15 ms·
Caddy is the first and only web server to use HTTPS automatically and by default
- zoidb 3y agoCaddy had been a joy for me personally coming from NGINX. I especially love the ease of adding a new site and how little config it takes. Small self plug, I recently wrote an article about some cool config examples https://jarv.org/posts/cool-caddy-config-tricks/ https://jarv.org/posts/cool-caddy-config-tricks/
- thomasfromcdnjs 3y agoFor local development, I don't think nginx/apache even contend against it. The config is incredibly readable, and caddy is a single executable with no dependencies.
- isodev 3y agoAlso for production, it's such a joy to be able to configure a VM with a single Caddyfile (or worst case, provision the server using the Caddy REST API). I love it!
- berkes 3y agoSame here. And, having mostly worked with Rails, PHP and Python http services, the proxying webserver is hardly ever a performance issue. You can stick the slowest webserver in front of a Rails (Rack) app and still be unable to measure the latency it adds. I've been using caddy for years and while it's slower in benchmarks, than others, I've never had the practical situation where that mattered.
- caddyroxors 3y agoComparing it to nginx is a such a low bar; 9 out of 10 masochists prefer nginx over any other tool. But I see and agree with your overall point. Caddy is like a breath of fresh air, and just as useful!
- layer8 3y agoIt’s funny to read this, remembering when Nginx was considered the fresh air in comparison to Apache.
- reactordev 3y agoIt’s funny because I remember when Apache was a breath of fresh air to httpd.
- fodkodrasz 3y agoBacking the days (5+ years ago I think) we tried it, and while it was nice its licensing/pricing made us not use it for our startup, as it seemed to pose a sustainability threat when growing (or not growing the right pace). Has it improved since then? disclaimer: I don't remember the details, I was just told to use nginx because caddy is problematic, so I built the system with nginx open source.
- 369548684892826 3y ago> Backing the days eggcorn or autocorrect?
- fodkodrasz 3y agoNeither. Lack of coffee. Won't correct it now :D (English is not my mother tongue, which is a phonetic language, Hungarian, and while I know the difference very well, being tired causes these kinds of typos sometimes)
- Semaphor 3y agoI (native language German) sometimes make similar homophone typing errors. My brain knew what I wanted to type, but is already further ahead, by the time (100-200ms) I get to typing it, my fingers only remember the sound of it and sometimes write something different that sounds similar (like to and two) or the same. It’s weird. Not sure if I’d make those mistakes in German as well, as I write far less in it ;)
- fodkodrasz 3y agoI do some handwriting (for journaling), and when I'm really tired, I sometimes also make these types of mistakes in Hungarian handwriting, though far less often than in typing. Probably we are always in a hurry, and should slow a bit down, and think twice (or more thoroughly) when composing text (or even in other aspects of our lives).
- alias_neo 3y ago
- BilalBudhani 3y agoI believe Caddy brought a much needed paradigm shift in web server space, it is an incredible piece of technology. I have moved all my servers from NGINX to Caddy for the pass few years and I couldn't be happier. Also, I would like to give a shoutout to the team behind Caddy. They have been nothing but great about constantly shipping updates and being incredibly helpful in their community forum.
- rekoil 3y agoCaddy is amazing, but on production machines remember to disable the unauthenticated and enabled by default JSON-based admin API bound to localhost:2019, as it can be a serious security risk in certain deployments. Put the following in your Caddyfile at the lowest scope to disable it: { admin off }
- executesorder66 3y agoAlternatively don't serve your site over HTTP at all. Just redirect to HTTPS. Edit, I just checked the Caddyfile for one of my sites. There is no config for redirecting HTTP to HTTPS is does it automatically. So this is entirely unnecessary.
- rekoil 3y agoNo what I'm talking about here is the unauthenticated JSON-based configuration API that hosts itself on port 2019 on localhost of the machine that runs Caddy. This is unrelated to sites hosted using HTTP. I was clumsily using the term "HTTP" to refer to the fact that this configuration mechanism is based on HTTP-communication.
- executesorder66 3y agoSo if I understand this correctly, anyone can bring down a site with a Caddy server by just running : curl -X POST "https://example.com:2019/stop https://example.com:2019/stop" ? [0] Seems counter to their objective of having secure defaults. [0] https://caddyserver.com/docs/api#post-stop https://caddyserver.com/docs/api#post-stop
- ttyyzz 3y agoI love Caddy, using it as a Reverse proxy (even in docker) is so nice and easy. All you need is 2 lines of config: :2080 reverse_proxy :9000
- dizhn 3y agoFree certs is also just a one line "email myemail@example.com". This applies to all sites and everything is auto managed. It also has a nice one line shortcut directive which applies to the vast majority of php sites out there.
