Caddy: Web Server With Automatic HTTPS
Last updated on

Caddy: Web Server With Automatic HTTPS

Caddy is a web server whose defining feature is that HTTPS simply works: it obtains, installs, and renews certificates from Let’s Encrypt without being asked.

The configuration difference

A working reverse proxy with valid TLS in Caddy looks like this:

app.example.com {
    reverse_proxy 127.0.0.1:8096
}

That is the complete configuration. The equivalent nginx block runs to fifteen lines plus a separate certbot setup and a renewal cron job. For a homelab where the requirement is routing a handful of hostnames to a handful of ports over HTTPS, this is the least configuration that can possibly work.

What else it does

Static file serving, HTTP/2 and HTTP/3, on-demand TLS for dynamic hostnames, and a plugin ecosystem covering DNS providers for wildcard certificates, authentication, and rate limiting. Configuration can also be driven through a JSON API for programmatic setups.

Where the alternatives win

Traefik discovers containers automatically from labels, which Caddy does not do natively. Nginx Proxy Manager provides a web UI for people who would rather click than edit a file. Plain nginx has deeper tuning options and a larger body of existing documentation for exotic requirements.

Our reverse proxy guide compares the three approaches in more detail.

Practical note

Automatic certificates require ports 80 and 443 reachable and a resolving DNS record, or a DNS provider plugin for the DNS challenge. That plugin route is what you want for internal-only services that should still have valid certificates.

License

Caddy is released under the Apache License 2.0.