5 ms·
One area we have found Caddy invaluable is for local testing of APIs with HTTP2 during development. Most dev servers are HTTP1 only, and so you are limited to m
by samwillis 2y ago
One area we have found Caddy invaluable is for local testing of APIs with HTTP2 during development. Most dev servers are HTTP1 only, and so you are limited to max of 6 concurrent connections to localhost. HTTP2 requires SSL, which would normally make it a PITA to test/setup locally for development.
Throw a Caddy reverse proxy in front of your normal dev server and you immediately get HTTP2 via the root certificate it installs in your OS trust store. (https://caddyserver.com/docs/automatic-https https://caddyserver.com/docs/automatic-https)
We (ElectricSQL) recommend it for our users as our APIs do long polling, which with HTTP2 doesn't lock up those 6 concurrent connections.
I've also found that placing it in front of Vite for normal development makes reloads much faster. Vite uses the JS module system for loading individual files in the browser with support for HMR (hot module replacement), this can result in a lot of concurrent requests for larger apps, creating a queue for those files on the six connections. Other bundlers/build tools bundle the code during development, reducing the number of files loaded into the browser, this created a bit of a debate last year on which is the better approach. With HTTP2 via Caddy in front of Vite you solve all those problems!
- srameshc 2y agoI assumed almost everyone (product, enterprise) uses ngork to expose development/localhost server to get HTTP2 now a days, but it's good to realize Caddy can do the job well.
- jsheard 2y ago> HTTP2 requires SSL Strictly speaking it doesn't, unencrypted HTTP2 is allowed per the spec (and Caddy supports that mode) but the browsers chose not to support it so it's only really useful when testing non-browser clients or routing requests between servers. HTTP3 does require encryption for reals though, there's no opting out anymore.
- samwillis 2y agoYep, it's really disappointing they didn't decide to support it for localhost.
- imdadadani 2y agoI think the reason why they have decided to not support it over plain text is because they would have to detect if the server answers with HTTP/2 or HTTP/1.1, which could be complicated. This is not needed when using TLS since ALPN is used instead
- jrockway 2y agoThis is meh excuse. If you want your browser to connect to a gopher server, you type gopher://example.com. If you want to use http2, http2://example.com should work. (I know, I know, everyone removed Gopher support a few years ago. Same idea though.) Having said all that, I just copied the certs out of here https://cs.opensource.google/go/go/+/refs/tags/go1.24.0:src/net/http/internal/testcert/testcert.go https://cs.opensource.google/go/go/+/refs/tags/go1.24.0:src/... and use them to do browser/http2 stuff locally. Why steal Go's certificates? Because it took 1 second less than making my own!
- taftster 2y agoHey, thanks for this. It saves me even more than 1 second!
- e12e 2y agoWhich browsers/libraries trust these? Or does the go tool chain install them?
- jrockway 2y agoNothing trusts them, they're just regular self-signed certificates. There is no benefit to using these over your own self-signed certificates except that you don't have to ask your LLM for the commands to generate them ;)
- e12e 2y agoAnd of course once you trust them on localhost, you expose yourself to some risk, since the whole world can get a copy of the key.
- tacone 2y agoAnother way is to create a regular DNS name, and ave it redirect to localhost. If you are unable or unwilling to do so, there are free DNS services like https://traefik.me/ https://traefik.me/ that provide you with a real domain name and related certificates. I personally use traefik.me for my hobbyist fiddling, and I have a working HTTP/2 local development experience. It's also very nice to be able to build for production and test the performance locally, without having to deploy to a dev environment.
- 8n4vidtmkvmk 2y agoAren't you exposing your dev instance to the world then? Not worried about that?
- adolph 2y agoDNS to a local address doesn’t expose anything. For example, postulate a DNS entry of myTopSecrets mapped to localhost. If you use it, it will be routed to your own computer. If someone else uses it, they would be routed to their own computer. The same follows for IP addresses within your local area network. Unless you did extra work outside the scope of DNS, nothing in your lan is addressable from outside your lan.
- TeMPOraL 2y agoYou're still revealing the existence of myTopSecrets to the world, though. Between this and certificate transparency logs, it seems insane to me that the commonly advised Correct Setup, to be able to experiment and hack random little personal stuff, and have it reliably work on modern browsers, requires you to 1) buy a subscription (domain), 2) enter into another subscription-ish contractual relationship (Let's Encrypt), and 3) announce to the whole world what you're doing (possibly in two places!). Imagine your computer stops booting up because you repositioned your desk, and everyone tells you the Correct Way to do it is to file a form with the post office, and apply for a free building permit from the local council. That's how this feels.
- 2y ago
- peterldowns 2y agoCompletely agree. If you want a nice way to do this with a shared config that you can commit to a git repo, check out my project, Localias. It also lets you visit dev servers from other devices on the same wifi network — great for mobile testing! Localias is built on Caddy; my whole goal is to make local web dev with https as simple as possible. https://github.com/peterldowns/localias https://github.com/peterldowns/localias
- breadwinner 2y agoThat only works on localhost, right? I am looking for a solution for intranet that doesn't require complex sysadmin skills such as setting up DNS servers and installing root certificates. This is for my customers who need to run my web server on the intranet while encrypting traffic (no need to verify that the server is who it claims to be).
- HumanOstrich 2y agoWithout verifying the server identity, the encryption is useless.
- peterldowns 2y agoLocalias is not designed for your usecase and cannot solve your problem, sorry.
- JasonSage 2y agoJust a note, because this comment made me curious and prompted me to look into it: Vite does use HTTP2 automatically if you configure the cert, which is easy to do locally without Caddy. In that case specifically there's no real reason to use Caddy locally that I can see, other than wanting to use Caddy's local cert instead of mkcert or the Vite plugin that automatically provides a local cert.
- deleted 2y ago[deleted]
- noplacelikehome 2y ago> via the root certificate it installs in your OS trust store This does not sound like the kind of feature I would want in a web server
- bogdan 2y agoIt is optional for this purpose and you have to explicitly install it.
- jodrellblank 2y ago> so you are limited to max of 6 concurrent connections to localhost. I think a web server listening on 0.0.0.0 will accept “localhost” connections on 127.0.0.2, 127.0.0.3, 127.0.0.4 … etc., and that you could have six connections to each. https://superuser.com/questions/393700/what-is-the-127-0-0-2-ip-address-for#393701 https://superuser.com/questions/393700/what-is-the-127-0-0-2... ( a comment there says “not on macOS” though)
- ndriscoll 2y agoThe six connections thing is just a default that you can change in about:config. Really it should probably have a higher default in $currentYear, but I don't expect major browser vendors to care.