Self-host Pangolin
A self-hosted tunneled reverse proxy that exposes services on your private network to the internet over WireGuard, with built-in identity, access control, and automatic SSL — and, in recent releases, client-based private access to resources as well. A self-hostable alternative to Cloudflare Tunnel that keeps the ingress on a server you own.
Key facts
Pick Pangolin when the job is publishing services from a network you cannot open ports on: a site connector dials out over WireGuard to your VPS, and Pangolin fronts the traffic with Traefik, automatic certificates, SSO, RBAC, PIN and email-OTP gates, browser-based VNC/RDP/SSH and an identity-aware AI gateway — a self-hosted Cloudflare Tunnel. The Community Edition is AGPL-3.0; the Enterprise image is under the Fossorial Commercial License, free below $100K annual revenue but keyed. Upstream's sizing is 1 vCPU and 2 GB of RAM for most deployments, so treat our 1 GB floor as the swap-assisted minimum.
Follow the Pangolin deploy guide →What you need
- Any VPS with at least 1024 MB of RAM
- A domain you control — most self-hosted setups need HTTPS in front of them
- About an afternoon — budget time for troubleshooting
Paid link — we earn a commission if you shop through it.
Install
Run these commands on your server:
# Pangolin — official interactive installer (needs a domain + wildcard DNS)
curl -fsSL https://static.pangolin.net/get-installer.sh | bash
sudo ./installer
# Traefik serves 80/443; WireGuard on 51820/udp and 21820/udp.
# The installer is a full-screen TUI — answer it at a real terminal.What you take on
Pangolin is polished and moving fast (1.23.0 shipped on 16 September 2026); these are the parts of its docs to read before the installer:
An alternative to
Head-to-head
More self-hosted tools
Headscale
NetBird
wg-easy
OpenHands
Common questions
What is Pangolin a good alternative to?
Pangolin is a self-hosted alternative to Cloudflare Tunnel (and Tailscale Funnel) — it publishes services on your private network to the internet over WireGuard, but the ingress runs on a server you control instead of a third party's edge.
Do I need my own server to run Pangolin?
Yes — Pangolin needs a public VPS with a domain and wildcard DNS. That is the whole point: the tunnel endpoint and SSL termination live on hardware you own, so no external provider sits in front of your traffic.
How much RAM does Pangolin need?
It runs comfortably on a small 1 GB VPS — the dashboard is a lightweight Node/TypeScript app and the data plane (Gerbil) is a small Go service.
Is Pangolin open source?
Yes — the self-hosted Community Edition is AGPL-3.0. An Enterprise Edition with advanced features is open-core under the Fossorial Commercial License, which is free for personal use and for businesses under $100K in annual revenue.