Best Practice for running Pangolin both locally and for tunneling? #1235

Closed
opened 2026-04-05 18:33:45 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @silverjerk on 7/15/2025

Read through the docs, but still unclear on best practice for running Pangolin both locally and remotely with tunneling.

Running a 3-node Proxmox Cluster along with 2 local NAS devices. Running Pihole along with NPM for managing all local DNS and proxy to both the PVE nodes and NAS devices, along with Cloudflare for tunnels and certs when needed.

Deployed a Hetzner VPS with Pangolin to manage tunneling for the local services that require external access, mostly a few of my development services (accessed rarely) across both the PVE nodes and one of the NAS devices. Using two domains for this; one is almost always used for internal services, the other is outward facing -- but there is overlap.

Is the best practice to spin up a separate instance of Pangolin locally on my cluster and replace NPM with Pangolin for proxy management? How best to handle provisioning certs with this sort of setup, where I'm pointing my A records and wildcards to the VPS?

*Originally created by @silverjerk on 7/15/2025* Read through the docs, but still unclear on best practice for running Pangolin both locally and remotely with tunneling. Running a 3-node Proxmox Cluster along with 2 local NAS devices. Running Pihole along with NPM for managing all local DNS and proxy to both the PVE nodes and NAS devices, along with Cloudflare for tunnels and certs when needed. Deployed a Hetzner VPS with Pangolin to manage tunneling for the local services that require external access, mostly a few of my development services (accessed rarely) across both the PVE nodes and one of the NAS devices. Using two domains for this; one is almost always used for internal services, the other is outward facing -- but there is overlap. Is the best practice to spin up a separate instance of Pangolin locally on my cluster and replace NPM with Pangolin for proxy management? How best to handle provisioning certs with this sort of setup, where I'm pointing my A records and wildcards to the VPS?
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/pangolin#1235