Caddy
Reverse Proxy & GatewaysFast, multi-platform web server with automatic HTTPS
Replaces Nginx, Apache
Route and secure your services with self-hosted reverse proxies, gateways, and ingress managers.
121 self-hosted apps · 154 comparisons
Fast, multi-platform web server with automatic HTTPS
Replaces Nginx, Apache
Cloud-native reverse proxy and load balancer
Replaces HAProxy, AWS ELB
Blackhole for Internet advertisements with a GUI for management
Replaces NextDNS
Pure shell ACME client for TLS certificates
Replaces Certbot
Interactive HTTPS proxy for inspection and debugging
Replaces Charles Proxy, Fiddler
Cloud-native, fast, scalable API gateway
Replaces AWS API Gateway, Apigee
Full-featured service mesh for traffic and security control
Replaces AWS App Mesh
Network-wide DNS ad and tracker blocker
Replaces Pi-hole, NextDNS
Lightweight proxy server for intranet penetration
Replaces ngrok
Easy reverse proxy management with a web UI and free SSL
Replaces Cloudflare
High-performance web server and reverse proxy
Replaces Apache, IIS
Authentication and authorization server for reverse proxies
Replaces Okta, Cloudflare Access
Cloud-native high-performance edge and service proxy
Replaces Nginx, HAProxy
Rust framework to build fast, reliable network services
Replaces Nginx
Open-source identity provider with proxy outpost
Replaces Okta, Auth0
Self-hosted tunneled reverse proxy with identity access
Replaces Cloudflare Tunnel
Self-hosted web application firewall with a web console
Replaces Cloudflare WAF
Proof-of-work proxy to block AI scraper bots
Replaces Cloudflare Bot Management
Kubernetes ingress controller using NGINX
Replaces AWS ALB Ingress
Automatic dynamic DNS updater with a web interface
Replaces No-IP, DynDNS
Dynamic, real-time, high-performance API gateway
Replaces Kong, AWS API Gateway
Lightweight encrypted SOCKS5 proxy
Replaces commercial VPN proxies
Proxy server to bypass Cloudflare and DDoS-GUARD protection
Free and open source speedtest
Replaces Speedtest.net
Reverse proxy that adds authentication to any web app
Replaces Cloudflare Access
Collaborative open-source intrusion prevention system
Replaces Cloudflare WAF, Fail2ban
Flexible, plugin-based DNS server
Replaces BIND, dnsmasq
Automated TLS certificate management for Kubernetes
Replaces Certbot
Scalable web platform extending Nginx with Lua
Replaces Nginx
Encrypted DNS proxy supporting DNSCrypt and DoH
Replaces Cloudflare WARP
Nginx-derived web server with extra features
Replaces Nginx
All in one IP Toolbox
Ultralight, security-first service mesh for Kubernetes
Replaces Istio, AWS App Mesh
Modern PHP application server built on Caddy
Replaces nginx, Apache HTTP Server
Local DNS server that picks the fastest results
Replaces Pi-hole, dnsmasq
Fast and secure standalone server for resizing and converting remote
Next-gen Web Application Firewall (WAF) that will protect your web
Open-source API gateway and management platform
Replaces Apigee, AWS API Gateway
Self-hosted DNS server with ad-blocking and a web console
Replaces Pi-hole, AdGuard Home
Let's Encrypt and ACME client written in Go
Replaces Certbot
Reverse proxy toolkit for building proxies in .NET
Replaces Nginx
Synchronize Kubernetes services with DNS providers
Replaces Route 53 manual records
Simplest way to protect your apps with a login screen
Replaces Cloudflare Access
IPv4 over DNS tunnel solution, enabling you to start up a socks5 proxy
Zero-config load balancer driven by Consul
Replaces HAProxy, Nginx
Fast DNS proxy and ad-blocker for local networks
Replaces Pi-hole, AdGuard Home
Reliable, high-performance TCP/HTTP load balancer
Replaces F5 BIG-IP, AWS ELB
eBPF-based transparent proxy with traffic splitting
Replaces Clash
Lightweight HTTP and HTTPS forward proxy daemon
Replaces Squid
Dynamic application server and reverse proxy
Replaces Passenger, uWSGI
General-purpose HTTP reverse proxy and forwarding tool
Replaces Nginx Proxy Manager
Tiny multi-protocol proxy server suite
Replaces Squid
Web interface for managing WireGuard configurations
Replaces OpenVPN Access Server
Protocol multiplexer that shares one port between services
Replaces HAProxy
An invisible shield for your browsing experience
Identity-aware reverse proxy for zero-trust access
Replaces Cloudflare Access, BeyondCorp
HTTP(S)/WS(S)/TCP tunnels to localhost using only SSH (serveo/ngrok
Modern Shadowsocks proxy implementation in Go
Replaces VPN
Generate Caddy reverse proxy config from Docker labels
Replaces Traefik
Kubernetes-native API gateway built on Envoy
Replaces AWS API Gateway, Kong
Lightweight, simple, and performant reverse proxy with WebUI, Docker
High-performance HTTP accelerator and caching proxy
Replaces Cloudflare, Squid
The world's most widely used web server
Replaces Nginx, IIS
Universal service mesh for Kubernetes and VMs
Replaces Istio, Linkerd
Kubernetes ingress controller powered by Envoy
Replaces AWS ALB Ingress
OpenBSD load balancer and relay daemon
Replaces HAProxy, F5 BIG-IP
Open-source enterprise-grade web application firewall
Replaces ModSecurity, Cloudflare WAF
Free & Open-Source HTML5 Network Performance Estimation Tool
Flexible plugin-based forwarding DNS server
Replaces AdGuard DNS
Hot-reconfigurable HTTP reverse proxy in Rust
Replaces HAProxy, Nginx
Secure web application gateway with Nginx and Certbot
Replaces Cloudflare
HTTP router and reverse proxy for service composition
Replaces Nginx, Traefik
Caching and forwarding HTTP web proxy
