About this project

Pangolin is an open-source Secure Access Service Edge (SASE) platform built on WireGuard, designed to unify networking and security. It provides zero-trust VPN access, a zero-trust reverse proxy, privileged access management (PAM), and an identity-aware AI gateway, all sharing a single identity and policy model. The platform is self-hostable, lightweight, and aims to be simple to deploy and manage. Key features include: - **Site connectors**: Lightweight user-space connectors that establish outbound tunnels and use NAT traversal to access networks behind restrictive firewalls without open ports or public IPs. - **Browser-based reverse proxy**: Expose HTTPS web apps and access VNC, RDP, and SSH directly in the browser with authentication, granular access control, and automatic SSL certificates. - **Client-based private resource access**: Access private resources like SSH servers, databases, and network ranges through Pangolin clients, with peer-to-peer NAT traversal and DNS aliases. - **Identity-aware AI gateway**: Proxy access to cloud AI models (OpenAI, Anthropic, Gemini) and self-hosted model servers (Ollama, vLLM, Mistral) with budgets, session history, and usage analytics. - **RBAC and identity provider integration**: Use built-in users or bring your own IdP, with user- and role-based access control and full audit logging. - **Resource launcher**: A personalized home page for users to find and launch accessible resources, with searchable, filterable views. Deployment options include Pangolin Cloud (managed service), self-hosted Community Edition (AGPL-3), and Enterprise Edition (open-core with commercial license). Clients are available for Mac, Windows, Linux, iOS, and Android.