You say caddy. The next person will say nginx-proxy-manager. The next will say DNS challenge let's encrypt behind wireguard VPN. The next will say Traefik. The next will say CloudFlare tunnels.
Everyone has their preferred solution and its always the best and simplest.
Do you want a caddy service embedded with every web app you self host or are you running a single one serving all your apps?
From my understanding if you want acme http challenges to just work with let's encrypt you probably need to use a single, separated caddy to front all your apps.
In that case if I ship a caddy service pre configured to do TLS termination with my app it's just more trouble for you no?
My point was not to use http only as a finished solution, but to let the admin front the http-only service with their TLS termination solution of choice.
I self-host Immich with Caddy as TLS terminator, and it's far from obvious.
They all run on a small N150 PC in my closet, the same PC serves as my internet router. Both Immich and Caddy run in podman-compose, and there are firewall rules that allow incoming traffic to Caddy and outgoing traffic from Caddy to update certificates. There's also a tricky setup of Systemd dependencies that make sure podman networking and firewall rules play nicely together and with other system config, like the bridge for the 2.4Gz range internal Wi-Fi and for external 5Gz Wi-Fi 6 card.
If not for the LLM help, I would have spent many days figuring out all the rough edges of this setup.
Which is exactly the point OP is making. Hobbying webhosting is hard nowadays.
I self-host Immich with Caddy, and it's complex, really.
Caddy runs in podman compose next to Immich, there are firewall rules to allow traffic in and out and proper dependencies in custom systemd units in case podman networking goes bust after firewall rules are reloaded and a readme that covers all that.
Exactly the point OP is making.
If you want to put caddy in front of yours? Great it works.
For me, running a much larger setup? Great, it also works.
For users who never expose it beyond an IP address on lan? Great it also works.