Elektrine lite

← Feed

@confusedpuppy@lemmy.dbzer0.com

2026-09-22 15:42 UTC

Looking to move from Caddy Recently it’s come to my attention that Caddy has an AI sponsor so I have been looking at moving away from Caddy. I’m currently looking for another reverse proxy to use in place of Caddy. For TLS I am looking into using CertBot and it appears there’s a module (github.com/desec-io/certbot-dns-desec) I can use that works for desec.io to handle my certs. I have two questions, the first is about CertBot. Since Caddy is handling my certs automatically, how often would I want to renew my certs? Desec.io has this command to obtain a cert: certbot certonly \ --authenticator dns-desec \ --dns-desec-credentials /etc/letsencrypt/secrets/$DOMAIN.ini \ -d "$DOMAIN" \ -d "*.$DOMAIN" Would I be required to run the same command periodically to renew my cert? My second question is a bit more open ended. I am looking to hear any suggestions or experiences about different reverse proxies that are preferably free of AI. There is a list here with some suggested alternatives: codeberg.org/ethical-foss/open-slopware#web-serve…

Replies (3)

  • @stratself@lemdro.id 2026-09-23 04:39

    For TLS I am looking into using CertBot and it appears there’s a module (github.com/desec-io/certbot-dns-desec) I can use that works for desec.io to handle my certs. You can consider using lego-acme as well. It’s not too different, just that it comes prepackaged with a bunch of DNS providers including desec, so you don’t need to install an additional module. Since Caddy is handling my certs automatically, how often would I want to renew my certs? By default, certs are valid for 90 days so you’d wanna renew a bit earlier than that. There’s also the option to use 45-day certs or 6-day certs, depending on the profile chosen. Would I be required to run the same command periodically to renew my cert? Yes, but it’s better if you automate them, like Caddy did, and both Certbot and lego can do this well. I run lego via a cronjob which checks for the certs’ expiry, and renew it when it passes a certain deadline. I am looking to hear any suggestions or experiences about different reverse proxies that are preferably free of AI Not sure I can recommend anything from that list because I’m not familiar with them, but I’ve heard haproxy to be very performant.

    Open ##4899481

  • @diecknet@discuss.tchncs.de 2026-09-23 06:25

    I used traefik in the past, but moved to Caddy a while ago. In traefik I had to restart the service to apply the renewed certificate, which I found annoying. Caddy on the other hand just works. Anyway, are you using anything by the Linux Foundation?

    Open ##4902548

  • @dlsolo@lemmy.world 2026-09-22 18:20

    Not glamour but haproxy may be worth the look.

    Open ##4904996