Compose + Caddy Generator
Tick the apps, type your domain, and copy two files. Only Caddy publishes ports (80 and 443). Every app sits behind it on the internal Docker network, so there's nothing for Docker to leak past your firewall. Everything runs in your browser; nothing is sent anywhere.
compose.yaml
Caddyfile
Use it
mkdir -p ~/stack && cd ~/stack # save the two files here as compose.yaml and Caddyfile docker compose up -d docker compose logs -f caddy
If Caddy can't get a certificate, it's almost always DNS (the records aren't pointing at the server yet) or port 80 being blocked. The Caddy post explains each piece, and the first 15 minutes covers the firewall.
What the generator doesn't do
- Pin versions.
latestis fine for a first run. Pin tags once it works, so an update doesn't surprise you. - Make backups. Volumes are named, which is what you want for restic. Use the backup planner to size it.
- Handle everything. Immich, Pi-hole and game servers need ports or extra services that don't fit a simple generator, so they're left out on purpose.
Not sure the box is big enough for what you ticked? Check it in the VPS size calculator.