- francislavoie 3y agoActually, you don't even need the email for certificate automation. You only need to give Caddy a valid public domain as your site address.
- dizhn 3y agoGreat. Either something changed, or I took something optional as required when I started using it. (Or perhaps one of the cert providers needs it while the other doesn't?) Good to know anyway. Cheers. Here's some older instructions for zerossl where email seems to be necessary. (https://caddy.community/t/using-zerossls-acme-endpoint/9406 https://caddy.community/t/using-zerossls-acme-endpoint/9406)
- ilyt 3y agoIf you just need that you don't really need reverse proxy in the first place...
- poorlyknit 3y agoThis way the app doesn't have to handle HTTPS though.
- ilyt 3y agoBut you have 2 apps running instead of one. There are already apps (and libs for them) to built-in the letsencrypt directly into the app. Sure if it is a 3rd party app, but if you're writing one just adding it to your app and simplifying everything around it is worth compared to adding additional component to deploy
- deleted 3y ago[deleted]
- melx 3y agoI did benchmark it against nginx and found Caddy to be 5-7x times slower, but like all benchmarks go...results are subject to ones requirements (or mistakes). What got me away from using it: - the directives feel intuitive but as soon as I needed a complex config it all became a chain of very implicit strings - the caddy author(s) decided few years ago to add custom http header with their sponsors[0]. That header could not be removed, it's no longer present in current Caddy but the bad taste still remains. [0] https://news.ycombinator.com/item?id=15238315 https://news.ycombinator.com/item?id=15238315
- j-a-a-p 3y ago> it's no longer present in current Caddy but the bad taste still remains Adding a sponsor header is harmless (albeit useless IMO). For me that would be no reason to not choosing this software, and certainly no ground for having a 'bad taste'.
- rekoil 3y agoWhat purpose does it actually fulfil? Who is actually looking at individual HTTP requests like this? All it does is take up extra traffic... It's also a security risk if your web server is the only one doing it, as it is a way for an attacker to fingerprint the web server software in use. I understand and agree with melx's view here completely, even if I do feel Caddy's strengths outweigh it's weaknesses.
- user3939382 3y ago> Who is looking devs presumably
- mholt 3y agoWhich is exactly the audience we were targeting. I thought it was a good idea at the time. ¯\_(ツ)_/¯
- 3y ago
- KronisLV 3y agoCaddy seems to be continuously getting better and I think mholt occasionally hangs around here and is a rather pleasant person. I recall once needing to help a new person in another team setup TLS after they had tried to do it unsuccessfully themselves in some configuration (that might have had a networking setup where HTTP-01 for ACME doesn't work, actually). I just started recording my desktop, grabbed a server from Hetzner live and thanks to Caddy could give them an example of how things should work with all of the steps in like 5 minutes total. Nowadays I use Apache (mod_md) for my personal needs due to some plugins I need, it actually makes me wonder why Nginx doesn't seem to have integrated support for ACME yet, even if certbot is serviceable too. Either way, props to Caddy for raising the bar for web servers.
- yakubin 3y agoI like Caddy, mainly for the ease of configuration. One thing that surprised me though: by default it has compression disabled. I discovered it 1 year after moving from nginx (with the nginx config having compression enabled) and it was funny, because at the time of migration I got comparable performance out of the two. Obviously, after enabling compression, it’s faster now.
- mholt 3y agoWe don't enable compression by default because we leave it up to the site owner to decide whether to optimize for network efficiency or CPU efficiency. (Also, disabling implicit things is more tedious and confusing than enabling things.) Glad to hear you use Caddy! :)
- francislavoie 3y agoTo add onto mholt's reply, we avoid implicitly enabled functionality where possible (the only feature that's implicitly enabled generally is Automatic HTTPS, off the top of my head). By default, Caddy's HTTP handlers do nothing which is good because it gives you a clean slate to build on top of. If you had to turn off features to reset back to zero, that's cruft. For example, think of CSS resets, which are needed to turn off styles added by browsers by default; that's annoying and a complication that all websites need to deal with to get consistent behaviour.
