Head to head
Pangolin or Cloudflare Tunnel for exposing a home server?
Both get a service behind CGNAT onto a public hostname with outbound connections only. The difference is whose machine terminates TLS, and that one fact decides what you may stream, what you can expose and who absorbs an attack.
Should I use Pangolin or Cloudflare Tunnel to expose a home server?
Use Cloudflare Tunnel if you want a free, VPS-less setup with Cloudflare's DDoS protection and you only publish ordinary web apps. Use Pangolin if you stream media, upload files over 100 MB, need raw TCP or UDP ports without client software, or want TLS to terminate on a machine you control. Pangolin needs a VPS with a public IP and ports 80/tcp, 443/tcp, 51820/udp and 21820/udp open. Cloudflare's terms require a paid service for video on Free, Pro and Business plans, and its own docs say tunnel public hostnames are covered.
Use Cloudflare Tunnel if you publish ordinary web apps, want no VPS bill and want someone else to absorb a flood. Use Pangolin if you stream media, upload large files, need raw ports for people who will never install a client, or want TLS to terminate on a machine you rent rather than at a company you do not. Neither is a VPN in the Headscale vs wg-easy sense: both put a service on a public hostname that strangers can reach.
The architecture is the same shape in both. A small daemon at home dials out, so nothing is forwarded on your router and CGNAT stops mattering. What differs is the far end of that connection. With Cloudflare it is Cloudflare's network. With Pangolin it is a VPS you rent, running three containers you administer.
Who holds the edge, side by side#
Assembled from Pangolin's install docs, VPS guide and compose file, and Cloudflare's tunnel, firewall and limits pages, as of October 2026:
| Pangolin 1.24 (Community Edition) | Cloudflare Tunnel | |
|---|---|---|
| Where TLS terminates | Traefik on your VPS, Let's Encrypt certificates | Cloudflare's edge |
| What you run | Pangolin, Gerbil and Traefik v3.7 on a VPS; Newt or the Pangolin CLI at home | cloudflared at home |
| Inbound ports | 80/tcp, 443/tcp, 51820/udp, 21820/udp on the VPS | None; outbound 7844 TCP (http2) or UDP (quic) |
| Server OS | Ubuntu 20.04+ or Debian 11+, amd64 or arm64 | None, it is a hosted service |
| Server size | 1 vCPU, 2 GB RAM, 8 GB SSD "sufficient" | Not applicable |
| Price | Free software, plus the VPS | "Available on all plans", including Free |
| DDoS absorption | Whatever your VPS provider offers | Cloudflare's, applied automatically |
| Upload size per request | Your VPS and app limits | 100 MB on Free and Pro, 200 MB on Business |
| Video and large files | No third-party terms | Paid service required below Enterprise |
| Raw TCP/UDP for anyone | Yes, opt-in, unauthenticated | TCP only, and visitors must run cloudflared |
| Licence | AGPL-3 (Enterprise Edition under a commercial licence) | cloudflared is open source; the service is proprietary |
The first row produces most of the others. Whoever terminates TLS sees plaintext, sets the upload limit, and writes the terms of service.
The video clause is real, and Cloudflare says it covers tunnels#
Two answers circulate. One says Cloudflare Tunnel is a Zero Trust product rather than the CDN, so the CDN's video rule does not apply. The other says Cloudflare bans media over tunnels outright. Both are wrong, and Cloudflare's own documentation settles it.
The service-specific terms for application services, last updated 28 September 2026, say that unless you are an Enterprise customer, you must use specific paid services (the Developer Platform, Images, Stream) "in order to serve video and other large files via the CDN", and that Cloudflare may disable or limit your use of the CDN if you serve "video or a disproportionate percentage of pictures, audio files, or other large files" without them. The separate Zero Trust terms say nothing about Tunnel or video, which is where the first answer comes from.
It does not survive Cloudflare's tunnel docs. The routing page states that public hostname routes proxy traffic through Cloudflare and that on Free, Pro and Business plans the service-specific terms apply. The video policy page says the same, then adds the exception the second answer misses: the restriction does not apply to private network routes, meaning devices enrolled in your Zero Trust organization, usually through the Cloudflare One client, rather than a public hostname. The private networks page goes further and names media servers as a workload those routes can carry.
So a Jellyfin library on media.example.com through a free tunnel is inside the clause. The same library reached by family members running the Cloudflare One client on a private route is not. If the people watching will never install a client, Pangolin, or a plain public IP, is the answer. Jellyfin vs Plex covers the server side.
The 100 MB request limit is the quieter version of the same problem. Cloudflare returns 413 above it on Free and Pro, so a phone uploading a long video to Immich through the tunnel fails in a way that looks like an Immich bug.
