7 ms·
I am curious why I should consider using nginx when Caddy (https://caddyserver.com https://caddyserver.com) exists. It seems to have more activity behind it.
by nikivi 4y ago
I am curious why I should consider using nginx when Caddy (https://caddyserver.com https://caddyserver.com) exists. It seems to have more activity behind it.
- qbasic_forever 4y agoIn the context of kubernetes ingress caddy isn't really there yet, at least compared to nginx (which has two major k8s ingress implementations, one maintained by the core k8s devs themselves).
- francislavoie 4y agoThat is true, unfortunately. We, the core maintainers, don't use k8s ourselves, so we need to defer to the community for help. See https://github.com/caddyserver/ingress https://github.com/caddyserver/ingress
- qbasic_forever 4y agoYeah the whole k8s ingress world is a moving target that has changed substantially even in the last year or two. I don't blame you for not spending a ton of time on it. Caddy is still an awesome option to run inside a pod that needs to have a simple static file server, do some reverse proxying to services in the pod, etc.
- maxloh 4y agoCandy is written in Go (a garbage-collected language), which in theory slower than C (the language Nginx is written in).
- heurisko 4y agoWhen I evaluated Caddy it was missing some features, such as rate limiting. But I think Caddy is a fine server as well.
- francislavoie 4y agoRate limiting plugin: https://github.com/mholt/caddy-ratelimit https://github.com/mholt/caddy-ratelimit
- heurisko 4y agoYes, I came across that. Didn't really compare to rate limiting in nginx, in terms of maturity or support. > WORK IN PROGRESS: Please note that this module is still unfinished and may have bugs. Please try it out and file bug reports - thanks!
- francislavoie 4y agoSure, but it'll never reach maturity if you don't try it! We're always looking for more people to test things out, give their thoughts, and contribute ideas or fixes.
- heurisko 4y agoI think Caddy should adopt the module as a core module.
- francislavoie 4y agoWe may eventually do that, but we need evidence that it's actually useful for people, since it adds to the long-term maintenance burden if we bundle it.
- POPOSYS 4y agoRate limiting is a life saving jacket, not some fancy nice-to-have feature.
- francislavoie 4y agoUnderstood, but we don't want to ship something half-baked in the standard distribution. So we offer it as a plugin first so it can be worked on and polished without being tied to Caddy's versioning. Please try it out and give specific feedback on the plugin. We need to hear if there's any functionality missing or if the design doesn't fit user's needs before we can bundle it.
- deleted 4y ago[deleted]
- megous 4y agoBecause there are some benefits to using established software: Reading package lists... Done Building dependency tree... Done Reading state information... Done E: Unable to locate package caddy
- francislavoie 4y agoFor various reasons, we provide our own apt repo: https://caddyserver.com/docs/install#debian-ubuntu-raspbian https://caddyserver.com/docs/install#debian-ubuntu-raspbian Biggest reason is that debian's packaging requirements are way too much of a burden for us to conform to, especially for Go apps. And they update way too slow for us to be comfortable with.
- kanonieer 4y agoI stopped considering using Caddy when the following happened: https://web.archive.org/web/20170913160203/https://caddyserver.com/blog/accouncing-caddy-commercial-licenses.html https://web.archive.org/web/20170913160203/https://caddyserv... The project lost tons of good faith back then, and in my eyes (as a brand) never recovered.
- c0balt 4y agoIdk but for most projects that don't go down the apache foundation or GNU path funding via either support (Tidelift, consulting...) or non-oss extended versions (NGINX has NGINX+) is normal. Passion is nice but money for a sustainable livelihood has got to come from somewhere with donations often being insufficient.
- kanonieer 4y agoHave you read the article? Because what was proposed back then is not what NGINX is doing.
- turtlebits 4y agoMaybe it's just me, but the Caddy config file (either the docs or the format) isn't great. It took me way too long to turn on a simple feature (didn't work, no errors). That plus having to relearn the config going from v1 -> v2 turned me off to it.
- corrral 4y agoIt's much more widely used and has been around a whole lot longer, both of which confer many benefits. Personally, if nginx made letsencrypt as easy as caddy does, I'd never even think about caddy. That's its One Thing that kinda tempts me.
- ancientsofmumu 4y ago> if nginx made letsencrypt as easy as caddy does The EFF cerbot plugin has it covered; assuming your generic Debian server with nginx already configured to host www.domain.com (trivial hello, world setup - nothing fancy) then it's: apt-get install cerbot python3-certbot-nginx certbot --nginx -d www.domain.com -d domain.com \ --agree-tos -m "email@domain.com" --no-eff-email \ --deploy-hook "systemctl reload nginx" systemctl restart nginx All done. Certbot is already running as a systemd service to handle ongoing renewals and it'll now restart nginx if your cert is updated. This example uses the trivial http-01 ACME method, if you need the more complex DNS based setup for wildcards that'll take a bit more elbow grease.
- francislavoie 4y agoFWIW, having the ACME client separate from the server has a bunch of downsides. It's less robust, can't provide OCSP stapling and automatic renewal on revocation, doesn't have issuer fallback, can't offer you On-Demand TLS, etc.
