New: the Homelab Planning Bundle. Both planners together for $19.99 instead of $27.98Save $7.99GET THE BUNDLE

Homelab Addiction

Self-Hosted / Projects / Caddy

Caddy

Stable
caddyserver/caddy77.7k5.1k4h agoWeb Servers

Specs verified August 26, 2026 · against v2.11.4

Overview

Self-hosted reverse proxy and web server with automatic HTTPS, a simple Caddyfile, and fewer moving parts.

Caddy is a self-hosted reverse proxy and web server for people who want to publish apps over HTTPS without bolting together a separate certificate tool, custom Nginx snippets, and extra renewal jobs.

Why people choose Caddy

Official Caddy docs center the product around automatic HTTPS by default, and self-hosted operators often reach for it when they want a simpler reverse-proxy path than hand-maintained web-server configs.

What is included

The official site and reverse_proxy docs highlight automatic certificate issuance and renewal, local HTTPS for internal hosts, a simple Caddyfile syntax, a JSON config API, reverse proxying, load balancing, active and passive health checks, dynamic upstream discovery, and request or header manipulation.

What to know before you deploy

Automatic HTTPS is not magic if your network edge is wrong. The docs say public sites still need working DNS, externally reachable ports 80 and 443, and persistent writable storage for certificates. Caddy can also feel less comfortable if you want a GUI-first workflow instead of text config.

Best fit

Choose Caddy when you want a low-friction HTTPS-first reverse proxy for a homelab, small SaaS, or internal service edge. If you prefer label-driven orchestration metadata or a large Kubernetes-oriented routing model, Traefik may fit better.

Interface previews

Screenshots of the Caddy interface.

Feature support

Feature support in Caddy
FeatureSupport
Automatic HTTPS and renewalsOfficial docs say Caddy automatically obtains and renews certificates and redirects HTTP to HTTPS for qualifying hosts.Supported
Local HTTPS for internal hostsThe automatic HTTPS docs say local and internal hostnames can be served over HTTPS using Caddy’s locally trusted CA.Supported
Reverse proxy and load balancingThe reverse_proxy directive supports multiple upstreams, load-balancing policies, retries, and health checks.Supported
Active and passive health checksOfficial reverse_proxy docs document active health probes plus passive failure handling.Supported
Dynamic upstream discoveryThe reverse_proxy docs cover dynamic upstream resolution from SRV and A/AAAA DNS records.Supported
REST config API and JSON configThe homepage states Caddy’s native configuration is JSON and can be managed through a RESTful config API.Supported
Header and request rewritingOfficial reverse_proxy docs include request rewriting, method changes, and header_up/header_down controls.Supported
GUI-based proxy managementCaddy itself is configuration-file and API driven; a GUI requires third-party tooling rather than the core project.Partial support

Community signals

Stars
77.7k
Forks
5.1k
Open issues
282

Includes open pull requests

Last commit
4h ago
Latest release
v2.11.7

1w ago

Repo created
Jan 2015

Refreshed nightly from the GitHub API.

Questions

What is Caddy used for?

Caddy is used as a self-hosted reverse proxy and web server for publishing websites, internal apps, APIs, and local services with HTTPS enabled by default.

Does Caddy automatically handle SSL certificates?

Yes. The official automatic HTTPS docs say Caddy automatically obtains and renews TLS certificates and redirects HTTP to HTTPS for qualifying sites.

Can Caddy proxy local apps on my LAN?

Yes. The reverse_proxy docs show Caddy proxying local backends such as localhost services, internal IPs, Unix sockets, and upstream pools.

Does Caddy work for localhost or internal hostnames?

Yes. The official docs say Caddy can serve local and internal hosts over HTTPS using its own local certificate authority.

What do you need for automatic HTTPS on a public domain?

The docs say your DNS must point at the server, ports 80 and 443 must be reachable or forwarded to Caddy, and the certificate storage directory must be writable and persistent.

Do you need Certbot or a separate renewal job with Caddy?

No for standard Caddy-managed certificates. Automatic HTTPS is built in, so you do not need a separate certificate renewal tool for normal deployments.

Is Caddy a better fit than a heavier reverse-proxy stack for small homelabs?

It can be when your main goal is simpler HTTPS and text-based reverse-proxy config. Operators often praise that simplicity, but GUI-first users may still prefer a different workflow.

support // the lab

Found this write-up useful?

If it saved you time or a rebuild, you can support more practical homelab guides.

Support the lab