Skip to main content

Caddy and Cloudflare

Caddy terminates HTTPS and forwards traffic to the web container. Cloudflare hosts DNS for the domain.

homelab.stevehomelab.online {
encode zstd gzip
reverse_proxy 192.168.1.111:8088
}

Deployment​

  1. Reserve the website container's LAN IP and confirm Caddy can reach it.
  2. Add a Cloudflare DNS record for the hostname pointing to your public ingress address (not 192.168.1.111).
  3. Configure routing / firewall or a supported tunnel so external HTTPS requests reach Caddy.
  4. Add the site block to your active Caddy configuration, validate, and reload.
  5. Verify https://homelab.stevehomelab.online from outside your LAN.

Caddy command depends on how you installed it:

# Native Caddy example, only if /etc/caddy/Caddyfile is your active config:
caddy validate --config /etc/caddy/Caddyfile
systemctl reload caddy

For Dockerized Caddy, validate/reload using docker exec against the actual container and mounted Caddyfile. Do not deploy a second Caddy instance on occupied ports 80/443.

Hybrid access​

Publish only this documentation hostname. Keep Proxmox, Forgejo admin, BookStack admin, Docker, NAS, monitoring administration and other management interfaces LAN/VPN-only unless separately secured with an appropriate identity-aware access layer.