Looking to move from Caddy
Recently it’s come to my attention that Caddy has an AI sponsor so I have been looking at moving away from Caddy.
I’m currently looking for another reverse proxy to use in place of Caddy. For TLS I am looking into using CertBot and it appears there’s a module (github.com/desec-io/certbot-dns-desec) I can use that works for desec.io to handle my certs.
I have two questions, the first is about CertBot. Since Caddy is handling my certs automatically, how often would I want to renew my certs? Desec.io has this command to obtain a cert:
certbot certonly \ --authenticator dns-desec \ --dns-desec-credentials /etc/letsencrypt/secrets/$DOMAIN.ini \ -d "$DOMAIN" \ -d "*.$DOMAIN"
Would I be required to run the same command periodically to renew my cert?
My second question is a bit more open ended. I am looking to hear any suggestions or experiences about different reverse proxies that are preferably free of AI. There is a list here with some suggested alternatives: codeberg.org/ethical-foss/open-slopware#web-serve…
I’m also using Certbot with DeSEC. I simply run it daily with
anacron. If it doesn’t need to renew the certs yet it will say so and stop. That’s basically it.I think it’s a very good idea for your LE renewal to be independent of whatever reverse proxy or web server you’re using.
Please keep in mind that Certbot is a Python app so you can manage it with
venv. Here’s how I install it in a dedicated dir (let’s say/srv/letsencryptbecause using/etcis not appropriate and it bugs me 😆):And to update it:
As for renewing certs (the script is longer, I’m making sure to create dirs and so on but this is the gist of it):
For DeSEC you need
secrets/${DOMAIN}.inito contain:dns_desec_token = YOURTOKENHEREPlease note that DeSEC lets you restrict what the token can do, but setting the rights on the token has to be done through their API so you need a separate token for the API 😅.
To use the certs from Caddy, point it at the files under the
config/live/${DOMAIN}/dir (which are symlinks that are maintained by Certbot), NOT the ones underarchive/.tls /path/to/certbot/config/live/example.com/fullchain.pem /path/to/certbot/config/live/example.com/privkey.pemOr, if you want to also add mTLS to the mix:
Let me know if you have questions.
This is great, thank you for taking the time for this write up :) The provided scripts are a huge help to me
So far my only question I have is about the directories you use. I was wondering if you could provide the directories you use or even just an example so I could better understand the file tree. I’m very particular with my files and have a whole system dedicated to maintaining neat and organized files
I agree about not using /etc for server related stuff. I keep all my server/container related stuff in /srv so it’s easier for me to manage
The dirs are subdirs of
/srv/letsencrypt. I like to take advantage of explicit dir assignment if the software allows it, so I don’t have any surprises if the defaults change.Awesome, thanks so much, this is a big head start for me
I have a good idea how I want to organize things now