Skip to content

What it is

Caddy Proxy Manager is a web interface and API in front of Caddy. You configure hosts, certificates, firewall rules and access control in the UI; it renders those into a Caddy JSON configuration and applies it over Caddy’s admin API.

Piece What it is
Controller The web app and API. Holds the database and decides what the configuration should be
Agent Runs beside Caddy on each host. Applies configuration, recreates the container, and reports back
Caddy The server actually handling traffic
PostgreSQL Where everything is stored. SQLite instead, when DATABASE_URL names a file
Socket proxy The only thing that touches the Docker socket; the agent reaches Docker through it
ClickHouse Optional. Only for analytics
CrowdSec Optional. The security engine behind CrowdSec in managed mode

The controller never dials the agent. The agent connects out and holds an event stream open, which is what lets a Caddy host sit behind NAT with no inbound port.

Configuration lives in the database, not in a Caddyfile. Caddy’s running configuration is generated from the database on every apply, so the database is the source of truth and the Caddy config is derived - editing Caddy directly will be overwritten on the next apply.

Secrets - DNS provider credentials, private keys, auth keys - are encrypted at rest under the deployment’s SESSION_SECRET. Settings → Backup exports all of it as one file sealed with a passphrase of your own, which restores onto a new machine; see backup and restore.

  • Not a Caddyfile editor. You can attach a custom Caddyfile snippet to a host, or add a global Caddyfile to every agent’s config, but the normal path is the form, and neither can replace what CPM generates.
  • Not a DNS server. It talks to your DNS provider for ACME DNS-01 challenges; it does not host your zone.
  • Not multi-tenant. Roles and group grants delegate specific hosts to specific people, but everyone shares one instance and one configuration.