What it is
Caddy Proxy Manager is a web interface and API in front of Caddy. You configure hosts, certificates, firewall rules and access control in the UI; it renders those into a Caddy JSON configuration and applies it over Caddy’s admin API.
The pieces
Section titled “The pieces”| Piece | What it is |
|---|---|
| Controller | The web app and API. Holds the database and decides what the configuration should be |
| Agent | Runs beside Caddy on each host. Applies configuration, recreates the container, and reports back |
| Caddy | The server actually handling traffic |
| PostgreSQL | Where everything is stored. SQLite instead, when DATABASE_URL names a file |
| Socket proxy | The only thing that touches the Docker socket; the agent reaches Docker through it |
| ClickHouse | Optional. Only for analytics |
| CrowdSec | Optional. The security engine behind CrowdSec in managed mode |
The controller never dials the agent. The agent connects out and holds an event stream open, which is what lets a Caddy host sit behind NAT with no inbound port.
What it stores
Section titled “What it stores”Configuration lives in the database, not in a Caddyfile. Caddy’s running configuration is generated from the database on every apply, so the database is the source of truth and the Caddy config is derived - editing Caddy directly will be overwritten on the next apply.
Secrets - DNS provider credentials, private keys, auth keys - are encrypted at rest under the
deployment’s SESSION_SECRET. Settings → Backup exports all of it as one file sealed with a
passphrase of your own, which restores onto a new machine; see backup and
restore.
What it is not
Section titled “What it is not”- Not a Caddyfile editor. You can attach a custom Caddyfile snippet to a host, or add a global Caddyfile to every agent’s config, but the normal path is the form, and neither can replace what CPM generates.
- Not a DNS server. It talks to your DNS provider for ACME DNS-01 challenges; it does not host your zone.
- Not multi-tenant. Roles and group grants delegate specific hosts to specific people, but everyone shares one instance and one configuration.