Skip to content

Self-host Pangolin

updated Jul 2026prices checked · Jul 2026Install verified on Ubuntu 26.04 · Jul 2026 · how we test
We earn commissions when you shop through the links below. Full disclosure →

A self-hosted tunneled reverse proxy that exposes services on your private network to the internet over WireGuard, with built-in identity, access control, and automatic SSL — and, in recent releases, client-based private access to resources as well. A self-hostable alternative to Cloudflare Tunnel that keeps the ingress on a server you own.

Key facts

LicenseAGPL-3.0
StackTypeScript, Go
Min RAM1024 MB
Official imageyes
Difficulty
Our recommendation

Pick Pangolin when the job is publishing services from a network you cannot open ports on: a site connector dials out over WireGuard to your VPS, and Pangolin fronts the traffic with Traefik, automatic certificates, SSO, RBAC, PIN and email-OTP gates, browser-based VNC/RDP/SSH and an identity-aware AI gateway — a self-hosted Cloudflare Tunnel. The Community Edition is AGPL-3.0; the Enterprise image is under the Fossorial Commercial License, free below $100K annual revenue but keyed. Upstream's sizing is 1 vCPU and 2 GB of RAM for most deployments, so treat our 1 GB floor as the swap-assisted minimum.

Follow the Pangolin deploy guide →

What you need

  • Any VPS with at least 1024 MB of RAM
  • A domain you control — most self-hosted setups need HTTPS in front of them
  • About an afternoon — budget time for troubleshooting
Where to host itaffiliate disclosure
Hetzner Cloudrun it on
From $23.59/mo · 2 vCPU / 4 GB / 80 GB · EU + US
Get Hetzner Cloud (opens in new tab)
Kamaterafree trial
From $4/mo · 1 vCPU / 1 GB / 20 GB · US + EU + Asia
Start free on Kamatera → (opens in new tab)
DigitalOceanalso works on
From $6/mo · 1 vCPU / 1 GB / 25 GB · US + EU + Asia
Deploy on DigitalOcean → (opens in new tab)

Paid link — we earn a commission if you shop through it.

Install

Run these commands on your server:

# Pangolin — official interactive installer (needs a domain + wildcard DNS)
curl -fsSL https://static.pangolin.net/get-installer.sh | bash
sudo ./installer
# Traefik serves 80/443; WireGuard on 51820/udp and 21820/udp.
# The installer is a full-screen TUI — answer it at a real terminal.

What you take on

Pangolin is polished and moving fast (1.23.0 shipped on 16 September 2026); these are the parts of its docs to read before the installer:

non-negotiableIt needs a public VPS, a domain and a wildcard A record (* → your IP), plus TCP 80 and 443, UDP 51820 for site tunnels and UDP 21820 for clients. The VPS guide says 1 vCPU / 2 GB / 8 GB SSD "is sufficient for most deployments" and that with 1 GB "you may need to create swap space"; recommended is 2 vCPU / 2 GB. Our 1 GB floor is below upstream's own recommendation.
non-negotiableThe licence is per file. The LICENSE says files headed "Fossorial Commercial License" are proprietary, files headed AGPL-3 or with no header are AGPL-3, and bundled third-party components keep their own licences. On Community Edition, Enterprise features "may still appear in the dashboard but remain locked" — set flags.disable_enterprise_features: true to hide them. Enterprise is free for personal use and organisations under $100,000 gross annual revenue, but "You still need to apply for a valid license key".
non-negotiableUpdates run database migrations on start, and "A failed database migration blocks startup"; downgrading "is sometimes impossible and is not recommended". With SQLite, Pangolin copies the database before migrating (disable with DISABLE_BACKUP_ON_MIGRATION); upstream still says to back up the config directory and to step through versions (1.0 → 1.1 → 1.2) rather than jump.
non-negotiableAnonymous usage telemetry is on by default (app.telemetry.anonymous_usage: true in config.yml; set it to false to opt out).
non-negotiableThe installer pulls three images — pangolin, gerbil (the WireGuard side) and traefik — and prints a one-time setup token for /auth/initial-setup; if you skipped starting the containers, fetch it from the Pangolin container logs. SQLite is the default; PostgreSQL is a separate fosrl/pangolin:postgresql-<version> image, and the docs describe no migration between the two, so our advice is to choose before first start.

An alternative to

Cloudflare TunnelTailscale →

Head-to-head

More self-hosted tools

Common questions

What is Pangolin a good alternative to?

Pangolin is a self-hosted alternative to Cloudflare Tunnel (and Tailscale Funnel) — it publishes services on your private network to the internet over WireGuard, but the ingress runs on a server you control instead of a third party's edge.

Do I need my own server to run Pangolin?

Yes — Pangolin needs a public VPS with a domain and wildcard DNS. That is the whole point: the tunnel endpoint and SSL termination live on hardware you own, so no external provider sits in front of your traffic.

How much RAM does Pangolin need?

It runs comfortably on a small 1 GB VPS — the dashboard is a lightweight Node/TypeScript app and the data plane (Gerbil) is a small Go service.

Is Pangolin open source?

Yes — the self-hosted Community Edition is AGPL-3.0. An Enterprise Edition with advanced features is open-core under the Fossorial Commercial License, which is free for personal use and for businesses under $100K in annual revenue.

We use analytics cookies (Google Analytics, PostHog) to see which guides are useful. No ad networks, no cross-site tracking. See our privacy policy.