- kasdi 3y agoGreat approach. User agent default style sheets are the worst, especially since they are all different. But, instead of handing the user a empty slate with nothing, it should contain a note saying “look, these are the recommended options”. If the initial config is interactive, it could even prompt to activate them: “want to use compression?” - “yes”, etc.
- francislavoie 3y agoThose recommendations are in the documentation. Interactive configuration is easier said than done. We don't realistically have the time to build and maintain that on top of the core program and config. We're already stretched pretty thin.
- trinovantes 3y agoI'm currently reverse proxying a few docker containers with nginx. Caddy seems tempting but one dealbreaker I can't find in the docs is whether or not it automatically refreshes its DNS cache if a docker container restarts and changes its IP address? e.g. In nginx, I use "resolver 127.0.0.11 valid=30s" so "proxy_pass {container}:80" will only cache the {container}'s IP address for 30s
- avianlyric 3y agoFrom my experience I’ve not had any issues with Caddy using stale DNS entries when proxying Docker containers. From the forums it looks like Caddy doesn’t explicitly define any DNS behaviour, it relies on Golangs defaults, which in turn simply uses whatever the host provides. I.e. whatever IP your host DNS resolution returns is used, and Caddy doesn’t cache internally, it relies on your hosts DNS cache. It’s reasonable to assume that any modern OS respects DNS TTL, and for something like Docker it’s gonna be doing a lookup on every request (which should be pretty much instant, as everything is on the same machine). https://caddy.community/t/proxy-dns-resolver-mechanism/5934 https://caddy.community/t/proxy-dns-resolver-mechanism/5934 https://stackoverflow.com/questions/40251727/does-go-cache-dns-lookups#40252460 https://stackoverflow.com/questions/40251727/does-go-cache-d...
- trinovantes 3y agoPerfect, that's exactly what I'm looking for
- piaste 3y agoIf you want a slightly heavier but more robust solution, caddy-docker-proxy[0] is a plugin that listens to the Docker socket and automatically updates the Caddy configuration based on Docker labels you add to containers. I.e. it makes Caddy act a bit more like Traefik. Most of the time, you'll just add the label `caddy.reverse_proxy={{upstreams http 8080}}` to your containers and the plugin will regenerate Caddy's configuration whenever the container is modified. [0] https://github.com/lucaslorentz/caddy-docker-proxy https://github.com/lucaslorentz/caddy-docker-proxy
- dxuh 3y agoI'm always a bit bothered by them saying they are the "only" web server that can do this. First you can also just configure it in a way where it will not use HTTPS (e.g. if you provide an IP:port instead of a hostname). And if you do require specific configuration to enable HTTPS and automatically get certificates via ACME, then lots of other web servers can do this too. Even my own web server can do it: https://github.com/pfirsich/htcpp https://github.com/pfirsich/htcpp (see https://github.com/pfirsich/htcpp/blob/main/configs/acme.joml https://github.com/pfirsich/htcpp/blob/main/configs/acme.jom... for an admittedly much more complicated config).
- mholt 3y ago> if you provide an IP:port instead of a hostname That still gets served over HTTPS. The only time HTTPS isn't used is if a host portion is missing entirely (IP or name).
- francislavoie 3y agoThe distinction is that Caddy is the only webserver* that enables HTTPS by default. All others don't attempt to enable HTTPS by default, they start with HTTP and you need to add config to make it use HTTPS. Nor do they enable ACME by default. With Caddy you only need to tell it your domain name and it'll do the rest. * popular webserver anyway; we can't reasonably count yours with only 6 github stars that we've never heard of :P
- fouc 3y agoCaddy was the first to default to https.. because it was new. Nothing special about that.
- melx 3y agoI think you meant the Let's Encrypt was new. They started on November 18, 2014, and Caddy's first release was on 28 April 2015.
- yencabulator 3y agoBecause Caddy was new.
- francislavoie 3y agoIt's still the only popular webserver to default to HTTPS. Others default to HTTP first, and require you to add more config to enable HTTPS.
- lessname 3y agoHow does Caddy compare to Nginx Unit? Is the API easier to use?
- pm3003 3y agoYou can feed it JSON. I use the Caddyfile, but I found the documentation well done.
