A web server that automatically issues and renews certificates when you specify a domain
All connections are encrypted from the moment the server starts, so you do not need to worry about security settings separately. Caddy is a web server that uses TLS by default and a platform for running Go applications. It handles complex certificate management and protocol configuration, allowing developers to focus solely on application logic.
Automatic HTTPS and Configuration
Caddy automatically issues and renews certificates for public domains via ZeroSSL and Let's Encrypt. It applies HTTPS to internal names or IP addresses by managing its own local CA. Configuration can be written in the simple Caddyfile format or native JSON, and the configuration of a running server can be changed dynamically through the JSON API. Adapters are also supported for converting configuration files from other formats, such as NGINX, YAML, or TOML.
Extensible Go-Based Architecture
Written in Go, Caddy has no external dependencies, including libc, so it can run anywhere. Based on a modular architecture, a Caddy app is a module implemented as a Go program, with tls and http apps provided by default. This design provides built-in support for HTTP/1.1, HTTP/2, and HTTP/3. This approach prevents server downtime caused by TLS or certificate issues and ensures stable operation while managing millions of certificates.
Installation and Build Methods
The easiest method is to download the executable from GitHub Releases and add it to your PATH. To build from source, Go 1.26.0 or higher is required. Development builds can be performed with the go build command, while the xcaddy builder tool is used to include version information or plugins. On Linux, you may need to grant permissions using the sudo setcap cap_net_bind_service=+ep ./caddy command to bind to low ports.
Pre-Deployment Checks
Caddy is used in production environments that handle trillions of requests and manage millions of certificates. Building from source requires Go 1.26.0 or higher, and operating system permission settings may be required for specific port binding. Enterprise users can consider support contracts through Ardan Labs, while individual users can seek help in the community forum. The README does not specify license details or specific hardware requirements, so additional verification is needed for your deployment environment.