Three Caddy notes I keep re-learning

1. fmt and validate before every restart

Half of my "Caddy is broken" moments were a missing brace or a stray comma. The habit that fixed it:

caddy fmt --overwrite /etc/caddy/Caddyfile
caddy validate --config /etc/caddy/Caddyfile
systemctl restart caddy

fmt is not cosmetic here: when it re-indents a block strangely, that block is usually missing a brace.

2. Certificate renewal is port 80 plus DNS

Every renewal failure I have actually had was one of three things: port 80/tcp unreachable in the firewall, DNS pointing somewhere else, or the domain expired. Ten seconds to tell which:

journalctl -u caddy --no-pager | grep -i renew

The certificate plumbing itself has never once been the problem.

3. file_server can serve pre-compressed files

file_server {
    precompressed zstd br gzip
}

If index.html.zst (or .br, .gz) sits next to index.html, Caddy sends the best variant the client supports as-is — no per-request compression work. One real footgun: the sibling is served as long as it exists. Edit the HTML and forget to regenerate the compressed copies, and visitors happily receive the stale version. My fix is a two-line script that rebuilds them; it runs as part of "I edited the site", same as the reload.

← All notes