Self-hosting
Use Caddy as a reverse proxy for your homelab
Install Caddy on a Raspberry Pi and access homelab services using simple domain names instead of IP addresses and ports.
Prerequisites
You need:
- a Raspberry Pi running Raspberry Pi OS or another Debian-based Linux distribution
- terminal access to the Raspberry Pi
- a service running somewhere in your homelab
- DNS configured for your local domains
For example, your DNS server can make:
wiki.your_domainpoint to the Raspberry Pi running Caddy.
Install Caddy
Install the packages required for the official Caddy repository:
sudo apt install --yes debian-keyring debian-archive-keyring apt-transport-https curlAdd the Caddy repository:
curl -1sLf 'https://dl.cloudsmith.io/public/caddy/stable/gpg.key' \
| sudo gpg --dearmor -o /usr/share/keyrings/caddy-stable-archive-keyring.gpg
curl -1sLf 'https://dl.cloudsmith.io/public/caddy/stable/debian.deb.txt' \
| sudo tee /etc/apt/sources.list.d/caddy-stable.listInstall Caddy:
sudo apt update
sudo apt install caddyCheck that it is running:
systemctl status caddyYou should see:
Active: active (running)Configure a reverse proxy
Suppose you have a service running at:
192.168.1.102:8080and you want to access it using:
wiki.your_domainOpen the Caddy configuration:
sudo nano /etc/caddy/CaddyfileAdd:
http://wiki.your_domain {
reverse_proxy 192.168.1.102:8080
}The first line tells Caddy which hostname to handle:
http://wiki.your_domainThe second tells Caddy where to send the request:
reverse_proxy 192.168.1.102:8080The connection now looks like:
wiki.your_domain
↓
Caddy
↓
192.168.1.102:8080Apply the configuration
Check that the configuration is valid:
sudo caddy validate --config /etc/caddy/CaddyfileThen reload Caddy:
sudo systemctl reload caddyFrom another device on your network, open:
http://wiki.your_domainor test it with:
curl http://wiki.your_domainIf everything is configured correctly, Caddy will forward the request to:
192.168.1.102:8080You no longer need to remember the service’s IP address and port.
Your DNS server should make all of these domains point to the Raspberry Pi running Caddy:
wiki.your_domain
cloud.your_domain
admin.your_domainCaddy then decides which backend service should receive each request.
After changing the configuration, validate and reload it:
sudo caddy validate --config /etc/caddy/Caddyfile
sudo systemctl reload caddyEnable HTTPS
For private homelab domains, Caddy can create its own HTTPS certificates.
Change:
http://wiki.your_domain {
reverse_proxy 192.168.1.102:8080
}to:
wiki.your_domain {
reverse_proxy 192.168.1.102:8080
tls internal
}Validate and reload the configuration:
sudo caddy validate --config /etc/caddy/Caddyfile
sudo systemctl reload caddyYou can now access the service using:
https://wiki.your_domainBecause the certificate is generated by Caddy’s own certificate authority, your devices need to trust Caddy’s root certificate before browsers will accept it without a warning.
You can now access services using addresses such as:
https://wiki.your_domain
https://cloud.your_domain
https://admin.your_domaininstead of remembering IP addresses and port numbers.