Sign inSign up

cplieger/docker-caddy

By cplieger

•Updated about 18 hours ago

Run Caddy with Cloudflare DNS-01 certificates and CrowdSec IP blocking built in

Image
Networking
Security
Web servers
0

10K+

cplieger/docker-caddy repository overview

⁠docker-caddy

docker-caddy is the Caddy⁠ web server and reverse proxy with the Cloudflare DNS plugin and the CrowdSec bouncer built in. Everything else is standard Caddy, set up from your own Caddyfile as Caddy's documentation describes.

⁠What it does

docker-caddy gets trusted certificates for your public and LAN-only sites and keeps known attackers out at the proxy:

  • Gets wildcard and LAN-only certificates through your Cloudflare DNS, so the certificate check needs no open port.
  • Blocks the IP addresses on your CrowdSec decision list before their requests reach your services.
  • Checks its own health and ships Prometheus and Loki alert rules for certificates, reloads and CrowdSec.
  • Runs on a minimal base image with no shell or package manager.

⁠Who it is for

docker-caddy is built for people who write their own Caddyfile, keep their domain's DNS on Cloudflare and run CrowdSec. It carries exactly these two plugins, and only the CrowdSec plugin's IP blocking.

You need a Cloudflare API token that can edit DNS for your zone, and a CrowdSec Local API (LAPI) the container can reach, with a bouncer key from it.

Two other projects suit a different setup:

  • Consider caddy-docker-proxy⁠ if you want Caddy configured from labels on your containers. It writes the Caddyfile from those labels and reloads when containers change.
  • Consider Nginx Proxy Manager⁠ if you want to manage proxy hosts and certificates from a web admin page.

docker-caddy is free software under the Apache-2.0 license.

⁠Pull

docker pull cplieger/docker-caddy:latest

Also published to ghcr.io/cplieger/docker-caddy with identical images and tags. Release versions are tagged vX.Y.Z alongside latest.

⁠Quick start

# Example compose for docker-caddy. See docs/configuration.md and docs/hardening.md for all configuration options and hardening.
services:
  caddy:
    image: ghcr.io/cplieger/docker-caddy:latest
    container_name: caddy
    restart: unless-stopped

    environment:
      # Put both values in a .env file beside this one before the first start, and keep .env out of git.
      CLOUDFLARE_API_TOKEN: "${CLOUDFLARE_API_TOKEN:-}"  # Cloudflare API token for DNS-01 certificates
      CROWDSEC_BOUNCER_KEY: "${CROWDSEC_BOUNCER_KEY:-}"  # the key "cscli bouncers add caddy" prints

    ports:
      - "80:80"
      - "443:443"
      - "443:443/udp"  # HTTP/3

    volumes:
      # Before the first start, put your Caddyfile at ./caddy/Caddyfile. Mount the folder, not the file.
      - "./caddy:/etc/caddy:ro"
      - "./data:/data"  # certificates and ACME state, keep this folder

⁠Documentation

⁠License

Apache-2.0. See LICENSE⁠. The image carries the license text of every bundled component under /usr/share/licenses/.

The image packages Caddy⁠ (Apache-2.0, source at https://github.com/caddyserver/caddy⁠), built with xcaddy from the official caddy:2.11-builder image the Dockerfile pins by digest, together with the caddy-dns/cloudflare⁠ and caddy-crowdsec-bouncer⁠ plugins (both Apache-2.0) at the versions the Dockerfile's --with flags name. The build applies no patches. One linked module, hslatman/ipstore⁠, publishes no license file and carries the Apache-2.0 header in every source file; the packager supplies its license text under licenses/ in this repository, and it ships in the image beside the others.

Tag summary

Content type

Image

Digest

sha256:dea0ed5b4…

Size

23.8 MB

Last updated

about 18 hours ago

docker pull cplieger/docker-caddy