Caddy vs Nginx vs Traefik
All three put HTTPS in front of your apps. They differ in how much you write by hand and what they know about Docker. For a single small server the choice is easier than the internet makes it sound. Last checked: .
The short version
- Caddy: the least config. Certificates are automatic and a site is three lines. Best for most single-server setups.
- Nginx: the most documentation and the most control. Needs certbot or similar for HTTPS. Best if you already know it or need unusual tuning.
- Traefik: reads Docker labels, so new containers get routed without editing a central file. Best if you add and remove containers often.
Side by side
| Caddy | Nginx | Traefik | |
|---|---|---|---|
| HTTPS certificates | Automatic, built in | Separate tool (certbot, acme.sh) | Automatic, built in |
| Config style | One short Caddyfile | Verbose config files | Static config plus labels on each container |
| New app means | Add a block, reload | Add a server block, reload, get a cert | Add labels to the container |
| Learning curve | Gentle | Moderate; huge amount of existing help | Steeper; more concepts (routers, services, middlewares) |
| Footprint | Small | Smallest | Small, a bit more than the others |
| Docker awareness | Through a plugin or by service name | None | Native |
Pick Caddy if
You have one server and a handful of apps, and you'd rather not think about certificates. That covers most readers here. The Docker and Caddy post is a complete setup, and the Compose generator writes the files for you.
Pick Nginx if
You run it already, you need fine-grained control (caching rules, complex rewrites, specific TLS tuning), or you're serving a lot of static files and want every last bit of efficiency. Nginx is also the safe pick when a guide you're following assumes it. The price is more files to write and a separate certificate tool to keep working.
Pick Traefik if
You spin containers up and down regularly and don't want to touch a proxy file each time. Labels on the container are the single source of truth. Be aware that the label syntax takes a while to get comfortable with, and mistakes show up as a 404 rather than an error message.
The gotcha all three share
Don't publish app ports to the internet. Put the apps on an internal Docker network and let only the proxy publish 80 and 443. Docker ignores ufw rules for published ports, as covered in the first 15 minutes post.
Not sure the server has room for it all? The proxy itself is tiny. The apps behind it are what the size calculator counts.