Hey,
I am currently paying 5,50€ a month for a Hetzner VPS to selfhost a Pangolin instance. I’ve come to quite rely on Pangolin, because I have to access all of my selfhosted services from my home server from remote. That’s because I have to keep my server at home (while I live in a student dorm, which doesn’t allow using their network to host servers). Also their authentication and private resources are really good for security and exposing ssh and other stuff from my home server to authenticated clients.
Anyway, I like this setup, because it is fully FOSS and I have 100% control of what my VPS does. It is really expensive though and I am trying to reduce my monthly expenses right now.
I saw online, that you can get a free managed instance of Pangolin on their website (https://pangolin.net/pricing Cloud). It would meet all my needs, but I wouldn’t be 1. Fully FOSS (because they probably run the business licensed version of their software) and 2. I wouldn’t have full control.
These services work by managing all the https certs themselves, so the have to decrypt all their traffic and send it through the tunnel to your server. Theoretically, Pangolin could log all my traffic to and from my server, which would be a huge privacy risk. But probably they’re not, because that would be really impractical…? I don’t know.
Do you think, it would be worth the privacy tradeoff for the cost savings?
I think it’s worth it, but you could move to one of the VPS deals on racknerd (or another lowendbox.com deal), for like $10-20 a year and save a bunch.
I don’t like the idea of a third party doing MitM type intercepts. I want control over anything that sees my unencrypted data whether it’s web services or chat services, etc. So for me the VPS is worth it. But I do also use my VPS for some other services that use apps or other APIs that don’t allow for presenting the Pangolin/SSO login step, and aren’t too risky to have a bit exposed rather than the responsiveness and battery cost of the separate VPN connection. One day I need to find a better way to handle those but for now it’s fine.
lowendbox.com is where I go looking for good deals on VPSs.
https://lowendbox.com/blog/1-vps-1-usd-vps-per-month/
I’ve been using the $10.28/year Racknerd deal on that page to run my Netbird server since the start of the year. It’s been good enough for that job.Move over to racknerd. I pay $17 a year for my VPS to host Pangolin and it works great. They even have cheaper options than that too.
If FOSS is a concern you could look into NetBird. They also have a hosted alternative but as far as I know the entire stack is FOSS.
It’d still be a matter of trusting a private company though.
Tbh I couldn’t set up Netbird in a way that I’m happy with. I’d like to use it with an external Caddy and Authelia but the setup is so terribly documented and has various bugs I have given up.
Actually, they seem to have a tls-passtough mode, which would allow me to handle encryption myself
Yeah, I will maybe look into it, thanks. Allthough, at that point I could also probably trust Pangolin aswell, their stuff is also mostly FOSS
yes I would, I have moved from a fixed line with static IP at home to starlink and pangolin has been my life line.
I like having all my own infrastructure where I can manage it, I like to know how things work.
Also have a look at OVH for VPS
Maybe as another option, you could try to find a few other students and pool your money for a shared VPS? Back then I used to share an internet connection with few people to make it more affordable. We also used to share some storage space for stuff and the CS students did a website and an internal message board. I’m old, though. No clue how they do it as of today.
That is a cool idea, but unfortunately, I don’t know anyone, that would be willing to do this. One of my friends has a selfhosted server, but he doesn’t want to pay for stuff like that. He uses everything through a VPN, so he has no running costs.
I did just come up with a pretty good solution though. I looked into Netbird and they actually have tls-passthrough functionality, so I could just run my nginx-reverse proxy locally which handles the certs and encryption and I could be 100% shure, that the company can’t read my traffic.
Yeah install a reverse proxy at home and reach it through a service like Netbird or Tailscale. No VPS needed. And it’s probably a better idea to do it this way because a local reverse proxy would be 100% self-reliant. Hosting Pangolin on VPS would always make you dependent on the VPS.
NPM (Nginx Proxy Manager) is an Nginx distribution with a friendly UI and it includes certbot so you can get/renew certs automatically and use
https://service.yourdomain.com/URLs if you want.You will need a DNS provider for that btw, DeSEC.io is free and committed to privacy.
Totally, though I use towonel on an OVH VPS. Couldn’t be happier.
Oh, that’s really cool. I also tried that but couldn’t get it to work
You can still get a free account with Oracle Cloud
I have that and it’s hot garbage.
It’s so worth that I did it twice.








