Blog
3 min read

What Is Caddy? The Web Server With Automatic HTTPS

Caddy is a modern web server and reverse proxy that gets and renews HTTPS certificates automatically. What it does, a three-line Caddyfile that puts your app online with HTTPS, how it compares with Nginx, and the gotchas (ports, DNS, firewalls) to know first.

Caddy is a web server — like Nginx or Apache — best known for one feature: it gets and renews HTTPS certificates automatically, with no extra setup. Point a domain at your server, write a couple of lines of config, and your site is on HTTPS.

What Caddy does

  • Serves static files — HTML, CSS, images, a built React app.
  • Acts as a reverse proxy — receives requests on ports 80/443 and forwards them to your app running on, say, port 3000. (Reverse proxies explained)
  • Handles HTTPS — obtains certificates from Let's Encrypt (or ZeroSSL), renews them before expiry, and redirects HTTP to HTTPS. (How automatic SSL works)
  • Speaks HTTP/2 and HTTP/3 out of the box. (HTTP/1.1 vs HTTP/2 vs HTTP/3)

The famous three-line config

Put your Node, Python or any other app on port 3000, then write a Caddyfile:

example.com {
    reverse_proxy localhost:3000
}

That's a complete, production-ready HTTPS setup: certificate, renewal, HTTP→HTTPS redirect, modern TLS settings.

Several sites on one server:

example.com {
    reverse_proxy localhost:3000
}

api.example.com {
    reverse_proxy localhost:4000
}

www.example.com {
    redir https://example.com{uri} permanent
}

Serving a static site (like a Vite build) with fallback for client-side routes:

app.example.com {
    root * /var/www/app/dist
    try_files {path} /index.html
    file_server
    encode gzip zstd
}

try_files fixes the 404-on-refresh problem for single-page apps.

Installing and running

On Debian/Ubuntu, Caddy publishes an apt repository (see the install page on caddyserver.com). After install, it runs as a systemd service:

sudo nano /etc/caddy/Caddyfile
sudo systemctl reload caddy
sudo systemctl status caddy
journalctl -u caddy -f        # logs

(What is systemd?)

It's also available as an official Docker image.

Before the automatic HTTPS works

Caddy can only get a certificate if:

  1. DNS points at the server — an A (and/or AAAA) record for the domain. (DNS records explained)
  2. Ports 80 and 443 are open in the server firewall and the cloud provider's firewall. (UFW basics)
  3. Nothing else is using 80/443 — stop Apache or Nginx first.

If a certificate fails, the logs say why — usually one of those three.

Behind Cloudflare's proxy, use SSL mode Full (strict). (Cloudflare 521/522/525)

Caddy vs Nginx

Caddy Nginx
HTTPS certificates Automatic Separate tool (Certbot)
Config Short Caddyfile More verbose, more knobs
Performance Excellent for almost all sites Excellent, very battle-tested
Ecosystem / tutorials Growing Enormous
Written in Go C

For a small team or a single server, Caddy's simplicity is hard to beat. Nginx is everywhere and has an answer for every edge case. (What is Nginx?, Nginx vs Caddy vs Traefik)

Common uses

  • HTTPS in front of a Node, Python or Go app on a VPS (Deploy a Node.js app to a VPS)
  • Hosting several apps on one server by domain
  • Serving static sites and SPAs
  • Local development HTTPS (localhost with a locally trusted certificate)

EasySpawn puts a reverse proxy with automatic HTTPS in front of every app on your server, so you get the Caddy experience without writing the config. See how it works or join the waitlist.

Related: Reverse Proxies Explained · What Is Nginx? · How Automatic SSL Actually Works · Deploy a Node.js App to a VPS

Keep reading