TOPIC
Caddy & Reverse Proxy
Lessons, explainers, experiments, and implementation notes.
Caddy & Reverse Proxy · 16 min read · Lab period 2026-09
A 502 usually means the browser-to-Caddy leg worked and the Caddy-to-upstream leg did not.
By Reaz Romen ✓ verified
Caddy502reverse proxytroubleshooting
Caddy & Reverse Proxy · 16 min read · Lab period 2026-09
The most common Docker reverse-proxy mistake is technically valid networking aimed at the wrong namespace.
By Reaz Romen ✓ verified
CaddyDockerlocalhost502
Caddy & Reverse Proxy · 17 min read · Lab period 2026-09
Docker DNS only resolves service names inside the networks where those services actually meet.
By Reaz Romen ✓ verified
CaddyDocker DNSComposenetworking
Caddy & Reverse Proxy · 16 min read · Lab period 2026-09
An IP can be the correct route to an upstream while being the wrong identity for its certificate.
By Reaz Romen ✓ verified
CaddyTLSSNIprivate CA
Caddy & Reverse Proxy · 17 min read · Lab period 2026-09
Caddy 2.11 changed default Host behavior for HTTPS upstreams, exposing apps that relied on the old value.
By Reaz Romen ✓ verified
Caddy 2.11Host headerHTTPS upstreamredirect
Caddy & Reverse Proxy · 16 min read · Lab period 2026-09
Normal HTTP can succeed while a WebSocket upgrade fails on the same application.
By Reaz Romen ✓ verified
CaddyWebSocketHTTP upgradereal-time
Caddy & Reverse Proxy · 16 min read · Lab period 2026-09
Stripping a prefix is easy; making the application believe it lives under that prefix is harder.
By Reaz Romen ✓ verified
Caddyhandle_pathsubfolder problemreverse proxy
Caddy & Reverse Proxy · 16 min read · Lab period 2026-09
Client-side routes exist only after index.html loads; the server still needs a fallback for direct requests.
By Reaz Romen ✓ verified
CaddySPAtry_files404
Caddy & Reverse Proxy · 17 min read · Lab period 2026-09
A catch-all frontend fallback can hide backend routing mistakes behind a successful HTML response.
By Reaz Romen ✓ verified
CaddySPAAPIhandle
Caddy & Reverse Proxy · 16 min read · Lab period 2026-09
External redirects, internal rewrites and upstream canonicalization are different tools even when they change the same path.
By Reaz Romen ✓ verified
Caddyredirectrewritetrailing slash
Caddy & Reverse Proxy · 16 min read · Lab period 2026-09
The failing TLS identity may be on the Cloudflare-to-origin leg rather than in Caddy's upstream proxy.
By Reaz Romen ✓ verified
CaddyCloudflare Tunnel502TLS origin
Caddy & Reverse Proxy · 18 min read · Lab period 2026-09
Original client IP is trustworthy only when Caddy knows which proxy was allowed to write it.
By Reaz Romen ✓ verified
CaddyCloudflareclient IPtrusted proxies
Caddy & Reverse Proxy · 16 min read · Lab period 2026-09
Wildcard ACME certificates require DNS validation of the parent zone.
By Reaz Romen ✓ verified
Caddywildcard certificateACMEDNS challenge
Caddy & Reverse Proxy · 16 min read · Lab period 2026-09
DNS challenge syntax only works when the running binary contains that provider module.
By Reaz Romen ✓ verified
CaddyCloudflare DNSxcaddyDocker
Caddy & Reverse Proxy · 18 min read · Lab period 2026-09
ACME automation still depends on the challenge traffic reaching the Caddy instance that requested the certificate.
By Reaz Romen ✓ verified
CaddyAutomatic HTTPSACMEports 80 443
Caddy & Reverse Proxy · 16 min read · Lab period 2026-09
Private TLS is only trusted by clients that possess and trust the private root CA.
By Reaz Romen ✓ verified
Caddytls internalprivate CAbrowser
Caddy & Reverse Proxy · 17 min read · Lab period 2026-09
Internal HTTPS between proxies is useful only when the caller can verify the upstream identity.
By Reaz Romen ✓ verified
Caddyprivate CAreverse proxySNI
Caddy & Reverse Proxy · 16 min read · Lab period 2026-09
A proxied 5xx status is a response, not automatically a Caddy handler error.
By Reaz Romen ✓ verified
Caddy502maintenance pagehandle_response
Caddy & Reverse Proxy · 16 min read · Lab period 2026-09
Auth gateways need the original request context to decide and redirect correctly.
By Reaz Romen ✓ verified
Caddyforward_authSSOredirect loop
Caddy & Reverse Proxy · 17 min read · Lab period 2026-09
Identity headers are safe only when clients cannot inject equivalent values around the auth boundary.
By Reaz Romen ✓ verified
Caddyheadersforward_authsecurity
Caddy & Reverse Proxy · 16 min read · Lab period 2026-09
Path-based access control is safest when protected and public branches cannot accidentally fall through.
By Reaz Romen ✓ verified
Caddymatchersauthorizationrouting
Caddy & Reverse Proxy · 16 min read · Lab period 2026-09
The admin endpoint can replace active configuration, so broad exposure changes the security boundary of the edge.
By Reaz Romen ✓ verified
Caddyadmin APIsecurityconfiguration
Caddy & Reverse Proxy · 16 min read · Lab period 2026-09
Repeated auth, TLS and header policy drifts when every site block is cloned by hand.
By Reaz Romen ✓ verified
CaddyCaddyfileimportsnippets
Caddy & Reverse Proxy · 16 min read · Lab period 2026-09
A synthetic health request measures the service only if it looks like a request the service considers valid.
By Reaz Romen ✓ verified
Caddyhealth checksreverse proxy503
Caddy & Reverse Proxy · 17 min read · Lab period 2026-09
Retry policy is also application semantics: replaying a write may repeat a side effect.
By Reaz Romen ✓ verified
CaddyretriesPOSTload balancing
Caddy & Reverse Proxy · 16 min read · Lab period 2026-09
Keepalive timeout mismatches can fail a request even while proxy and backend are otherwise healthy.
By Reaz Romen ✓ verified
Caddykeepalive502HTTP
Caddy & Reverse Proxy · 17 min read · Lab period 2026-09
Multiple proxies are fine when each boundary has one explicit owner.
By Reaz Romen ✓ verified
Caddyingressarchitecturehomelab
Caddy & Reverse Proxy · 18 min read · Lab period 2026-09
Caddy has graceful config reloads; restarting the process turns a routing edit into avoidable downtime.
By Reaz Romen ✓ verified
Caddyreloadzero downtimedeployment
Caddy & Reverse Proxy · 16 min read · Lab period 2026-09
Logs become useful when access records, proxy errors and request identity can be correlated.
By Reaz Romen ✓ verified
CaddylogsJSONtroubleshooting
Caddy & Reverse Proxy · 17 min read · Lab period 2026-09
The edge process can be green while one proxied service is failing behind it.
By Reaz Romen ✓ verified
CaddyPrometheusmetricsupstream health