Hello! I have 2 services that are only being accessed locally but require HTTPS so I am using Caddy & DuckDNS w/ DNS-01 to reverse proxy them. In DuckDNS, both subdomains are pointing at the local IP address of Caddy, and my Caddyfile has:

service1.duckdns.org:443 {
        tls {
                dns duckdns {
                        api_token API-TOKEN
                }
        }
        reverse_proxy 192.168.0.51:8080
	}

service2.duckdns.org:443 {
        tls {
                dns duckdns {
                        api_token API-TOKEN
                }
        }
        reverse_proxy 192.168.0.20:8080
	}

The issue is that I can access https://service1.duckdns.org/ (within my home network), but I can’t access https://service2.duckdns.org/ (502 Bad Gateway). Caddy is running in a LXC in Proxmox, and Service1 is on a different VM on the same Proxmox machine, while Service2 is on a different machine on my network. I don’t see any entries in my router’s firewall logs or PiHole that indicates something is blocking it. I enabled logging in Caddy for both services and I am only able to see activity for Service1, so I guess that means something is blocking Service2 from reaching Caddy entirely?

I’m able to access service2 directly from the IP address but I’m a novice in networking so I’m trying to understand and learn what could be causing this. Any help would be appreciated!

Edit: service2 is ActualBudget and I had configured it to use the certs using the instructions here (https://actualbudget.org/docs/config/https/) when I didn’t need to (since Caddy handles all of this already… i think)

  • dimjim@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    3
    ·
    1 day ago

    This is the right approach, I’ve had several services require extra bits in the caddy config such as:

    reverse_proxy 192.168.50.6:8006 { transport http { tls_insecure_skip_verify } }

    I would do a search for “your service & caddy”, someone probably has ran into the same issue.

    • HoodedBandit@lemmy.zip
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 day ago

      FWIW, here is my ActualBudget Caddy config.

      budget.example.com {
          reverse_proxy actual-server:5006 {
              header_down -Access-Control-Allow-Origin
              header_down Cross-Origin-Opener-Policy same-origin
              header_down Cross-Origin-Embedder-Policy credentialless
          }
      }
      
      • dimjim@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 day ago

        I’ve never used ActualBudget, but their docs have a slightly different caddy example config:

        budget.example.org {
            encode gzip zstd
            reverse_proxy actual_server:5006
        }```