- pilif 4y agoI agree with most points, but OCSP stapling is independent of ACME and thus is perfectly doable with nginx and an externally obtained let’s encrypt certificate. That aside, for me the trade-off was different and I was willing to give up the benefits of included acme support for the benefits of running a very well-supported and well-known web server that at this point hosts most of the internet and which can run on port 80/443 without iptables hacks (not sure whether this still applies to caddy)
- 4y ago
- loganmarchione 4y agoI don't think any large corporations are using Caddy. Everywhere I've worked has used Nginx for any high-traffic applications. As a side note, I'm looking at Traefik in my homelab and it's honestly difficult because I'm so comfortable with Nginx.
- number6 4y agoIt's difficult because of the boilerplate. Compare traefik with caddy-docker-proxy. Same feature set but only 30% of the code
- mholt 4y agoThere are several large corporations using Caddy. Several companies you've heard of and probably used the products of! I have a call with one of them every few weeks. I also know a huge hospital chain in the US is using Caddy.
- tfigment 4y agoCaddy has problems with streaming gRPC (not simple request/response). So does Traefik to my understanding but Traefik might work better if reports are to be believed. Nginx has support i think but ive not verified it. I like caddy simple config when it works. None of the proxies seem to do well with bidirectional gRPC streams as they just treat gRPC as a h2 proxy but I'd love to see that proven wrong.
- m_sahaf 4y agoCaddy is capable of handling bidirectional gRPC streams! I have just tested it, and it works just fine. Caddy will immediately flush writes when upstream is `h2` or `h2c`[0] instead of having to wait until reading from socket is complete I used this Caddyfile to proxy to the route_guide example (https://github.com/grpc/grpc-go/tree/master/examples/route_guide https://github.com/grpc/grpc-go/tree/master/examples/route_g...): ``` localhost { reverse_proxy h2c://localhost:50051 } ``` It works like a charm. [0] https://github.com/caddyserver/caddy/blob/e4ce40f8ff0424054045de2461fc7228c66f3c61/modules/caddyhttp/reverseproxy/streaming.go#L125-L127 https://github.com/caddyserver/caddy/blob/e4ce40f8ff04240540...
- chamakits 4y agoFrom my limited and possibly outdated experience (about a year since I last looked), caddy's documentation was lacking a bit when compared to nginx. Even worse than that, any time I tried to google to better understand how to do something with caddy, every result returned how to achieve exactly that with nginx; and would rarely find the way to do it with caddy. But it's been about a year since that, unsure if things have changed.
- francislavoie 4y ago> caddy's documentation was lacking a bit when compared to nginx Could you be more specific? We keep hearing vague comments like this about our docs, but without feedback pointing to specific issues, we can't improve them. I suggest that next time you have trouble finding the information you're looking for, reach out to us and let us know. Open a topic on the forums, we'll be glad to help you find what you're looking for. And if you do so and point out a lack in our docs, we'll know where to focus our efforts.
- chamakits 4y agoI don’t remember off the top of my head, apologies. I’ll take a look at my notes see if I can find what I was looking for! Having said that, I’ll keep this in mind next time I try out again; and if I run into something, I’ll reach out in the forums.
- chamakits 4y agoOh, I’m remembering bits of it! I was at the time trying to setup jupyter to work with a reverse proxy such that I could access jupyter through zerotier. Sorry this is all probably a messy set of words that don’t all make sense together with more details. I’ll commit to next time that I’m trying this or anything else, and I hit a wall, I’ll ask.
- eddieroger 4y agoI used to use Caddy in the v1 days, but after some really unfortunately licensing decisions (which I think were reverted ultimately), I felt burned and stopped using it. It was my go-to for static site serving containers for a while, but because some of the time I need to make what they considered "commercial" ones (work related), I couldn't any longer. And it was handled really poorly in my recollection, with some random sponsor header injection. I decided that nginx on a slim distro container is more than fine most of the time.
- zmxz 4y agoSeeing you're someone capable of using a web server, it implies you're beyond capable of finding why Caddy over nginx and vice versa, which brings up the question: why didn't you?
- alskdjflaskjdhf 4y agoThis kind of response is rude and unhelpful. This is how they are finding it out. Just googling "X vs Y" invariably gives you worthless SEO spam these days. A forum like HN, where you can hear about the experiences of other people in the field, is a great way of getting more useful information.
- zmxz 4y agoThank you for the response and the judgement, but we obviously consider the word "rude" to mean something else. I was not offensive or ill-mannered, I merely wondered why a person, that's apparently capable of doing minimal research, does not do so before asking for opinion of people on HN in regards to software details. Briefly judging GitHub activity is not the way to make conclusions, which was the only detail being covered. It's easy to label someone or something rude, I can't control how you read the text I write and what the imaginary tone of voice is. Great Robin Hood display, I love the fact we all get to be judge and jury who decide what's good and what's bad, often missing the real intent.
- formerly_proven 4y agoI recall some licensing fuss with Caddy but it looks like it's actually open source now. But stuff like this does tarnish a brand for a long time, see e.g. people still being uncertain about Qt licensing, not because of the more recent developments, but because of licensing issues that were settled in the 90s.
- mholt 4y agoCaddy has always been open source. The source code has always been Apache licensed.
- kanonieer 4y agoYou're absolutely right, it was a dumpster fire and it tarnished the name for me as well. https://web.archive.org/web/20170913160203/https://caddyserver.com/blog/accouncing-caddy-commercial-licenses.html https://web.archive.org/web/20170913160203/https://caddyserv...