What Pangolin's Community Edition actually gates#
Pangolin's install docs offer a choice of Community or Enterprise Edition without saying what differs. The answers are in three other places.
The LICENSE file says files carrying a "Fossorial Commercial License" header are commercial, and every file without a header defaults to AGPL-3. The README calls Community Edition free, open source and AGPL-3, and Enterprise Edition open core under the Fossorial Commercial License. The Enterprise docs say both editions provide the same core functionality, Enterprise unlocks additional features on the ee image with a licence key, and it is free for personal use and organizations under $100,000 USD gross annual revenue. You still apply for that key with an account at app.pangolin.net, and the docs warn that inaccurate representation gets it revoked.
The docs then point to the self-hosted pricing table as the source of truth. In October 2026 it shows Community Edition with:
- 2FA, OAuth2/OIDC and server-level identity providers, with user auto provisioning
- geoblocking, API keys, blueprints, labels and multi-site routing
- browser-based SSH, RDP and VNC resources, and client-based SSH and HTTP private resources
And locked to Enterprise:
- multiple roles per user, Google and Azure identity providers, role-based SSH
- 2FA enforcement, session and password policies, device posture, device approvals
- HTTP request, authentication, network and admin action logs, CSV export, SIEM streaming
- wildcard resources, standalone health checks, alert rules and automatic site updates
- clustering and geographic distribution, which need Scale ($1,249 a year) rather than Starter ($449)
The logs line is the one a homelab notices. Community Edition does not record HTTP requests or logins in the dashboard; the Traefik access log on the VPS is still yours to read. And the free Enterprise key counts users and sites, so going over the quantity on it turns features off and shows a red "Unlicensed" banner.
Switching editions is an image swap between fosrl/pangolin:latest and fosrl/pangolin:ee-latest on the same database schema, so you can start on Community and move later.
What running Pangolin costs you#
The install is one script and about three minutes. The ongoing cost is that you now operate an internet-facing server:
curl -fsSL https://static.pangolin.net/get-installer.sh | bash
sudo ./installer # edition, base domain, dashboard domain, Let's Encrypt emailThe shipped compose file runs Traefik with network_mode: service:gerbil, so all four ports appear on the Gerbil container, and Gerbil needs NET_ADMIN and SYS_MODULE. The VPS guide warns that 1 GB of RAM may need swap during installs and updates. Every byte a visitor downloads crosses that VPS, so a provider's bandwidth allowance is part of the sizing. Keep the OS patched and read A security baseline for a home server before pointing DNS at it.
Raw TCP and UDP take more than a toggle. You set allow_raw_resources: true, open the port in the VPS firewall, add it to the Gerbil ports: list and add a Traefik entry point, then restart. Pangolin's docs state that these resources get no Pangolin authentication: they are pipes. That is right for a game server and wrong for an admin panel.
The DDoS argument, and where it runs out#
Cloudflare's tunnel docs say traffic through a published hostname gets CDN caching, WAF and DDoS protection applied automatically. With Pangolin, DNS points at your VPS's public IP and what stands between it and a flood is your VPS provider.
How much that matters depends on what you publish. A family photo album and a Vaultwarden instance are not targets. A public game server or anything that attracts attention is. If you want both, Pangolin documents running behind Cloudflare's orange cloud: Full (Strict) TLS only, wildcard certificates via DNS-01, and gerbil.base_endpoint set to the real VPS address. Its own warning is that this binds you to Cloudflare's terms. You get the DDoS layer back, and you also get TLS termination at Cloudflare and the video clause back. There is no configuration that keeps all three.
Pangolin's own comparison, a vendor page dated 23 February 2026, says Cloudflare "could, in principle, man-in-the-middle" traffic it decrypts. That is the vendor's framing. What is not framing is that Cloudflare's own routing table describes the HTTP service type as proxying incoming HTTPS to your origin over HTTP: the edge holds the certificate and the plaintext.
Which one for your situation#
| Situation | Use | Why |
|---|---|---|
| A few web apps for yourself, no budget for a VPS | Cloudflare Tunnel | Free on every plan, nothing to administer |
| Media streaming to people outside the house | Pangolin | The video clause covers tunnel public hostnames below Enterprise |
| Uploads over 100 MB from phones or browsers | Pangolin | Cloudflare returns 413 on Free and Pro |
| A game server friends join with no extra software | Pangolin | Raw TCP and UDP resources; Cloudflare needs cloudflared on the client |
| Something likely to be attacked | Cloudflare Tunnel | DDoS absorption is the one thing a VPS cannot match |
| You self-host so that no company reads your traffic | Pangolin | TLS ends on your VPS, not at a third party's edge |
| Only your own devices need access | Neither | A mesh VPN: Headscale or Tailscale |
Where this answer stops applying#
Cloudflare Enterprise customers are outside the video clause. Private network routes through the Cloudflare One client are outside it on every plan. Pangolin Cloud, the vendor's managed service, is not what this page compares. The Enterprise feature list and prices above are Pangolin's pricing page in October 2026, which its docs call the source of truth and which can change.
