Pangolin, the open-source reverse proxy that started out as a way to publish services from a homelab or Docker host, has shipped version 1.24 with a feature that changes what the tool is for: exit nodes.
Until now, users installed the Pangolin client to reach resources exposed through the Pangolin network — the classic 'access my NAS or Home Assistant from holiday' use case. With exit nodes, a device can send all of its internet traffic out through one or more sites, turning each site into a VPN gateway. Any admin can now build what looks and behaves like a commercial VPN, using their own infrastructure.
That puts Pangolin into direct competition with Tailscale and with the WireGuard setups baked into router operating systems such as FritzOS. Pangolin's pitch is convenience plus consolidation: network, user and resource management in a single graphical interface, with per-device exit-node selection that resembles a commercial VPN client.
Pangolin is typically installed on a small VM at a cloud provider, with self-hosted 'sites' attached over WireGuard tunnels — a home NAS, for instance, or individual company locations. A core feature remains its reverse proxy, where admins define the services each site exposes internally or to the internet.
The release follows a pattern from the project's commercial steward, New York-based startup Fossorial: important features arrive soon after each other, and capabilities once reserved for paying customers get folded into the free tier. In version 1.23, that meant a highly available, load-balanced cluster of multiple Pangolin instances.
For homelab operators the practical upshot is fewer boxes to run: one tool for reverse proxying, identity and now VPN egress — at the cost of depending on one project for all three.




