Skip to content
Back to skills

Caddy

ASecurity

Configure Caddy as a reverse proxy with automatic HTTPS and simple Caddyfile syntax.

  • 17 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 6, 2026
devopsdockertestingdebuggingbackendsecurityperformance

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 6, 2026

npx -y skills add clawic/skills --skill caddy --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Caddy?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Caddy
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/clawic-caddy/badge)](https://www.skillsdirectory.com/skills/clawic-caddy)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: Caddy
slug: caddy
version: 1.0.0
description: Configure Caddy as a reverse proxy with automatic HTTPS and simple Caddyfile syntax.
homepage: https://clawic.com/skills/caddy
metadata:
  clawdbot:
    emoji: πŸ”’
    requires:
      bins:
      - caddy
    os:
    - linux
    - darwin
    - win32
    displayName: Caddy
---

# Caddy Configuration Rules

## Automatic HTTPS
- Caddy provisions SSL certificates automatically β€” don't manually configure Let's Encrypt unless you have specific needs
- Domain must resolve to the server publicly for HTTP challenge β€” use DNS challenge for internal/wildcard certs
- Ports 80 and 443 must be free β€” Caddy needs both even for HTTPS-only (80 handles ACME challenges and redirects)
- Let's Encrypt has rate limits β€” use staging CA during testing to avoid hitting production limits

## Caddyfile Syntax
- Indentation is significant β€” blocks are defined by indentation, not braces in shorthand
- Site blocks need a space before the opening brace: `example.com {` not `example.com{`
- Use `caddy fmt --overwrite` to fix formatting β€” catches most syntax issues
- Validate before applying: `caddy validate --config /etc/caddy/Caddyfile`

## Reverse Proxy
- Caddy adds `X-Forwarded-For`, `X-Forwarded-Proto`, `X-Forwarded-Host` automatically β€” don't add them manually
- WebSocket works out of the box β€” no special configuration needed
- Load balancing is automatic with multiple backends β€” default is random, use `lb_policy` to change
- Passive health checks remove failed backends automatically

## Docker Networking
- Use container names as hostnames: `reverse_proxy container_name:3000`
- Caddy and backends must share a Docker network β€” default bridge doesn't support DNS resolution
- For Docker Compose, service names work as hostnames when on the same network

## Configuration Management
- Use `caddy reload` not restart β€” reload applies changes without dropping connections
- Config changes are atomic β€” if new config fails validation, old config stays active
- Test without applying: `caddy adapt --config Caddyfile` shows parsed JSON output

## Certificate Storage
- Certificates stored in `~/.local/share/caddy` by default β€” preserve this across reinstalls
- For Docker, mount volumes for `/data` and `/config` β€” losing these means re-requesting all certificates
- Multiple Caddy instances need shared storage or will fight over certificates

## Debugging
- Enable debug logging: add `debug` as first line in global options block
- Check certificate status in `/data/caddy/certificates/` directory
- Common issue: DNS not pointing to server yet β€” certificates fail silently until domain resolves

## Security Headers
- Caddy doesn't add security headers by default β€” add X-Frame-Options, X-Content-Type-Options explicitly
- HSTS is automatic when serving HTTPS β€” no manual configuration needed

## Performance
- Handles thousands of concurrent connections without tuning
- HTTP/3 available with `servers { protocols h1 h2 h3 }`
- Compression automatic for text content

Files in this skill

  • SKILL.md3 KB
  • _meta.json162 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…