- teekert 3y agoI love caddy, I used to litter my docker-compose.yaml files with Traefik labels like: labels: - traefik.enable=true - traefik.http.routers.foundryvtt-http.entrypoints=web - traefik.http.routers.foundryvtt-http.rule=Host(`vtt.xxx.nl`) - traefik.http.routers.foundryvtt-http.middlewares=foundryvtt-https - traefik.http.middlewares.foundryvtt-https.redirectscheme.scheme=https - traefik.http.routers.foundryvtt.middlewares=foundryvtt-auth - traefik.http.middlewares.foundryvtt-auth.basicauth.users=${foundryvtt-BASIC_AUTH} - traefik.http.routers.foundryvtt.entrypoints=websecure - traefik.http.routers.foundryvtt.rule=Host(`vtt.xxx.nl`) - traefik.http.routers.foundryvtt.tls=true - traefik.http.routers.foundryvtt.tls.certresolver=mytlschallenge - traefik.http.services.foundryvtt.loadbalancer.server.port=30000 Now I just add the containers (by name), no labels, and map Caddy to their port, like so (in the Caddyfile): data.xxx.com { reverse_proxy projectsend:80 } or, this snippet refers to a WordPress container with BasicAuth in front of it: restricted.xxxx.com { root * /var/www/html/restricted.xxxx.com/wordpress php_fastcgi wordpress-xxxx-restricted:9000 { root /var/www/html } basicauth /* { xxx $xx$x05xxxxxxxxx.xx } file_server } Here's just an index.html (from Hugo in this case) in some dir: blog.xxx.nl { # Set this path to your site's directory. root * /var/www/html/blog.xxx.nl # Enable the static file server. file_server } I love the simplicity.
- ilyt 3y agoThat says more about shitty trend of using labels as a config than anything else. 12 factor app did untold damage to the industry convincing smart-but-inexperienced developers that key-value-only systems are somehow good way to configure anything more complex than "this app needs server, password and user"
- teekert 3y agoWell, apart from the labels, I'm also happy I got rid of that middleware stuff that I still don't fully understand. I mean, I want https, and I want it in front of my standard docker container that listens on some random port. Caddy requires me to enter only exactly what I need, no more (container name and port and required function (rev-proxy), 2 lines, boom).
- TigerTeamX 3y agoI love Cadd and I have been using it for a few years now. The documentation is kinda crap, but I still use less time to get things done. Most projects are just copy/paste of old config files. Everytime I had a problem, I asked and got an answer within 2 days. And nice answers, not like Stackoverflow...
- mholt 3y agoThat's because Francis, Mohammed, Matthew, and our other helpers are awesome. They are volunteers and do it because they like to help and find the project interesting. Thanks for being a part of the community
- francislavoie 3y agoThanks for the kind words. > The documentation is kinda crap We continually get comments like this, but we rarely get elaboration on why people think this. Please explain what you mean. What's crap about it? We spend a lot of time improving the docs, and without specific feedback we're surprised to hear this.
- mooreds 3y agoBig fan of caddy. We use it internally and our company provides financial support to the developers.
- mholt 3y agoFusionAuth is awesome :D Thank you for your sponsorship!!
- asimops 3y agoThe thing I am missing the most is some kind of HTTP-01 by proxy, like https://github.com/acmesh-official/acme.sh/wiki/Stateless-Mode https://github.com/acmesh-official/acme.sh/wiki/Stateless-Mo... If DNS-01 is not an option or to complicated, this saves you from exposing a host to the internet for no good reason.
- mholt 3y agoI'm a little wary of copying things from acme.sh after I discovered a 0-day RCE in it. Could you open an issue to discuss your requirements? We'll take a look at solutions.
- hackerbrother 3y agoEasiest way to use HTTP/3!!
- TimCTRL 3y ago>All hostnames (domain names) qualify for fully-managed certificates if they: -are non-empty -consist only of alphanumerics, hyphens, dots, and wildcard (*) -do not start or end with a dot (RFC 1034) Someone help me understand this part...didn't know this
- francislavoie 3y agoI'm not sure I understand the question. What's unclear exactly?
- coldblues 3y agoThe most hassle free way to reverse proxy with Docker. I love it.
- supz_k 3y agoJust a personal experience. About 6 months ago, we moved from NGINX to Caddy on our web app, which handled about 300 million HTTP requests per month at that time (2 web servers, so about 150 million each) CPU Usage: with NGINX - 15-20% with Caddy - 70-80% I tried multiple tweaks but nothing helped to get NGINX-level performance. So, after a few weeks, we migrated back to NGINX. That being said, I still absolutely love Caddy and use it in a few small scale apps. - The DX it provides is amazing. - Creating a PHP-FPM reverse proxy is just a couple of lines. - Generating SSL certificates on the server is a breeze. With NGINX, you have to mess with other software like certbot. - It just works :)
- BitPirate 3y agoHave you used caddy with HTTP/3? The quic-go version shipped with v2.6.0 wasn't tuned for optimal performance.
