If you've done any self-hosting - a homelab, internal services, a small team's own tooling - you've probably been through this ritual:
A service is running, you want to put a domain and HTTPS in front of it. So you install nginx, write a reverse-proxy config, install certbot, request a Let's Encrypt cert, and wire up a cron job to renew it. Three months later, the day the cert expires, you discover the cron path was wrong, or certbot's webroot mode is fighting your nginx config, and the site is a wall of red.
The third time I went through this, I decided to replace the whole thing. The short version: for self-hosted HTTPS, Caddy + DNS-01 gets you to "set it once, never touch it again." Here's the part that's actually worth knowing.
1. What Caddy's automatic HTTPS actually saves you
Caddy's most underrated feature is that the entire ACME flow is built in. No separate certbot, no renewal cron. A whole Caddyfile can be this short:






