TLS certificates
Every domain has a TLS mode. The default, Automatic, needs nothing from you: Caddy on your server obtains and renews a Let’s Encrypt certificate as soon as DNS points at it.
TLS modes
Section titled “TLS modes”| Mode | Value | How the certificate is obtained | Publicly trusted |
|---|---|---|---|
| Automatic (Let’s Encrypt) | auto |
ACME HTTP-01 / TLS-ALPN-01 on ports 80/443 | Yes |
| DNS-01 (wildcard) | dns |
ACME DNS-01 through a Cloudflare API token | Yes |
| Custom certificate | custom |
You upload certificate, private key and optional chain | Depends on your CA |
| Internal CA | internal |
Caddy’s local CA (self-signed) | No |
| Off (HTTP only) | off |
none | — |
Change the mode per domain in the domains table under Settings → Networking.
Automatic
Section titled “Automatic”Requirements:
- DNS for the name points at the server (or load balancer), and records are not proxied.
- Ports 80 and 443 are reachable from the internet (the server firewall allows them by default for app, web and lb servers; check your cloud provider’s security groups).
The ACME account e-mail is FALAK_ACME_EMAIL (set by the installer from --email). FALAK_ACME_CA overrides the ACME directory (for example Let’s Encrypt staging).
DNS-01 with Cloudflare
Section titled “DNS-01 with Cloudflare”Use DNS-01 for wildcard names (*.example.com), for servers not reachable on port 80, or behind a proxy.
- Create a Cloudflare API token with Zone → DNS → Edit for the zone (at least 20 characters).
- In Settings → Networking, under DNS providers, click Add, choose Cloudflare, name it and paste the token. Tokens are shared by the organization (permission
edge.dns.manage, admins). - Set the domain’s TLS mode to DNS-01 and pick the credential.
Custom certificates
Section titled “Custom certificates”Upload under Settings → Networking → Custom certificates: the certificate (PEM), the private key and an optional chain, up to 64 KiB each. Falak installs it on every server routing the site. Then set the domain’s TLS mode to Custom and select it. You are responsible for renewals.
Internal CA
Section titled “Internal CA”Caddy issues a certificate from its own local CA. Browsers show a warning unless you trust that CA. Use it for private networks only. Health checks do not verify internal-CA certificates.
Alerts
Section titled “Alerts”edge.certificate_failed(critical) when installing a certificate fails.edge.certificate_installed(info) when it recovers.
Troubleshooting
Section titled “Troubleshooting”| Symptom | Fix |
|---|---|
| Certificate stays pending | Run the DNS check. The name must point at the server and not be proxied. Ports 80/443 must be open in your cloud firewall. |
| Let’s Encrypt rate limit errors | Too many certificates for the same registered domain (common on shared sslip.io names). Use your own domain. |
| Browser warns about the certificate | The domain uses Internal CA, or a custom certificate without its chain. |