I largely agree with this, but it's not like there's a huge gap between Caddy and Apache with mod_md (https://httpd.apache.org/docs/2.4/mod/mod_md.html) or even Nginx with certbot (https://www.digitalocean.com/community/tutorials/how-to-secu...), at least for HTTP-01 challenges.
Personally I think that Caddy v1 configuration was a little bit nicer than the current versions, but honestly it's a cool web server and I see its popularity continuing to rise in the future!
That's actually how most of my personal and homelab stuff runs, with Docker Swarm due to how lightweight and simple it is. There, Apache actually works better for me since if I have 10 different domains configured and only 9 resolve (e.g. containers not running yet) then something like Nginx would complain about a non existent domain and crash the whole thing, whereas Apache would serve the 9 other domains and eventually proxy the 10th as well, instead of just returning an error.
I did tune Apache a little bit, in that I disabled .htaccess to avoid too much I/O (now the config is more like nginx.conf), though also sometimes add other modules, like mod_security (simple WAF) or mod_auth_openidc (Relying Party, so using OIDC wouldn't make me insane), as well as PHP-FPM if I ever need PHP in a particular container.
Nginx is still better for serving static files in general (e.g. packaged SPA), Traefik for HTTPS, but Apache is generally okay at most things.
I'm still an Apache/nginx user, but certificates that require no configuration are the selling point of Caddy for me (and I use it on two very small projects because of that).
[1] Which meant that I had to write some sort of automation that detected the reissue and restart Apache (and set up appropriate systemd service/timers, limited user permissions to only allow passwordless restart, etc). In the end I kept certbot (which I wanted to get rid off) and let it manage the certificate (DNS challenge) and Apache restart. I'm open to a suggestion on how this can be done in a minimal way and requiring no supervision after.
For something more precise, there is MDMessageCmd (e.g. listen for "renewed" and trigger reload; probably a short Bash script). Reload instead of restart should also be less disruptive.
The other option with MDMessageCmd, would require (on a SELinux distro) to grant Apache command exec permissions, among other tweaks.
What would be better in this case were if Apache could message via DBus these events and I could make a dbus service that listens and restarts accordingly (better execution isolation).
If Apache would do internally the certificate swap, now that would be perfect.
In what way? Caddy v1 config was very inflexible, so there were lots of things that were simply impossible to do with it. I think we struck a good balance of simplicity to expressiveness.
That actually does look like it'll be reasonable, but 1. it still requires that the user figure out how to enable mod_md and add the config to enable it, and 2. it's currently labeled "Status: Experimental", which https://httpd.apache.org/docs/2.4/mod/module-dict.html#Statu... describes as
> "Experimental" status indicates that the module is available as part of the Apache kit, but you are on your own if you try to use it. The module is being documented for completeness, and is not necessarily supported.
so it seems more like something that will eventually become a good alternative.
> Nginx with certbot
I'm fine with certbot, but there's a world of difference between "install this web server and tell it your URL starts with https://" vs "install the web server, install this other package, read the docs to configure the other package or run the setup script and follow the prompts".
Traefik has that.
I'm speak objectively here. Of course, any built-in auto HTTPS that works (more or less) is better than none. Traefik uses an ACME library that was originally written for Caddy. After the original author left that project, Traefik team started maintaining it. Caddy's users' requirements exceeded what the library was capable of, but unfortunately there was friction in getting it to achieve our requirements. So I ended up writing a new ACME client library in Go and, together with upgrades in CertMagic (Caddy's auto-TLS lib), Caddy has the more flexible, robust, and capable auto-HTTPS functionality.
That is to say, not all auto-HTTPS functionalities are the same.