Skip to content

How to obtain an SSL certificate via Caddy

What separates Caddy from other proxy services is that it automatically gets SSL certificates for your services (from Let's Encrypt).

Once you've added the record (of your site) to your Caddyfile, all you have to do is restart Caddy and then wait for the magic to happen.

Here's a step by step walkthrough:

  1. Restart Caddy

    cd ~/services
    docker compose restart caddy
    
  2. Check the Caddy logs

    cd ~/services
    docker compose logs -f caddy
    

    You should see something like this:

    caddy  | {"level":"info","ts":1735415790.7010942,"logger":"http.acme_client","msg":"authorization finalized","identifier":"yourservice.yourdomain.com","authz_status":"valid"}
    caddy  | {"level":"info","ts":1735415790.7011356,"logger":"http.acme_client","msg":"validations succeeded; finalizing order","order":"https://acme-v02.api.letsencrypt.org/acme/order/2029509207/338245143465"}
    caddy  | {"level":"info","ts":1735415791.4802299,"logger":"http.acme_client","msg":"got renewal info","names":["yourservice.yourdomain.com"],"window_start":1740511049,"window_end":1740683849,"selected_time":1740651785,"recheck_after":1735437391.480223,"explanation_url":""}
    caddy  | {"level":"info","ts":1735415791.8548343,"logger":"http.acme_client","msg":"got renewal info","names":["yourservice.yourdomain.com"],"window_start":1740511049,"window_end":1740683849,"selected_time":1740545750,"recheck_after":1735437391.8548286,"explanation_url":""}
    caddy  | {"level":"info","ts":1735415791.854933,"logger":"http.acme_client","msg":"successfully downloaded available certificate chains","count":2,"first_url":"https://acme-v02.api.letsencrypt.org/acme/cert/0347f48843e5fe82ce606dae879df25b42d9"}
    caddy  | {"level":"info","ts":1735415791.8558862,"logger":"tls.obtain","msg":"certificate obtained successfully","identifier":"yourservice.yourdomain.com","issuer":"acme-v02.api.letsencrypt.org-directory"}
    caddy  | {"level":"info","ts":1735415791.8561459,"logger":"tls.obtain","msg":"releasing lock","identifier":"yourservice.yourdomain.com"}
    
    caddy  | {"level":"info","ts":1735415790.7010942,"logger":"http.acme_client","msg":"authorization finalized","identifier":"audiobookshelf.akdscloud.eu","authz_status":"valid"}
    caddy  | {"level":"info","ts":1735415790.7011356,"logger":"http.acme_client","msg":"validations succeeded; finalizing order","order":"https://acme-v02.api.letsencrypt.org/acme/order/2029509207/338245143465"}
    caddy  | {"level":"info","ts":1735415791.4802299,"logger":"http.acme_client","msg":"got renewal info","names":["audiobookshelf.akdscloud.eu"],"window_start":1740511049,"window_end":1740683849,"selected_time":1740651785,"recheck_after":1735437391.480223,"explanation_url":""}
    caddy  | {"level":"info","ts":1735415791.8548343,"logger":"http.acme_client","msg":"got renewal info","names":["audiobookshelf.akdscloud.eu"],"window_start":1740511049,"window_end":1740683849,"selected_time":1740545750,"recheck_after":1735437391.8548286,"explanation_url":""}
    caddy  | {"level":"info","ts":1735415791.854933,"logger":"http.acme_client","msg":"successfully downloaded available certificate chains","count":2,"first_url":"https://acme-v02.api.letsencrypt.org/acme/cert/0347f48843e5fe82ce606dae879df25b42d9"}
    caddy  | {"level":"info","ts":1735415791.8558862,"logger":"tls.obtain","msg":"certificate obtained successfully","identifier":"audiobookshelf.akdscloud.eu","issuer":"acme-v02.api.letsencrypt.org-directory"}
    caddy  | {"level":"info","ts":1735415791.8561459,"logger":"tls.obtain","msg":"releasing lock","identifier":"audiobookshelf.akdscloud.eu"}
    

Basically, if it says "certificate obtained successfully", you're good to go.

Success

And that's it!
Enjoy accessing your service via HTTPS!