4 ms·
Caddy is the greatest thing since sliced bread. It is such a good reverse proxy and a paradigm-shifter for its auto-certificates and HTTP/3 support. It's a grea
by hackerbrother 2y ago
Caddy is the greatest thing since sliced bread. It is such a good reverse proxy and a paradigm-shifter for its auto-certificates and HTTP/3 support. It's a great example of how high quality Go software can be. (Thank you Matt Holt)
- bigyikes 2y agoI still have nightmares about trying to set up SSL with nginx and my own self-managed certificates. I set the same thing up with Caddy in minutes and it’s been running flawlessly for years. Shoutout to Let’s Encrypt as well for making this so much easier!
- KronisLV 2y ago> I still have nightmares about trying to set up SSL with nginx and my own self-managed certificates. For anyone who needs to run their own CA (which I'm now doing for my homelab), I've found that using GUI software like KeyStore explorer is a sufficiently easy and lazy way of doing that, which actually works well, both for securing regular sites, as well as doing mTLS: https://keystore-explorer.org/ https://keystore-explorer.org/ For what it's worth, using OpenSSL directly and automating that for more frequently rotated certificates wouldn't be quite as pleasant, yet doable. > Shoutout to Let’s Encrypt as well for making this so much easier! For ACME stuff, Caddy will be excellent and honestly is probably the best option out there right now! Nginx (and certbot) or Apache (and mod_md or certbot) will get you most of the way there as well, though the route will be a bit longer.
- francislavoie 2y agoCaddy comes with Smallstep, it can be your CA too. Caddy is both and ACME client and ACME server.
- sbstp 2y agoCaddy is amazingly simple to setup. Automatic HTTPS is a killer feature. I have to use Envoy at work for gRPC services and I want to quit the industry every time I have to edit their YAML/protobuf monstrosity of a config system.
- bb1234 2y agoMy websites run on https because how easy Caddy makes it. Caddy made it possible for me. Cannot thank Matt Holt enough for creating Caddy and making it available to all of us.
- DEADMINCE 2y agoI haven't used Caddy and I'm sure it's great, but you could have used nginx or anything else as well also. Offering https is honestly pretty easy these days.
- mholt 2y agoThousands of Caddy users beg to differ -- nginx won't scale HTTPS automation as well as Caddy can.
- ngrilly 2y agoI've been using nginx for years and switched to Caddy just because I was so fed up with configuring nginx to automatically renew TLS certs issued by Let's Encrypt. This is so much easier and reliable with Caddy.
- influx 2y agoI recently found certbot and it makes TLS with nginx a breeze. I like Caddy as well, but if you're forced to use nginx, try certbot!
- pbreit 2y agoIn layperson's terms, what is the difference between a "reverse proxy" and a "web server"?
- francislavoie 2y agoReverse proxying is just one task that a web server can perform. Caddy also has a file server (directly serving files from disk or from some virtual filesystem), can write static responses, can directly execute code via plugins like FrankenPHP, can manipulate/rewrite/filter/route the request and/or response, etc. Just look at this list https://caddyserver.com/features https://caddyserver.com/features
- tcmart14 2y agoIn simple terms, you can think of a reverse proxy as an http server that is a middle man. For a simple case why you might use one. SSL/TLS can be a pain to set up in your web application code. So what you can do is write your web application and not worry about SSL/TLS certs. Then you can place a reverse proxy infront of it and configure the reverse proxy for SSL/TLS. This way your not dealing with that complexity in your code and someone else is managing it. From there, the reverse proxy takes requests and reroute them to your web application. My reverse proxy is exposed to the internet on port 443, when a packet hits it, it knows to rereoute the traffic to server running on my machine at localhost port 8080. You can also have a reverse proxy to have one singular ingress point for many web applications. The reverse proxy will know that requests for http://MyCoolWebApp.com http://MyCoolWebApp.com go to localhost:8080 and http://MyOtherCoolWebApp.com http://MyOtherCoolWebApp.com go to localhost:8081.
- deleted 2y ago[deleted]
- viraptor 2y agoIt's really opinionated about it though. I still don't know how to stop it from trying to get certificates for specific hostnames. It seems to work with everything auto, or nothing at all.
- tracker1 2y agoDefine the host as http://hostname http://hostname in the config instead of just hostname and it will do only http for that config. You can have a separate https config that's is different as well.
- JeremyNT 2y ago> It's really opinionated about it though. That's its value really. It has the defaults you usually want with minimal boilerplate. If you need/want something more complex it's not necessarily the right tool any more. I say this not as any kind of dig against Caddy but I feel like the entire value proposition is that its default configuration covers the 90% case so well. Sometimes being easy to use with good defaults goes a really long way.
- francislavoie 2y agoHere's the relevant docs: https://caddyserver.com/docs/caddyfile/concepts#addresses https://caddyserver.com/docs/caddyfile/concepts#addresses