Run Caddy with Cloudflare DNS-01 certificates and CrowdSec IP blocking built in
10K+
docker-caddy is the Caddy web server and reverse proxy with the Cloudflare DNS plugin and the CrowdSec bouncer built in. Everything else is standard Caddy, set up from your own Caddyfile as Caddy's documentation describes.
docker-caddy gets trusted certificates for your public and LAN-only sites and keeps known attackers out at the proxy:
docker-caddy is built for people who write their own Caddyfile, keep their domain's DNS on Cloudflare and run CrowdSec. It carries exactly these two plugins, and only the CrowdSec plugin's IP blocking.
You need a Cloudflare API token that can edit DNS for your zone, and a CrowdSec Local API (LAPI) the container can reach, with a bouncer key from it.
Two other projects suit a different setup:
docker-caddy is free software under the Apache-2.0 license.
docker pull cplieger/docker-caddy:latest
Also published to ghcr.io/cplieger/docker-caddy with identical images and tags. Release versions are tagged vX.Y.Z alongside latest.
# Example compose for docker-caddy. See docs/configuration.md and docs/hardening.md for all configuration options and hardening.
services:
caddy:
image: ghcr.io/cplieger/docker-caddy:latest
container_name: caddy
restart: unless-stopped
environment:
# Put both values in a .env file beside this one before the first start, and keep .env out of git.
CLOUDFLARE_API_TOKEN: "${CLOUDFLARE_API_TOKEN:-}" # Cloudflare API token for DNS-01 certificates
CROWDSEC_BOUNCER_KEY: "${CROWDSEC_BOUNCER_KEY:-}" # the key "cscli bouncers add caddy" prints
ports:
- "80:80"
- "443:443"
- "443:443/udp" # HTTP/3
volumes:
# Before the first start, put your Caddyfile at ./caddy/Caddyfile. Mount the folder, not the file.
- "./caddy:/etc/caddy:ro"
- "./data:/data" # certificates and ACME state, keep this folder
Apache-2.0. See LICENSE. The image carries the license text of every bundled component under /usr/share/licenses/.
The image packages Caddy (Apache-2.0, source at https://github.com/caddyserver/caddy), built with xcaddy from the official caddy:2.11-builder image the Dockerfile pins by digest, together with the caddy-dns/cloudflare and caddy-crowdsec-bouncer plugins (both Apache-2.0) at the versions the Dockerfile's --with flags name. The build applies no patches. One linked module, hslatman/ipstore, publishes no license file and carries the Apache-2.0 header in every source file; the packager supplies its license text under licenses/ in this repository, and it ships in the image beside the others.
Content type
Image
Digest
sha256:dea0ed5b4…
Size
23.8 MB
Last updated
about 18 hours ago
docker pull cplieger/docker-caddy