Besides that Caddy is indeed amazing and very well thought out!
It's an unnecessary security risk is all I'm saying, and I personally would have preferred it was authenticated or off by default.
I really love Caddy, you've built an amazing piece of software, I just disagree with your design decision on this one little thing. It's good that you put that notice in the docs at least!
If the host is popped, I'm not sure what Caddy can do to save you. Even authentication has to be stored on the machine... that was popped.
I'm just worried that Caddy will be the source of "security misconfiguration" (1) findings in penetration test reports. It's my opinion that we as software engineers should strive not to leave our software insecure by default, is what I'm saying, and that's how I see Caddy 2's admin API.
1: https://owasp.org/Top10/A05_2021-Security_Misconfiguration/
Yes, including your server, because you're probably forwarding that port to your workstation via ssh.