Replaces Cloudflare Gateway
Generates lightweight, embedded honeypot triggers called canary tokens
Small self-contained pure-Go web server with Lua, Markdown, HTTP/2,
Speed test analysis software that shows your internet speed for up
Next-generation Kubernetes traffic routing standard
Replaces Kubernetes Ingress
Scale services to zero and start them on demand
Replaces AWS Lambda
Ultra-high-performance API gateway
Replaces AWS API Gateway, Kong
Drop-in nginx fork with extended features
Replaces nginx
Centralized syslog server with real-time web UI
Cross-platform, high-performance, and asynchronous web server
Configurable reverse proxy from the Pingora project
Replaces nginx, HAProxy
Honeypot framework designed to provide a highly secure environment
Lightweight service mesh built on Traefik
Replaces Istio, Linkerd
Modern L4 load balancer and reverse proxy
Replaces HAProxy, NGINX Plus
Fast, scalable caching proxy server
Replaces Varnish, Squid
Local ad blocker
Web management panel for the frp reverse proxy
Replaces ngrok
Synchronize AdGuard Home config to replicas
Layer 4 proxy module for the Caddy server
Replaces HAProxy
Industry-leading high-performance, AI and semantic technology web
Expose your services easily and securely
Reverse proxy built on Cloudflare's Pingora framework
Replaces nginx
Network relay tool for forwarding traffic over many transports
Replaces Shadowsocks
Download torrents with your Umbrel
Flexible DNS forwarding proxy with per-client policy
Replaces NextDNS
Forward proxy server supporting proxy chaining, protocol inspection,
The Unifi-controller software is a powerful, enterprise wireless
Kubernetes ingress controller based on HAProxy
Replaces AWS ALB Ingress
Open-source API management platform
Replaces Apigee, MuleSoft
REST API for dynamic HAProxy configuration
Replaces NGINX Plus API
The open-source browser project
Duck DNS is a free Dynamic DNS service
Geo-blocking middleware plugin for Traefik
Replaces Cloudflare WAF
Update DNS records on Cloudflare
Privacy-enhancing web proxy with content filtering
Replaces commercial ad-filtering proxies
Wake On LAN Machine Manager based on network traffic
SOCKS5 proxy server with built-in authentication and Telegram-bot
Lightweight reverse proxy and HTTPS load balancer
Replaces NGINX, HAProxy
Access your Umbrel apps from the Internet using Cloudflare network
Update your Gandi DNS zone records with your WAN IP
Run Urbit on your Umbrel
Manage multiple holesail P2P tunnels from a single dashboard
Secure, fast, compliant, and very flexible web server that has been
Web application accelerator/caching HTTP reverse proxy (formerly
Firefox is a free and open-source web browser
Help defeat internet censorship
Remote access screen and file sharing
Twingate Connector for CasaOS
World's most advanced adblocker!
No apps match these filters.
Last reviewed Aug 26, 2026 · 455 words
Caddy is the right reverse proxy for most self-hosters: three lines of config per service, automatic HTTPS, a single 64 MB binary. The rest of this page covers the cases where it isn't, and the sizable slice of this category (DNS blockers, API gateways, debugging proxies) that isn't a reverse proxy at all.
Configuration model is the real differentiator, because all the serious contenders handle TLS automatically. Caddy uses a static Caddyfile you edit and reload — obvious to read, easy to version-control. Traefik inverts that: it watches Docker labels and configures itself as containers appear, which is superb once you run 15 services and opaque while you learn it. Nginx Proxy Manager puts a web UI over Nginx — click to add a proxy host, click again for a Let's Encrypt certificate — on about 256 MB. The full head-to-head between the first two is in Caddy vs Traefik.
Second axis: environment. On a single Docker host, any of the three works. On Kubernetes, Traefik is the natural fit, and Kong belongs in the conversation only when you are managing API traffic with rate limiting and auth plugins — it typically wants Postgres and brings a steep configuration curve.
Third: certificate operations, where the beginner mistakes live. Persist Caddy's /data volume, or every container recreate re-issues certificates and burns through Let's Encrypt rate limits. On Nginx Proxy Manager, the admin UI listens on port 81 with a default login of [email protected] / changeme — expose ports 80 and 443 to the internet, never 81, and change that password on first login.
Caddy for anyone comfortable editing a text file: least config, fewest surprises, HTTP/3 included if you keep the 443/udp port mapping. Nginx Proxy Manager for anyone who wants a GUI and a certificate without reading documentation — it is the favorite first proxy in home labs for a reason. Traefik when your services live and die by docker compose and you want routing to follow automatically.
Pi-hole and AdGuard Home are network-wide DNS ad blockers, not proxies — they sit in front of your DNS, not your web apps, and both fight systemd-resolved for port 53 on first install. mitmproxy is an interception tool for debugging HTTPS traffic, explicitly not for production. acme.sh is a certificate client for stacks that don't manage their own. Useful software, wrong shelf.
A first-timer should deploy Caddy, put two services behind it, and stop. Everything else in the category can wait until a concrete need names it.
154 head-to-head comparisons in this category.