caddy-security
caddy-docker-proxy
Our great sponsors
caddy-security | caddy-docker-proxy | |
---|---|---|
17 | 54 | |
1,234 | 2,358 | |
- | - | |
8.1 | 7.4 | |
20 days ago | 6 days ago | |
Go | Go | |
Apache License 2.0 | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
caddy-security
- Caddy-Security: Security App and Plugin for Caddy
-
Security flaws in an SSO plugin for Caddy
There is no "refusal" as far as I can tell. The issues were reported [1] in September 2023 (as was this blog post) and the simplest one has been fixed (insecure random seed). I'm not aware of any public statements from the plugin maintainers, and there is no hostility in the issue comments.
[1]: https://github.com/greenpau/caddy-security/issues?q=is%3Aiss...
> September 18, 2023: The disclosure blog post was released and issues were filed with the original project repository.
I don't see those issues listed in the GitHub project issue tracker https://github.com/greenpau/caddy-security/issues. Have they been deleted?
-
Web authentication for reverse proxy
Check out https://github.com/greenpau/caddy-security
-
What 3rd party auth provider would you guys recommend to use with Caddy on Windows, and are there any tutorials or documentation?
There a pretty comprehensive auth plugin for Caddy. It can do local authentication with a session cookie, which should work with your IPTV apps. If your app can show a login form, it's super easy, but if I remember correctly you can also authenticate with basic auth and store the session in a cookie (this is mostly used to carry over the authentication to a different subdomain).
-
Q: I need help with securing my selfhosted services
I use Caddy + Caddy Security, set up OAuth, and also only expose services over IPv6. It's not extra security, but it's less logs to deal with because nobody is scanning IPv6 address ranges, and there are less IPv6 capable hosts who are compromised.
- Authentication in Go? Best practices
-
Web server with content upload and authentication
Not sure if this fits your bill, but have a look at Caddy web server and its available authentification methods or even more with a plugin
-
Hiding Public IP
Also look at github.com/greenpau/caddy-security to enable MFA for Caddy.
-
Guacamole + LetsEncrypt (Nginx/Træfik) + VPN ? (x-post r/selfhosted)
- Guacamole docker connects to Debian VNC Desktop - Caddy docker offers HTTPS proxy with Guacamole and the Caddy Security plug in for Auth with TOTP
caddy-docker-proxy
- Caddy-Docker-Proxy: Caddy as a Reverse Proxy for Docker
-
Self-Hosted Is Awesome
https://github.com/lucaslorentz/caddy-docker-proxy
It handles the routing to multiple dockerized projects on one server, by scanning docker compose files for labels and automatically setting up the required caddy configuration.
-
Keycloak SSO with Docker Compose and Nginx
My go to is always this instead:
https://github.com/lucaslorentz/caddy-docker-proxy
Single label to a docker container and with correct DNS you’ll have an automatically managed certificate right away.
-
Working on Multiple Web Projects with Docker Compose and Traefik
I have had a great experience with using this: https://github.com/lucaslorentz/caddy-docker-proxy
It combines caddy with docker-compose labels, making it super easy to spin up new projects that can immediately be exposed.
-
Caddy is the first and only web server to use HTTPS automatically and by default
If you want a slightly heavier but more robust solution, caddy-docker-proxy[0] is a plugin that listens to the Docker socket and automatically updates the Caddy configuration based on Docker labels you add to containers.
I.e. it makes Caddy act a bit more like Traefik. Most of the time, you'll just add the label `caddy.reverse_proxy={{upstreams http 8080}}` to your containers and the plugin will regenerate Caddy's configuration whenever the container is modified.
[0] https://github.com/lucaslorentz/caddy-docker-proxy
-
Nginx Development Guide
I disagree, Caddy works great in Docker. See https://caddyserver.com/docs/running#docker-compose, and CDP is a project that autoconfigures Caddy from labels https://github.com/lucaslorentz/caddy-docker-proxy. Regarding plugins, it's super simple to write a Dockerfile to add plugins, we ship a builder image variant that can be used to compile in any plugins you want.
-
How I run my servers
````
This way, Caddy will buffer the request and give 30 seconds for your new service to get online when you're deploying a new version.
Ideally, during deployment of a new version the new version should go live and healthy before caddy starts using it (and kills the old container). I've looked at https://github.com/Wowu/docker-rollout and https://github.com/lucaslorentz/caddy-docker-proxy but haven't had time to prioritize it yet.
-
Which reverse proxy are you using?
Docker labels support is available via a plugin https://github.com/lucaslorentz/caddy-docker-proxy
-
My repository of the week: NGINX Proxy - Automated nginx for your containers
Or caddy-docker-proxy: https://github.com/lucaslorentz/caddy-docker-proxy
-
Caddy Repository from Lucas lorentz cant use Caddyfile?
I am trying now for some Days to use a Caddyfile additionaly to the auto generated files from lucas lorentzes caddy repositroy. https://github.com/lucaslorentz/caddy-docker-proxy
What are some alternatives?
caddy-auth-portal - Authentication Plugin for Caddy v2 implementing Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google, Facebook, Okta, etc.), SAML Authentication. MFA with App Authenticators and Yubico.
Nginx Proxy Manager - Docker container for managing Nginx proxy hosts with a simple, powerful interface
scim-for-keycloak - a third party module that extends keycloak by SCIM functionality
Caddy - Fast and extensible multi-platform HTTP/1-2-3 web server with automatic HTTPS
caddy-maxmind-geolocation - Caddy v2 module to filter requests based on source IP geolocation
traefik - The Cloud Native Application Proxy
SuperTokens Community - Open source alternative to Auth0 / Firebase Auth / AWS Cognito
Portainer - Making Docker and Kubernetes management easy.
webauthn - WebAuthn (FIDO2) server library written in Go
jellyfin-media-player - Jellyfin Desktop Client based on Plex Media Player
Keycloak - Open Source Identity and Access Management For Modern Applications and Services
docker-pi-hole - Pi-hole in a docker container