The modern web interface for Caddy Server. Automatic HTTPS, geo blocking, traffic analytics, and a full audit trail. All in one place.
+The modern web interface for Caddy Server. WAF protection, automatic HTTPS, geo blocking, traffic analytics, instance sync, and a full audit trail. All in one place.
Configure multiple upstreams, load balancing, custom headers, and per-host enable/disable with a clean editor.
Web Application Firewall powered by Coraza with OWASP CRS. Block SQLi, XSS, LFI, and RCE with per-host control and rule suppression.
+Automatic TLS for every proxy host via Caddy ACME. Let's Encrypt, ZeroSSL, and Cloudflare DNS-01 out of the box.
+Automatic TLS via Caddy ACME with Let's Encrypt and Cloudflare DNS-01. Built-in CA for issuing internal client certificates.
HTTP basic auth lists or full OAuth2/OIDC SSO via Authentik, Keycloak, Auth0, and any OIDC provider.
Master/slave configuration sync for multi-instance deployments. Push proxy hosts, certs, and settings to replicas on every change.
+Every configuration change is tracked and full-text searchable. See who did what and when.
Issuer, expiry status, and health for every ACME-managed cert. No more guessing what Caddy obtained.
+ +Fully responsive UI with card views, mobile app bar, and touch-friendly controls. Manage your infrastructure from any device.
Caddy handles certificate issuance automatically. The Certificates page shows issuer, expiry, and status for every managed cert and lets you import custom ones when needed.
+Caddy handles certificate issuance automatically. The Certificates page shows issuer, expiry, and status for every managed cert. Import custom certs or use the built-in CA to issue internal client certificates.
@@ -176,6 +186,19 @@
Enable the Coraza-powered WAF with OWASP Core Rule Set in one click. View blocked and detected events, suppress noisy rules globally or per host, and add custom SecLang directives.
+
+