Menu
Tutorial navigation
On this page

Self-hosting

Use Caddy as a reverse proxy for your homelab

Install Caddy on a Raspberry Pi and access homelab services using simple domain names instead of IP addresses and ports.

beginnerPublished Updated
  • caddy
  • raspberry-pi
  • homelab
  • reverse-proxy

Prerequisites

You need:

  • a Raspberry Pi running Raspberry Pi OS or another Debian-based Linux distribution
  • terminal access to the Raspberry Pi
  • a service running somewhere in your homelab
  • DNS configured for your local domains

For example, your DNS server can make:

text
wiki.your_domain

point to the Raspberry Pi running Caddy.

Install Caddy

Install the packages required for the official Caddy repository:

bash
sudo apt install --yes debian-keyring debian-archive-keyring apt-transport-https curl

Add the Caddy repository:

bash
curl -1sLf 'https://dl.cloudsmith.io/public/caddy/stable/gpg.key' \
  | sudo gpg --dearmor -o /usr/share/keyrings/caddy-stable-archive-keyring.gpg

curl -1sLf 'https://dl.cloudsmith.io/public/caddy/stable/debian.deb.txt' \
  | sudo tee /etc/apt/sources.list.d/caddy-stable.list

Install Caddy:

bash
sudo apt update
sudo apt install caddy

Check that it is running:

bash
systemctl status caddy

You should see:

text
Active: active (running)

Configure a reverse proxy

Suppose you have a service running at:

text
192.168.1.102:8080

and you want to access it using:

text
wiki.your_domain

Open the Caddy configuration:

bash
sudo nano /etc/caddy/Caddyfile

Add:

plaintext
http://wiki.your_domain {
    reverse_proxy 192.168.1.102:8080
}

The first line tells Caddy which hostname to handle:

plaintext
http://wiki.your_domain

The second tells Caddy where to send the request:

plaintext
reverse_proxy 192.168.1.102:8080

The connection now looks like:

text
wiki.your_domain
       ↓
     Caddy
       ↓
192.168.1.102:8080

Apply the configuration

Check that the configuration is valid:

bash
sudo caddy validate --config /etc/caddy/Caddyfile

Then reload Caddy:

bash
sudo systemctl reload caddy

From another device on your network, open:

text
http://wiki.your_domain

or test it with:

bash
curl http://wiki.your_domain

If everything is configured correctly, Caddy will forward the request to:

text
192.168.1.102:8080

You no longer need to remember the service’s IP address and port.

Your DNS server should make all of these domains point to the Raspberry Pi running Caddy:

text
wiki.your_domain
cloud.your_domain
admin.your_domain

Caddy then decides which backend service should receive each request.

After changing the configuration, validate and reload it:

bash
sudo caddy validate --config /etc/caddy/Caddyfile
sudo systemctl reload caddy

Enable HTTPS

For private homelab domains, Caddy can create its own HTTPS certificates.

Change:

plaintext
http://wiki.your_domain {
    reverse_proxy 192.168.1.102:8080
}

to:

plaintext
wiki.your_domain {
    reverse_proxy 192.168.1.102:8080
    tls internal
}

Validate and reload the configuration:

bash
sudo caddy validate --config /etc/caddy/Caddyfile
sudo systemctl reload caddy

You can now access the service using:

text
https://wiki.your_domain

Because the certificate is generated by Caddy’s own certificate authority, your devices need to trust Caddy’s root certificate before browsers will accept it without a warning.

You can now access services using addresses such as:

text
https://wiki.your_domain
https://cloud.your_domain
https://admin.your_domain

instead of remembering IP addresses and port numbers.