this post was submitted on 14 Aug 2025
96 points (99.0% liked)

Selfhosted

50554 readers
439 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
top 10 comments
sorted by: hot top controversial new old
[–] lightnegative@lemmy.world 30 points 2 days ago (2 children)

I guess Caddy has been stealing its market share

[–] pier@pcube.social 2 points 2 hours ago

Even though I've been using traefik and caddy more lately, I appreciate that nginx has finally woken up :)

[–] BlueEther@no.lastname.nz 7 points 2 days ago (1 children)

I knew there was a reason that I used Caddy all these years

[–] elvith@feddit.org 13 points 2 days ago

For me it was usually that the config that I need to serve a site with TLS is quite short, there are sensible defaults and many things (e.g. websockets) just work without further declaration. That's especially important if you want to host a container that has some lacking documentation about usage of reverse proxies, as most things "just work fine" for me.

And using a simple include directive, you can even replicate 'sites-available' and 'sites-enabled' behaviour. My standard Caddyfile just sets up the log file format and location and basic Let Encrypt values. Then it includes /foo/bar/sites-available/*. Every deployment/container now has its own Caddyfile that just gets linked there.

[–] theit8514@lemmy.world 14 points 2 days ago (1 children)
[–] missphant@lemmy.blahaj.zone 9 points 2 days ago* (last edited 2 days ago) (2 children)

I believe Let's Encrypt only allows wildcard certs for DNS challenges so it's not really in the scope of Nginx; but I haven't used other web servers, do they implement that?

Edit: Looked into Caddy, it seems to have a plugin system for DNS providers, that's pretty slick. I can't see that ever happening for Nginx they seem very opinionated in wanting to be unopinionated unfortunately. I'm still sad they rejected the PR to implement prefers-color-scheme for default error pages.

[–] tux7350@lemmy.world 2 points 2 days ago

You can setup wild card certs with a DNS challenge using traefik. No plug-ins needed, works right out the box.

Personally, I quite prefer traefik. Its harder to use than Caddy but offers more features. Also, it uses yaml or docker labels for config. I'm not a fan of the nginx .conf format.

[–] Darkassassin07@lemmy.ca 1 points 2 days ago

DNS-01 is in the pipeline at least, so hopefully we'll see that bring wildcard certs along with it.

It's nice to see this being integrated into nginx. I've been using ACME.sh for around a decade instead. It just triggers through a script on a crontab schedule grabbing a new cert via DNS-01 if necessary, then refreshing nginx to recognize the new file.

[–] TheBigRoomXXL@leminal.space 10 points 2 days ago

FINALLY! Caddy has been doing it for years! I still prefere caddy overall but it's nice to have as we don't always choose the stack we work with.

ACME Website Host-inator or idk, i don't know much about networking