SELFHOST.COMPUTER

Caddy vs Nginx vs Traefik

All three put HTTPS in front of your apps. They differ in how much you write by hand and what they know about Docker. For a single small server the choice is easier than the internet makes it sound. Last checked: .

The short version

  • Caddy: the least config. Certificates are automatic and a site is three lines. Best for most single-server setups.
  • Nginx: the most documentation and the most control. Needs certbot or similar for HTTPS. Best if you already know it or need unusual tuning.
  • Traefik: reads Docker labels, so new containers get routed without editing a central file. Best if you add and remove containers often.

Side by side

CaddyNginxTraefik
HTTPS certificatesAutomatic, built inSeparate tool (certbot, acme.sh)Automatic, built in
Config styleOne short CaddyfileVerbose config filesStatic config plus labels on each container
New app meansAdd a block, reloadAdd a server block, reload, get a certAdd labels to the container
Learning curveGentleModerate; huge amount of existing helpSteeper; more concepts (routers, services, middlewares)
FootprintSmallSmallestSmall, a bit more than the others
Docker awarenessThrough a plugin or by service nameNoneNative

Pick Caddy if

You have one server and a handful of apps, and you'd rather not think about certificates. That covers most readers here. The Docker and Caddy post is a complete setup, and the Compose generator writes the files for you.

Pick Nginx if

You run it already, you need fine-grained control (caching rules, complex rewrites, specific TLS tuning), or you're serving a lot of static files and want every last bit of efficiency. Nginx is also the safe pick when a guide you're following assumes it. The price is more files to write and a separate certificate tool to keep working.

Pick Traefik if

You spin containers up and down regularly and don't want to touch a proxy file each time. Labels on the container are the single source of truth. Be aware that the label syntax takes a while to get comfortable with, and mistakes show up as a 404 rather than an error message.

The gotcha all three share

Don't publish app ports to the internet. Put the apps on an internal Docker network and let only the proxy publish 80 and 443. Docker ignores ufw rules for published ports, as covered in the first 15 minutes post.

Not sure the server has room for it all? The proxy itself is tiny. The apps behind it are what the size calculator counts.