional setups with Nginx or standalone WireGuard, Pangolin requires no open ports — making it ideal for users behind CGNAT or restrictive ISPs. It deploys via Docker Compose, automates SSL with Let's Encrypt, supports SSO with RBAC and 2FA, and provides a web dashboard to manage all self-hosted services under a custom domain. The author switched from Nginx and WireGuard to Pangolin for its simplicity, security, and zero-trust architecture.

5m read timeFrom xda-developers.com
Post cover image
Table of contents
What is Pangolin? Why would you use it?Why is Pangolin better than the alternatives?Why I stopped using Nginx and WireGuard

Sort: