Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Pangolin: Open-source identity-based VPN (Twingate/Zscaler alternative)

Details

External ID
47022745
Source
HN
Company
—
Product
Pangolin: Open-source identity-based VPN (Twingate/Zscaler alternative)
Website domain
github.com
Launched
Feb. 15, 2026
Cohort
—
Upvotes
81
Upvotes percentile
0.866576819407008
Tags
—
Fetched at
Sept. 7, 2026, 9:25 p.m.
Updated at
Sept. 7, 2026, 9:25 p.m.

Description

Pangolin (https://github.com/fosrl/pangolin) is an open-source tool for identity-based remote access to internal resources - an alternative to Cloudflare ZTNA, Zscaler, and Twingate.It’s different than existing approaches: mesh VPNs (Tailscale, ZeroTier, etc.) create flat overlay networks where ACL and IP space management becomes complex at scale and every device can talk to every other device, while corporate ZTNA solutions (Zscaler, Cato, Netskope etc.) are closed-source and add latency by forcing traffic through a central server.Pangolin takes a resource-centric approach. You deploy lightweight connectors that bridge to specific resources (private web apps, SSH, databases, CIDR ranges). Admins delegate resource-access to specific users and roles. It uses WireGuard with NAT hole-punching for peer-to-peer connections and traffic goes directly between the user and connector instead of through a central server. It supports native clients (Mac/Windows/Linux/iOS/Android) plus identity-aware, browser-based access when a client isn’t required.Pangolin has a cloud and is optionally self-hosted. The Community Edition is AGPLv3. The Enterprise Edition is also open-source under the commercial license which enables free personal/small business use.Everything, from the server to the clients, is fully open-source and you can even self-host the whole stack. We’d love to hear what you think and I'm happy to answer any questions!

Enrichment

Theme
self-hosted infrastructure and security tools
Vertical
Security
Function
Dev tools
Audience
Developer
AI stance
Not AI
Project type
Hobby / open-source project
Normalized one-liner
identity-based vpn for zero trust access
Manually corrected
False

Could you build this?

No Building a zero-trust network access (ZTNA) system requires deep systems networking, low-level OS tunnel interfaces (TUN/TAP, WireGuard), identity token exchange, and high-performance packet routing.

What it would actually take: A production ZTNA system requires a custom control plane orchestrating WireGuard or custom TLS/mTLS tunnels, identity provider integrations (OIDC/SAML), and low-level agent software running across operating systems handling TUN interfaces and kernel routing tables. The architecture demands high-throughput proxy daemons (typically in Rust or Go) and rigorous security auditing to guarantee memory safety and prevent network bypasses.

Discussion

20 comments analyzed.

Competitors mentioned: Tailscale, Cloudflare Tunnels, Twingate, OpenZiti, DIY WireGuard

Concerns raised: Symmetric NAT hole-punching fallback to relay servers defeats P2P purpose, Lack of network performance/throughput documentation, Concerns about open-source version being discontinued for paid-only model, Enterprise edition falsely advertised as open source with mixed source code, Deliberate brand confusion with Tailscale's pangolin mascot

Feature requests: Direct LDAP authentication support, Kubernetes RBAC integration with API for resource discovery, Multiple resources per connector clarification, 4K streaming performance benchmarks

Competitors

Other products that read as similar to this one — 68 launches clear the similarity bar, closest 8 shown.

Attention rank: #12 of 69 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 80 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a dev tools tool for Sales yet.