Star 历史趋势
数据来源: GitHub API · 生成自 Stargazers.cn
README.md

Caddy Proxy Manager

A modern web interface for managing Caddy reverse proxy hosts.

Add, edit and delete proxy hosts from a clean UI — let Caddy handle TLS, HTTP/2, HSTS and automatic certificates for you.

CI Go React Caddy License


[!WARNING] This project is under active development and not yet considered stable. Use at your own risk and review the configuration before exposing it publicly.

✨ Features

  • Host management — create, edit and delete hosts with multiple domains and upstream backends.
  • Two ways to drive Caddy, switchable at runtime:
    • 📝 Caddyfile mode (default) — renders a per-host Caddyfile snippet and reloads Caddy.
    • 🔌 API mode — manages Caddy's JSON config through the admin API, one route per host, no reload required.
  • Flexible authentication — local email/password or external OIDC/OAuth (Authelia, Keycloak, Authentik, …) with just-in-time user provisioning.
  • Single binary — a modern SPA (Vite · React · TypeScript · Tailwind · shadcn/ui) embedded directly in the Go binary, or served from an external directory.
  • Container-ready — multi-stage Docker image that bundles Caddy and starts everything for you.

🚀 Quick start (Docker)

docker run -d --name cpm \
  -p 3001:3001 -p 80:80 -p 443:443 \
  -v cpm-data:/data \
  ghcr.io/pacerino/caddyproxymanager

Then open http://localhost:3001 and sign in with the default credentials:

EmailPassword
admin@example.comchangeme

[!IMPORTANT] Change the defaults via CPM_ADMIN_EMAIL / CPM_ADMIN_PASSWORD on first run.

The container starts Caddy (with its admin API) and CPM in api mode. Mount your own Caddy config at /data/caddy.json to customise it.

🏗️ How it works

┌──────────────┐      ┌──────────────────────┐      ┌─────────────────┐
│   Browser    │ ───► │  CPM (Go + embedded  │ ───► │      Caddy      │
│  (React SPA) │      │   React frontend)    │      │ (reverse proxy) │
└──────────────┘      └──────────┬───────────┘      └─────────────────┘
                                 │
                  Caddyfile mode │ writes host_<id>.conf + reload
                       API mode  │ PUT/PATCH/DELETE via admin API

CPM stores hosts in a local SQLite database and applies each change to Caddy using the selected provider.

⚙️ Configuration

All settings are environment variables prefixed with CPM_.

Caddy

VariableDefaultDescription
CPM_CADDY_MODEcaddyfileProvider to use: caddyfile or api.
CPM_CADDY_ADMINURLhttp://localhost:2019Caddy admin API base URL (API mode + api reload).
CPM_CADDY_SERVERNAMEsrv0HTTP server name routes are managed under (API mode).
CPM_CADDY_LISTEN:80,:443Listen addresses for the bootstrapped server (API mode); use e.g. :8080 for local non-root testing.
CPM_CADDY_RELOADSTRATEGYsystemdReload strategy (Caddyfile mode): systemd, exec, api or none.
CPM_CADDY_BINARYcaddyCaddy executable for the exec reload strategy.
CPM_CADDY_SERVICEcaddy.servicesystemd unit for the systemd reload strategy.
CPM_CADDYFILE/etc/caddy/CaddyfileMain Caddyfile (used by exec/api reload).

Authentication

VariableDefaultDescription
CPM_AUTH_MODElocallocal or oidc.
CPM_AUTH_OIDC_ISSUEROIDC issuer URL (e.g. Keycloak/Authelia).
CPM_AUTH_OIDC_CLIENTIDOIDC client ID.
CPM_AUTH_OIDC_CLIENTSECRETOIDC client secret.
CPM_AUTH_OIDC_REDIRECTURLCallback URL, e.g. https://cpm.example.com/api/auth/oidc/callback.
CPM_AUTH_OIDC_SCOPESopenid,profile,emailRequested scopes.
CPM_AUTH_OIDC_ALLOWEDDOMAINSOptional email-domain allowlist for JIT provisioning.

General

VariableDefaultDescription
CPM_DATAFOLDER/etc/caddy/Data + per-host config folder.
CPM_LOGFOLDER/var/log/caddyPer-host log folder.
CPM_FRONTENDDIRServe the frontend from this directory instead of the embedded assets.
CPM_ADMIN_EMAILadmin@example.comSeed admin email (first run, local mode).
CPM_ADMIN_PASSWORDchangemeSeed admin password (first run, local mode).

🧑‍💻 Development

Prerequisites: Go 1.24+, Node 22+, and a local Caddy for end-to-end testing.

Run the backend and frontend in two terminals:

# Terminal 1 — backend on :3001
cd backend
CPM_DATAFOLDER=./data CPM_LOGFOLDER=./data CPM_CADDY_RELOADSTRATEGY=none \
  go run ./cmd/main.go

# Terminal 2 — frontend dev server on :5173 (proxies /api → :3001)
cd frontend
npm install
npm run dev

Open http://localhost:5173 and log in with admin@example.com / changeme.

Building a single binary

cd frontend && npm run build      # emits into backend/embed/assets
cd ../backend && go build ./cmd/main.go

Testing

cd backend && go test ./...       # backend
cd frontend && npm run build      # frontend type-check + build

CI (.github/workflows/ci.yml) runs the backend tests, builds the frontend, and publishes the Docker image to GHCR on pushes to master and version tags.

🐳 Building the image yourself

docker build -t caddyproxymanager .

The multi-stage build compiles the frontend and backend (a pure-Go build, no C toolchain required) into a small Alpine runtime that bundles Caddy.

❓ FAQ

Should I use Caddyfile mode or API mode?

Use Caddyfile mode (the default) for the simplest setup — CPM writes snippets that Caddy imports, and you keep all of Caddy's conveniences (automatic HTTPS, HSTS, HTTP/2). Use API mode when you want CPM to manage Caddy's live JSON config directly through the admin API, with no reloads.

Can I use external SSO (Authelia, Keycloak, Authentik …)?

Yes. Set CPM_AUTH_MODE=oidc and configure the CPM_AUTH_OIDC_* variables. On first successful login CPM provisions the matching user automatically (JIT). Restrict access with CPM_AUTH_OIDC_ALLOWEDDOMAINS.

Does CPM run Caddy for me?

The Docker image does — its entrypoint launches Caddy with the admin API and then CPM. For bare-metal installs, run Caddy yourself and point CPM at it (CPM_CADDYFILE / CPM_CADDY_ADMINURL) with the appropriate reload strategy.

🗺️ Roadmap

  • Log viewer
  • Plugin management
  • Per-host advanced directives

🙌 Acknowledgements

Inspired by the excellent Nginx Proxy Manager by jc21 — go check it out. CPM brings the same idea to Caddy.

🤝 Contributing

Pull requests and issues are welcome! Please open an issue to discuss larger changes first.

📄 License

MIT

关于 About

CaddyProxyManager - Manage Caddy via a web interface
caddycaddyserverreverse-proxywebinterface

语言 Languages

Go69.9%
TypeScript25.8%
Shell2.2%
CSS1.0%
Dockerfile0.9%
Handlebars0.2%
HTML0.1%

提交活跃度 Commit Activity

代码提交热力图
过去 52 周的开发活跃度
19
Total Commits
峰值: 19次/周
Less
More

核心贡献者 Contributors