What to do next#
Decide what must be public and what only needs to be reachable by you; Remote access without port forwarding walks through that split. If it is Pangolin, read Reverse proxy and TLS for the DNS-01 path that wildcard certificates need, and back up the config directory: the shipped compose file mounts it into all three containers, Let's Encrypt store included. If it is Cloudflare, keep media and big uploads off the tunnel. The rest of the category is at Networking.
Questions#
Is streaming Jellyfin or Plex through Cloudflare Tunnel against the terms?
On a public hostname, yes. Cloudflare's service-specific terms (updated 28 September 2026) say that unless you are an Enterprise customer you must use paid services such as Stream to serve video and other large files via the CDN, and that Cloudflare may disable or limit access if you do not. Cloudflare's Tunnel routing docs state that public hostname routes proxy traffic through Cloudflare and fall under those terms. Its video policy page adds that the restriction does not apply to private network routes reached through the Cloudflare One client.
Is Pangolin open source?
The Community Edition is, under AGPL-3. The repository is dual licensed: files with a Fossorial Commercial License header are commercial, and files without a header default to AGPL-3. The Enterprise Edition is the same codebase run from the fosrl/pangolin:ee-latest image with a licence key. It is free for personal use and for organizations under $100,000 USD gross annual revenue, but you still have to create an account at app.pangolin.net and apply for the key.
What does Pangolin Enterprise Edition add over Community Edition?
According to Pangolin's self-hosted pricing matrix: multiple roles per user, Google and Azure identity providers, tenant-isolated identity providers, 2FA enforcement, session and password policies, device posture and approvals, every log type (HTTP request, authentication, network, admin action), SIEM streaming, wildcard resources, standalone health checks, alerting, automatic site updates and custom branding. Clustering and geographic distribution need the Scale tier or above. Community Edition keeps 2FA, OIDC identity providers, geoblocking, API keys, blueprints and browser-based SSH, RDP and VNC.
How big a VPS does Pangolin need?
Pangolin's VPS guide says 1 vCPU, 2 GB of RAM and 8 GB of SSD is sufficient for most deployments, recommends 2 vCPU, 2 GB and 20 GB, and warns that a 1 GB VPS may need swap during installs and updates. The shipped compose file caps the Pangolin container at 1 GB and reserves 256 MB. The documented install targets Ubuntu 20.04+ or Debian 11+ on amd64 or arm64. Every byte your visitors download crosses that VPS, so its bandwidth allowance matters as much as its RAM.
Can Cloudflare Tunnel expose a game server or other raw TCP or UDP port?
Not to people without client software. Cloudflare's routing docs list TCP, SSH, RDP and SMB as public hostname service types, streamed over a WebSocket, and say end users must run cloudflared on their own machine to connect. UDP is not in that list. Pangolin's raw TCP and UDP resources bind a port on the VPS that anyone can connect to directly, with the caveat that Pangolin applies no authentication to them.
Can I put Pangolin behind Cloudflare's proxy?
Yes, and Pangolin documents it: SSL/TLS mode must be Full (Strict), wildcard certificates over DNS-01 are recommended, and gerbil.base_endpoint must be set to the VPS's real IP because the proxy hides it. Pangolin's own warning is the point, though: enabling the proxy binds you to Cloudflare's terms because traffic routes through its network. You regain DDoS absorption and hand TLS termination and the video clause straight back.
Sources#
- Pangolin docs, quick install guide
- Pangolin docs, choosing a VPS
- Pangolin docs, Enterprise Edition, personal use and licence limits
- Pangolin pricing, self-hosted feature matrix
- Pangolin repository, LICENSE and README
- Pangolin docs, raw TCP and UDP resources
- Pangolin docs, running behind the Cloudflare proxy
- Pangolin, Pangolin vs Cloudflare One (vendor, 23 February 2026)
- Cloudflare docs, Cloudflare Tunnel overview and routing
- Cloudflare docs, Tunnel with firewall (port 7844)
- Cloudflare, service-specific terms for application services (28 September 2026)
- Cloudflare docs, delivering videos with Cloudflare
- Cloudflare docs, Tunnel private networks
- Cloudflare docs, error 413 and upload limits by plan
Published . Last reviewed . Found something out of date? Tell us and we will fix it and log the change.