7 ms·
Deploying Web Apps with Caddy: A Beginner's Guide Caddy
- jtovarys 3y agoWhy is everyone so hyped about caddy, I don't get it
- jiyinyiyong 3y agoI use it to setup local development env with self signed HTTPS support. Easier than using Nginx Webpack combined.
- davidcollantes 3y agoA single drop in binary of a web server with powerful features, highly extensible. I am not hyped, I just find it very handy.
- yjftsjthsd-h 3y agoIts killer feature is simplicity. The biggest thing is automatic HTTPS without having to install/configure anything but the base server, but even configuration is easier than other options.
- KronisLV 3y ago> The biggest thing is automatic HTTPS without having to install/configure anything but the base server, but even configuration is easier than other options. I largely agree with this, but it's not like there's a huge gap between Caddy and Apache with mod_md (https://httpd.apache.org/docs/2.4/mod/mod_md.html https://httpd.apache.org/docs/2.4/mod/mod_md.html) or even Nginx with certbot (https://www.digitalocean.com/community/tutorials/how-to-secure-nginx-with-let-s-encrypt-on-ubuntu-22-04 https://www.digitalocean.com/community/tutorials/how-to-secu...), at least for HTTP-01 challenges. Personally I think that Caddy v1 configuration was a little bit nicer than the current versions, but honestly it's a cool web server and I see its popularity continuing to rise in the future!
- theteapot 3y agoAre you using Apache as a reverse proxy with SSL in front of containers?
- KronisLV 3y agoYep, sometimes, when I'm not using Kubernetes with a Traefik or Nginx ingress. That's actually how most of my personal and homelab stuff runs, with Docker Swarm due to how lightweight and simple it is. There, Apache actually works better for me since if I have 10 different domains configured and only 9 resolve (e.g. containers not running yet) then something like Nginx would complain about a non existent domain and crash the whole thing, whereas Apache would serve the 9 other domains and eventually proxy the 10th as well, instead of just returning an error. I did tune Apache a little bit, in that I disabled .htaccess to avoid too much I/O (now the config is more like nginx.conf), though also sometimes add other modules, like mod_security (simple WAF) or mod_auth_openidc (Relying Party, so using OIDC wouldn't make me insane), as well as PHP-FPM if I ever need PHP in a particular container. Nginx is still better for serving static files in general (e.g. packaged SPA), Traefik for HTTPS, but Apache is generally okay at most things.
- mhitza 3y agoA few years ago I tweaked an Apache config to the most minimal set of modules and configs that I needed for my project. I considered this module as well, however it couldn't use the certificate when issued/renewed without a restart[1]. Based on the current docs, that still seems to be the case. Whereas with Caddy, and other software that (I assume) use the same underlying libraries, like gotosocial, I start the service and it does it all. I'm still an Apache/nginx user, but certificates that require no configuration are the selling point of Caddy for me (and I use it on two very small projects because of that). [1] Which meant that I had to write some sort of automation that detected the reissue and restart Apache (and set up appropriate systemd service/timers, limited user permissions to only allow passwordless restart, etc). In the end I kept certbot (which I wanted to get rid off) and let it manage the certificate (DNS challenge) and Apache restart. I'm open to a suggestion on how this can be done in a minimal way and requiring no supervision after.
- theteapot 3y ago> The biggest thing is automatic HTTPS ... Traefik has that.
- mholt 3y agoNot as good though. Case in point: https://github.com/traefik/traefik/issues/5472#issuecomment-1966563229 https://github.com/traefik/traefik/issues/5472#issuecomment-... (that's just from this morning) I'm speak objectively here. Of course, any built-in auto HTTPS that works (more or less) is better than none. Traefik uses an ACME library that was originally written for Caddy. After the original author left that project, Traefik team started maintaining it. Caddy's users' requirements exceeded what the library was capable of, but unfortunately there was friction in getting it to achieve our requirements. So I ended up writing a new ACME client library in Go and, together with upgrades in CertMagic (Caddy's auto-TLS lib), Caddy has the more flexible, robust, and capable auto-HTTPS functionality. That is to say, not all auto-HTTPS functionalities are the same.
- bosch_mind 3y agoWriting Go > Lua and C for extensibility these days
- jurajmasar 3y agoit's simple. convention over configuration. there's a lot to like
- deleted 3y ago[deleted]
- ailurooo 3y agoit's a memory safe web server with alot of sane defaults. When comparing apache, nginx, and caddy configs. Caddy's are alot more terse and have alot of settings turned on by default that make sense, but can be further customized.
- no_wizard 3y agoCaddy is a wonderful alternative for nginx for small / medium sized projects I've worked with it on. Mid market enterprise is where I have seen alot of Caddy uptick as of late. nginx has a ton of inertia, but Caddy is a welcome player. I highly recommend anyone into this sort of thing give it a try. The configuration is so easy by comparison and its handling of HTTPS certs automatically is a huge win. I feel its a leap forward from the typical Apache / nginx setup to me nowadays
- drcongo 3y agoAgree with all of this - Caddy is a great project.
- bklyn11201 3y agoCaddy is indeed wonderful for straightforward and simple projects. There are a number of complex configurations used by larger organizations that are well served today by Nginx Plus, HAProxy, and Traefik that don't seem possible with Caddy. And it's difficult to get a sense of whether the Caddy developers are interested in meeting those more complex use cases or whether they want to keep Caddy smaller and simpler. But yes, by all means, for a simple project pick Caddy!
- bosch_mind 3y agoCan you speak more to usecases that aren’t fulfilled by Caddy? Also, any ideas if performance matches NGINX at scale?
