9 ms·
Why is everyone so hyped about caddy, I don't get it
by jtovarys 3y ago
Why is everyone so hyped about caddy, I don't get it
- jiyinyiyong 3y agoI use it to setup local development env with self signed HTTPS support. Easier than using Nginx Webpack combined.
- davidcollantes 3y agoA single drop in binary of a web server with powerful features, highly extensible. I am not hyped, I just find it very handy.
- yjftsjthsd-h 3y agoIts killer feature is simplicity. The biggest thing is automatic HTTPS without having to install/configure anything but the base server, but even configuration is easier than other options.
- KronisLV 3y ago> The biggest thing is automatic HTTPS without having to install/configure anything but the base server, but even configuration is easier than other options. I largely agree with this, but it's not like there's a huge gap between Caddy and Apache with mod_md (https://httpd.apache.org/docs/2.4/mod/mod_md.html https://httpd.apache.org/docs/2.4/mod/mod_md.html) or even Nginx with certbot (https://www.digitalocean.com/community/tutorials/how-to-secure-nginx-with-let-s-encrypt-on-ubuntu-22-04 https://www.digitalocean.com/community/tutorials/how-to-secu...), at least for HTTP-01 challenges. Personally I think that Caddy v1 configuration was a little bit nicer than the current versions, but honestly it's a cool web server and I see its popularity continuing to rise in the future!
- theteapot 3y agoAre you using Apache as a reverse proxy with SSL in front of containers?
- KronisLV 3y agoYep, sometimes, when I'm not using Kubernetes with a Traefik or Nginx ingress. That's actually how most of my personal and homelab stuff runs, with Docker Swarm due to how lightweight and simple it is. There, Apache actually works better for me since if I have 10 different domains configured and only 9 resolve (e.g. containers not running yet) then something like Nginx would complain about a non existent domain and crash the whole thing, whereas Apache would serve the 9 other domains and eventually proxy the 10th as well, instead of just returning an error. I did tune Apache a little bit, in that I disabled .htaccess to avoid too much I/O (now the config is more like nginx.conf), though also sometimes add other modules, like mod_security (simple WAF) or mod_auth_openidc (Relying Party, so using OIDC wouldn't make me insane), as well as PHP-FPM if I ever need PHP in a particular container. Nginx is still better for serving static files in general (e.g. packaged SPA), Traefik for HTTPS, but Apache is generally okay at most things.
- mhitza 3y agoA few years ago I tweaked an Apache config to the most minimal set of modules and configs that I needed for my project. I considered this module as well, however it couldn't use the certificate when issued/renewed without a restart[1]. Based on the current docs, that still seems to be the case. Whereas with Caddy, and other software that (I assume) use the same underlying libraries, like gotosocial, I start the service and it does it all. I'm still an Apache/nginx user, but certificates that require no configuration are the selling point of Caddy for me (and I use it on two very small projects because of that). [1] Which meant that I had to write some sort of automation that detected the reissue and restart Apache (and set up appropriate systemd service/timers, limited user permissions to only allow passwordless restart, etc). In the end I kept certbot (which I wanted to get rid off) and let it manage the certificate (DNS challenge) and Apache restart. I'm open to a suggestion on how this can be done in a minimal way and requiring no supervision after.
- KronisLV 3y agoFor my own needs, I did something a bit naughty: scheduled restarts, since in my particular use case a dozen seconds of downtime here or there don't really matter. For something more precise, there is MDMessageCmd (e.g. listen for "renewed" and trigger reload; probably a short Bash script). Reload instead of restart should also be less disruptive.
- mhitza 3y agoThe automatic restart could definitely work (since graceful is enough and doesn't cause downtime). Though it's better if unnecessary stuff isn't done on the server. The other option with MDMessageCmd, would require (on a SELinux distro) to grant Apache command exec permissions, among other tweaks. What would be better in this case were if Apache could message via DBus these events and I could make a dbus service that listens and restarts accordingly (better execution isolation). If Apache would do internally the certificate swap, now that would be perfect.
- francislavoie 3y ago> Personally I think that Caddy v1 configuration was a little bit nicer than the current versions In what way? Caddy v1 config was very inflexible, so there were lots of things that were simply impossible to do with it. I think we struck a good balance of simplicity to expressiveness.
- yjftsjthsd-h 3y agoBeing less flexible often makes simpler things simpler even as it makes hard things harder.
- francislavoie 3y agoSure, but what's harder? I'm looking for examples.
- yjftsjthsd-h 3y ago> mod_md That actually does look like it'll be reasonable, but 1. it still requires that the user figure out how to enable mod_md and add the config to enable it, and 2. it's currently labeled "Status: Experimental", which https://httpd.apache.org/docs/2.4/mod/module-dict.html#Status https://httpd.apache.org/docs/2.4/mod/module-dict.html#Statu... describes as > "Experimental" status indicates that the module is available as part of the Apache kit, but you are on your own if you try to use it. The module is being documented for completeness, and is not necessarily supported. so it seems more like something that will eventually become a good alternative. > Nginx with certbot I'm fine with certbot, but there's a world of difference between "install this web server and tell it your URL starts with https:// https://" vs "install the web server, install this other package, read the docs to configure the other package or run the setup script and follow the prompts".
- theteapot 3y ago> The biggest thing is automatic HTTPS ... Traefik has that.
- mholt 3y agoNot as good though. Case in point: https://github.com/traefik/traefik/issues/5472#issuecomment-1966563229 https://github.com/traefik/traefik/issues/5472#issuecomment-... (that's just from this morning) I'm speak objectively here. Of course, any built-in auto HTTPS that works (more or less) is better than none. Traefik uses an ACME library that was originally written for Caddy. After the original author left that project, Traefik team started maintaining it. Caddy's users' requirements exceeded what the library was capable of, but unfortunately there was friction in getting it to achieve our requirements. So I ended up writing a new ACME client library in Go and, together with upgrades in CertMagic (Caddy's auto-TLS lib), Caddy has the more flexible, robust, and capable auto-HTTPS functionality. That is to say, not all auto-HTTPS functionalities are the same.
- bosch_mind 3y agoWriting Go > Lua and C for extensibility these days
- jurajmasar 3y agoit's simple. convention over configuration. there's a lot to like
- deleted 3y ago[deleted]
- ailurooo 3y agoit's a memory safe web server with alot of sane defaults. When comparing apache, nginx, and caddy configs. Caddy's are alot more terse and have alot of settings turned on by default that make sense, but can be further customized.