Self-Hosted / Projects / Caddy

Caddy
StableSpecs verified August 26, 2026 · against v2.11.4
Overview
Self-hosted reverse proxy and web server with automatic HTTPS, a simple Caddyfile, and fewer moving parts.
Caddy is a self-hosted reverse proxy and web server for people who want to publish apps over HTTPS without bolting together a separate certificate tool, custom Nginx snippets, and extra renewal jobs.
Why people choose Caddy
Official Caddy docs center the product around automatic HTTPS by default, and self-hosted operators often reach for it when they want a simpler reverse-proxy path than hand-maintained web-server configs.
What is included
The official site and reverse_proxy docs highlight automatic certificate issuance and renewal, local HTTPS for internal hosts, a simple Caddyfile syntax, a JSON config API, reverse proxying, load balancing, active and passive health checks, dynamic upstream discovery, and request or header manipulation.
What to know before you deploy
Automatic HTTPS is not magic if your network edge is wrong. The docs say public sites still need working DNS, externally reachable ports 80 and 443, and persistent writable storage for certificates. Caddy can also feel less comfortable if you want a GUI-first workflow instead of text config.
Best fit
Choose Caddy when you want a low-friction HTTPS-first reverse proxy for a homelab, small SaaS, or internal service edge. If you prefer label-driven orchestration metadata or a large Kubernetes-oriented routing model, Traefik may fit better.
Interface previews
Screenshots of the Caddy interface.
Feature support
| Feature | Support |
|---|---|
| Automatic HTTPS and renewalsOfficial docs say Caddy automatically obtains and renews certificates and redirects HTTP to HTTPS for qualifying hosts. | Supported |
| Local HTTPS for internal hostsThe automatic HTTPS docs say local and internal hostnames can be served over HTTPS using Caddy’s locally trusted CA. | Supported |
| Reverse proxy and load balancingThe reverse_proxy directive supports multiple upstreams, load-balancing policies, retries, and health checks. | Supported |
| Active and passive health checksOfficial reverse_proxy docs document active health probes plus passive failure handling. | Supported |
| Dynamic upstream discoveryThe reverse_proxy docs cover dynamic upstream resolution from SRV and A/AAAA DNS records. | Supported |
| REST config API and JSON configThe homepage states Caddy’s native configuration is JSON and can be managed through a RESTful config API. | Supported |
| Header and request rewritingOfficial reverse_proxy docs include request rewriting, method changes, and header_up/header_down controls. | Supported |
| GUI-based proxy managementCaddy itself is configuration-file and API driven; a GUI requires third-party tooling rather than the core project. | Partial support |
Community signals
- Stars
- 77.7k
- Forks
- 5.1k
- Open issues
- 282
- Last commit
- 4h ago
- Latest release
- v2.11.7
- Repo created
- Jan 2015
Includes open pull requests
1w ago
Refreshed nightly from the GitHub API.
Questions
What is Caddy used for?
Caddy is used as a self-hosted reverse proxy and web server for publishing websites, internal apps, APIs, and local services with HTTPS enabled by default.
Does Caddy automatically handle SSL certificates?
Yes. The official automatic HTTPS docs say Caddy automatically obtains and renews TLS certificates and redirects HTTP to HTTPS for qualifying sites.
Can Caddy proxy local apps on my LAN?
Yes. The reverse_proxy docs show Caddy proxying local backends such as localhost services, internal IPs, Unix sockets, and upstream pools.
Does Caddy work for localhost or internal hostnames?
Yes. The official docs say Caddy can serve local and internal hosts over HTTPS using its own local certificate authority.
What do you need for automatic HTTPS on a public domain?
The docs say your DNS must point at the server, ports 80 and 443 must be reachable or forwarded to Caddy, and the certificate storage directory must be writable and persistent.
Do you need Certbot or a separate renewal job with Caddy?
No for standard Caddy-managed certificates. Automatic HTTPS is built in, so you do not need a separate certificate renewal tool for normal deployments.
Is Caddy a better fit than a heavier reverse-proxy stack for small homelabs?
It can be when your main goal is simpler HTTPS and text-based reverse-proxy config. Operators often praise that simplicity, but GUI-first users may still prefer a different workflow.
support // the lab
Found this write-up useful?
If it saved you time or a rebuild, you can support more practical homelab guides.