Skip to content

Caddy Proxy Manager

Control every edge. The modern web interface for Caddy Server.
DashboardEvery page on this site works like this one.DemoNothing you change here is saved

Welcome back, Avery

11of 12
Proxy hosts
9
Certificates
3
Access lists
Requests68,620
Server events17
5xx responses282
4xx responses1,566
Bandwidth out2.6 GB
Blocked requests412

All metrics

Server log

All metrics
TimeStatusWhat happened
200
GET media.example.com/library/sections/2/all48 KB · HTTP/2.0 · US · 203.0.113.24
update
Enabled the WAF on grafana.example.comavery · proxy_host
200
POST git.example.com/avery/infra/git-upload-pack1.2 MB · HTTP/2.0 · GB · 198.51.100.7
update
Added upstream http://app-2:8080 to app.example.comavery · proxy_host
502
GET app.example.com/v1/devices/sync0 · HTTP/1.1 · - · 10.0.2.51
403
GET status.example.com/.env512 B · HTTP/1.1 · NL · 45.148.10.62
create
Created L4 proxy host postgres (5432/tcp)avery · l4_proxy_host
304
GET home.example.com/static/frontend_latest/app.js0 · HTTP/3.0 · - · 10.0.2.14
renew
Issued client certificate backup-runnersystem · certificate
200
GET grafana.example.com/api/dashboards/uid/caddy96 KB · HTTP/2.0 · US · 203.0.113.88
delete
Removed old-laptop from the Staging access listavery · access_list
Requests from traffic_events in ClickHouse, changes from the audit log. Only the requests need access logging.
Traffic (24h): 68,620 · Blocked 0.6%

Caddy is a web server that gets TLS right by default. Caddy Proxy Manager is a UI in front of it, so the things Caddy can do - reverse proxying, certificates, a WAF, layer-4 streams - become things you configure and watch rather than things you write into a config file and hope about.

Reverse proxy

Multiple upstreams, twelve load-balancing policies, health checks, upstream timeouts, custom headers, location rules, redirects, rewrites, asset caching, compression, rate limiting, maintenance mode, Force HTTPS and HSTS, upstream DNS pinning, and bulk actions across hosts.

L4 TCP/UDP proxy

Layer 4 stream proxying. Port ranges, TLS SNI matching, PROXY protocol, health checks, geo blocking and access-list IP rules below HTTP.

Automatic HTTPS

ACME through Let’s Encrypt or any directory you point it at, DNS-01 across twenty-two providers with challenge delegation, certificates read from files on an agent’s host, plus a built-in CA for mutual TLS.

WAF

Coraza with the OWASP Core Rule Set. Per-host control, rule suppression, and a searchable event log that shows the rule that fired beside each event.

Traffic analytics

Live request charts, protocol breakdown, a country map, top user agents and blocked requests, backed by ClickHouse - plus a live view of the raw access, WAF and Caddy logs.

Accounts, audited

Sign in with a password, a passkey, SSO or LDAP/Active Directory. Every configuration change is recorded with the account that made it, and searchable. The whole configuration backs up to one encrypted file.