- rob74 3y agoWell yeah, NGINX is a highly optimized C application, whereas Caddy is written in Go, so it would be unfair to expect NGINX-level performance. Caddy is more modern and has more helpful features (that are easier to implement thanks to Go), but performance-wise... OTOH, if you use NGINX to serve a PHP or Node app, Caddy serving a Go app should be competitive ;)
- rcme 3y agoIt’s definitely fair to expect performance to be within one order of magnitude. 4 is really unreasonable.
- k_bx 3y agoJust curious. I use Ubuntu on my servers (as many do) and I deploy everything as standard Systemd service (even my apps). However, when I wanted to try out Caddy, I realized they don't provide you with one, so you have to write your own scripts putting systemd config files, enabling the service etc. Is this what everyone does these days? Seemed kinda strange for mainstream software.
- __jonas 3y agoBut they do provide systemd unit files: https://caddyserver.com/docs/running#unit-files https://caddyserver.com/docs/running#unit-files Or are you saying they should be included with the download?
- k_bx 3y agoIt's just so strange. They provide two systemd files, you need to choose one, edit (!) it, put on the machine etc. Comparing with nginx's boring apt-get install that does the right thing this feels like non-mature way to distribute things. Especially for people who script and document all of their server setup procedures.
- ripley12 3y agoTake a look at the Debian/Ubuntu install instructions. “Installing this package automatically starts and runs Caddy as a systemd service” https://caddyserver.com/docs/install#debian-ubuntu-raspbian https://caddyserver.com/docs/install#debian-ubuntu-raspbian
- k_bx 3y agoAll right, totally missed it then, thank you
- yjftsjthsd-h 3y agoThat's really more of a packaged/non-packaged thing, though, isn't it? Like, I once installed caddy on a CentOS (RIP) system by running `yum install caddy` and that did give me the right systemd config out of the box, which I wouldn't expect to get from a out-of-tree binary I just plopped on the system.
- hn92726819 3y agoCaddy is great. My only complaint is they insist on sending a: Server: caddy Header that is impossible to turn off since it's hardcoded here: https://github.com/caddyserver/caddy/blob/master/modules/caddyhttp/server.go#L260 https://github.com/caddyserver/caddy/blob/master/modules/cad... The developer's annoying response is "it doesnt improve privacy or security, so we won't give you the option to remove it".
- mholt 3y agoIt's not impossible to turn off. NGINX does this too, but you have to recompile NGINX to disable that header. With Caddy, you just need: header -Server in your config.
- hn92726819 3y agoThis doesnt work for http redirects to https. I couldn't find any way to disable the server header in those responses without patching.
- Freaky 3y agoThey insist on adding it to the standard response path, but they're happy for you to remove it: header -Server However as this isn't global configuration it'll tend to pop back up in implicit configs like HTTP redirects and error handling if not overridden.
- hn92726819 3y agoIs it possible to disable it on http redirects? I haven't found any way to do that
- lagniappe 3y agoMaybe first but not the only! https://github.com/donuts-are-good/appserve https://github.com/donuts-are-good/appserve
- mholt 3y agoJust curious, why use autocert instead of CertMagic?
- lagniappe 3y agoIt's what I was familiar with, and it works great. That doesn't mean I can't be swayed by something better though. What features make you choose certmagic over autocert?
- mholt 3y agoMakes sense -- I will often go for what I'm familiar with, too. Aside from creating CertMagic, I think CertMagic has a few benefits over autocert. It is designed to scale to thousands of certificates. It will staple OCSP for you automatically. It can obtain certificates "on demand" during handshakes. It is more robust to failures and can keep sites up even when other ACME libs let you down. CertMagic supports all challenge types; I think autocert only does TLS-ALPN challenge, which requires port 443. There's a lot of other improvements and enhancements that autocert is lacking IMO. A scan of the readme should help illustrate: https://pkg.go.dev/github.com/caddyserver/certmagic#section-readme https://pkg.go.dev/github.com/caddyserver/certmagic#section-... But I guess use what works for you!
- lagniappe 3y agoNothing wrong with another tool in my chest, I'll give it a shot! Thanks for the referral.
- francislavoie 3y agoOnly popular though! We can't reasonably consider projects with only 8 github stars as part of marketing statements.
- bsndev 3y ago[dead]