← BACK TO FORUM INDEX

Caddy vs Nginx Proxy Manager vs Traefik: Reverse Proxies for Self-Hosting

BY | Sep 4, 2026 | Self Hosted Email

Caddy vs Nginx Proxy Manager vs Traefik: Reverse Proxies for Self-Hosting in 2026

Storage, hypervisors, and containers get the attention. The piece that actually publishes your apps is the reverse proxy. In a hybrid lab the proxy sits between Cloudflare (or a mesh VPN) and Nextcloud, Immich, Grafana, Portainer, Mailcow, and everything else.

Three options dominate homelabs in 2026: Caddy, Nginx Proxy Manager (NPM), and Traefik. They all terminate TLS and route hostnames. They do not all fit the same operator.

What the Proxy Is For

TLS

One Place for Certificates

Let’s Encrypt, DNS-01, or origin certs should live on the proxy — not copied into every container.

Routing

Hostname to Service

photos.example.com → Immich, git.example.com → Forgejo, without opening a new WAN port per app.

Control

Access Policy at the Edge

Forward-auth, IP allowlists, and websocket support belong here so apps stay off the public internet.

The Three Contenders

Automatic HTTPS

Caddy

Config is a Caddyfile. Certificates happen by default. Excellent for a small, version-controlled lab. Less “click ops,” more text you can back up in Git.

GUI Homelab Standard

Nginx Proxy Manager

The usual pick next to Unraid, Docker, and Cloudflare. Hosts, SSL, and redirections from a web UI. Fast to learn. Easy to outgrow if you need dynamic config.

Container Native

Traefik

Reads Docker/Kubernetes labels and builds routes as stacks come up. Best when apps are ephemeral. Steeper first week than NPM.

Day-2 Work

Backups and Drift

NPM lives in a database plus cert volume. Caddy and Traefik prefer files and labels you can diff. Pick the failure mode you can restore at 2 a.m.

Auth

Forward-Auth / SSO

All three can sit in front of Authelia or Authentik. Traefik middlewares and Caddy matchers are more flexible. NPM is enough for many labs.

Hybrid

Cloudflare + Mesh VPN

Typical 2026 path: Cloudflare or Tunnel → proxy → app on LAN or Tailscale. The proxy should not be the only layer, and it should not require a WAN pinhole per container.

A Practical 1-2-3

1 — Put TLS on the proxy only

Apps listen on HTTP inside the Docker network or mesh. The proxy owns certificates. Do not duplicate Let’s Encrypt inside every stack.

2 — Publish fewer public hostnames

Admin UIs (Portainer, Proxmox, NAS) belong on Tailscale/Netbird, not on the same proxy vhost list as the family photo app.

3 — Backup the proxy like it is production

NPM data volume, Caddyfile, or Traefik dynamic config plus cert storage. If the proxy dies, every pretty hostname dies with it.

Which One Should You Run?

Choose NPM if

You want a GUI, a handful of stable hostnames, and the same workflow as most Unraid/Docker homelab guides.

Choose Caddy if

You want automatic HTTPS, a short config file in Git, and you are fine editing text instead of clicking hosts.

Choose Traefik if

Stacks come and go, you already label containers, or you are heading toward Swarm/Kubernetes-style routing.

Official Resources

Questions for the Community

What are you running in front of your apps?

Caddy, NPM, Traefik, raw Nginx, or Cloudflare Tunnel only?

What made you switch?

Was it SSL pain, Docker labels, a GUI, or a restore after the proxy volume vanished?

Hybrid reality

How do you split public hostnames from admin tools that should stay on the mesh?

The reverse proxy is the control plane for a self-hosted lab. Pick the one you can restore, not the one with the most blog posts.

Disclaimer

This content is for educational and informational purposes only. It is not technical advice. Proxy and TLS changes can take sites offline. Test on a staging hostname and keep a working backup of proxy config and certificates.

DISCUSSION

No replies yet. Be the first to join the discussion!

A1 AI Assistant
Call Text A1 Forum Tech News Contact Form