• 0 Posts
  • 1 Comment
Joined 7 days ago
cake
Cake day: September 9th, 2026

help-circle
  • Two things that I think are tripping you up:

    1. DNS. Your router only maps proxmox.DOMAIN.com to 192.168.10.22. The other services (in LXCs, with their own container IPs) resolve to nothing, so the browser can’t reach Caddy for them at all - that’s why Proxmox works and the rest don’t. Either add a record per service name pointing at the right IP, or forward those service ports into Caddy.

    2. Certs. If you want to stay fully local (nothing needs the internet), skip DNS challenges entirely: Caddy has a built-in CA (tls internal in the site block). It auto-issues self-signed certs for whatever hostname you hit, no challenge, no DNS. You do need to export that CA and install it as a trusted root on the machines you browse from, but after that every service works with zero DNS configuration.

    Wildcard aside: DNS-01 + wildcard only covers issuance, it doesn’t fix the resolution gap in point 1.

    If you’re open to egress, a quick tunnel (cloudflared) removes cert management completely - Cloudflare terminates TLS on a random public URL. That’s how I expose a small self-hosted API of mine; the trade-off is the URL changes on every tunnel restart.