https://hub.docker.com/_/caddy/
You also get automatic TLS certificate management and tons of other goodies that nginx doesn't offer out of the box.
https://hub.docker.com/_/caddy/
You also get automatic TLS certificate management and tons of other goodies that nginx doesn't offer out of the box.
I missed the whole Caddy thing anyway because the source code was not completely open back in the days I was looking for nginx alternatives that provided with LetsEncrypt automatically.
However, it seems Caddy can be used as an alternative to Traefik if you use a plugin: https://caddyserver.com/v1/docs/docker Apparently it requires swarm though, which I don't need anyway, so, still no reason for me to try Caddy unfortunately because it does look pretty cool now.
The Caddy source code has always been open source (Apache 2.0 licensed) from day one all the way to today, and will continue to be in the future.
Beware when using other Let's Encrypt integrations. Caddy will keep your site online when other servers don't. (We saw this recently when Let's Encrypt had a revocation incident and when OCSP responders / other network infrastructure went down. Caddy kept the sites up, where other sites went down or left sysadmins scrambling to renew their certs.)
Interestingly, the LetsEncrypt incident you mentioned went completely under my radar, none of my traefik instances in production or else were affected at all, or it wasn't caught by my uptimerobot, so I'm really not sure what you were talking about then. Maybe the 2017 incident, but I was still using nginx at the time. Pretty concerning, going to check it out.
Honestly I didn't require any of the nginx paid features ever nor did I with traefik, which also has an EE edition that I just found about, I suppose needing those would be a "problem I want to have" kind of problem (meaning the project I'm taking care of is growing). I'm more into software that will generate configuration by introspecting my systems but configuration APIs are also nice to have otherwise.
Nonetheless, Caddy is a great alternative in a domain where innovation had been stalling for a while. I would like to send over a one-time donation to help Caddy development if possible to support development.
It didn't affect every site. But it did affect millions of them. You're lucky!
And in contrast to caddy, my setup actually follows the DNS and URL standards, and actually handles Absolute URIs correctly, in contrast to e.g. http://caddyserver.com./, which doesn’t even set HSTS on caddyserver.com., while even browsers consider caddyserver.com. the same origin for the purpose of TLS and HSTS.
If you’re already using something like kubernetes, which does such resolutions, this can actually become an issue. e.g. in the cluster ServiceA can call ServiceB by navigating to http://serviceb/, and if the name of serviceb overlaps with an actual real-world domain, you need to use http://serviceb./ to ensure you call the outside-world site.
So, I need all websites intended to be fetched this way to support the proper DNS RFCs.
Ever since Caddy and Traefik became a thing my tool has stopped working for more and more non-standard webpages.
Even caddyserver.com itself is broken.
In the end, I’ve simply chosen not to use caddy or traefik based websites.