- mholt 3y agoCaddy is more capable and extensible than all those servers, even out of the box. Example: https://github.com/traefik/traefik/issues/5472#issuecomment-1966563229 https://github.com/traefik/traefik/issues/5472#issuecomment-... > welcome to 2024. it is shame that traefik cannot handle functionality which can be handled by caddy2. (posted this morning) Anyway, we already do walk up to quite a few complex requirements in large enterprise deployments. Happy to hear about your use case that isn't possible!
- latifk 3y agoOne thing I miss in Caddy is something like Nginx-unit to avoid the need of setting up application server.
- mholt 3y agoDepending on the application you can already do this. For example: https://frankenphp.dev/ https://frankenphp.dev/
- zoidb 3y agoCaddy is great and it's configuration is such a breath of fresh air compared to other web servers. As a little self plug I wrote about some cool things you can do with only using caddy config https://jarv.org/posts/cool-caddy-config-tricks/ https://jarv.org/posts/cool-caddy-config-tricks/
- rob-olmos 3y agoRecent question I haven't look much into yet: Is there a way to limit the number of simultaneous http2/3 streams from an IP address with Caddy?
- mholt 3y agoYou can rate limit HTTP requests (agnostic of specific HTTP versions): https://github.com/mholt/caddy-ratelimit https://github.com/mholt/caddy-ratelimit
- mmh0000 3y agoI love caddy. Most recently, I used it for a small personal project where I wanted to be able to upload files via Webdav and serve them out over HTTPS. I can't believe how small the configuration for this setup is. Especially if you compare it to something like Apache: ``` { order webdav before file_server log { level DEBUG } } files.example.org { log { output stdout format json } @notget { not method GET } root * /srv/ssftp route @notget { basicauth { bob $2y$10$f/asdasd.asdsadasd.asdasdasd } webdav } file_server browse } ``` The integrated LetsEncrypt support makes life so much easier than a comparable setup with apache or nginx.
- RandomWorker 3y agoI’m so confused by these things, setting up a Linux box with nginx isn’t that hard. It takes maybe a day to do, and while doing it you really understand better how your server works. The first time might take you 5 days to go through some tutorials, but generally after that it’s less than 1 day of work. For me personally I really want to know what is going on in each folder and keep track of new folders, files etc. It’s maybe my paranoia of hacking. Context; when I was a kid I hacked so many things and knowing where the files are kept and hiding them is a key part of hacking. Therefore it’s always been a priority for me to check in regularly see what’s happening.
- amanzi 3y agoThe main benefit for me is the integrated SSL certificate generation without needing to configure separate certificate infrastructure or Letsencrypt/acme. Also, Caddy implements a number of best practices by default without needing to specifically configure them, e.g. redirecting HTTP to HTTPS. I do still manage a couple of fairly complex Nginx configurations, and I don't really see any benefit to retrofitting Caddy into that kind of scenario. But for a new deployment, I'll almost always reach for Caddy in the first instance.
- mholt 3y agoYes! The best part of: > without needing to configure separate certificate infrastructure or Letsencrypt/acme. is not only that your deployment is simpler, it also scales better and is more robust to failures. It can tolerate external factors more robustly.
- frankjr 3y agoCaddy is great and to my surprise it's actually very competitive with nginx in terms of performance, sometimes even faster. https://blog.tjll.net/reverse-proxy-hot-dog-eating-contest-caddy-vs-nginx https://blog.tjll.net/reverse-proxy-hot-dog-eating-contest-c... https://news.ycombinator.com/item?id=32865497 https://news.ycombinator.com/item?id=32865497
- k_bx 3y agoInstalling Docker to run a web server is crazy to me.
- amanzi 3y agoSeems unnecessary to me - I would only consider running Caddy in Docker if the web application it was serving was also in Docker. Installing Caddy without Docker is pretty straight-forward - I have a basic Ansible playbook that does this with just 5 tasks.
- francislavoie 3y agoYep, I agree, only need to run Caddy in Docker if you're planning to use Docker for things Caddy will serve. Our docs cover many installation methods, most commonly used is our apt or rpm repos, which run Caddy as a systemd service. See https://caddyserver.com/docs/install https://caddyserver.com/docs/install
- Rebelgecko 3y agoOke thing I really like about caddy is that it's super easy to use it to expose a bunch of docker-compose services to the Internet, with HTTPS, compression, and all that jazz. It helps avoid weird stuff I've ran into with other web servers like "oh, this nginx feature requires you import some random dudes packages because the official version doesn't enable it, and if the random dude and the official package versions ever diverge everything breaks"
- deleted 3y ago[deleted]
- ks2048 3y agoI often read Caddy is nice for smaller projects, but to use nginx for high performance. What kind of magic is nginx doing that is so hard for others to replicate? (I’m interested in the simple case of serving static files - nothing fancy) Edit: I just saw the other post here saying it may be as good as nginx.
- mholt 3y agoCaddy is written in Go, which is fast enough for Google, Netflix, Stripe, and many others. It even has higher memory safety than nginx, which is written in C.
- account-5 3y agoI'm a beginner, but clearly too much of a beginner for this beginner guide. Went to it expecting a guide on how to set up a caddy webserver, spent most of the time reading about how to use docker. I just want to be able to set up a server to server html/CSS/JavaScript easily, and securely. Not edit yaml files and run containers locally.
- avtar 3y agoThe Caddy project has a section in their docs for serving static assets: https://caddyserver.com/docs/quick-starts/static-files https://caddyserver.com/docs/quick-starts/static-files
- nurettin 3y agoapache's way of enabling/disabling sites, certbot plugin, access management and directory sharing stuck with me for the past 20 years. So much so that it feels like caddy has nothing to offer. Certbot already has a timer on ubuntu, so all I really need to do is run certbot --apache and enter a number.