{"repo":"brickpop/tailcaddy","free":true,"listed":false,"github":"https://github.com/brickpop/tailcaddy","clone":"git clone https://github.com/brickpop/tailcaddy.git","description":"Your own domain and real HTTPS for self-hosted services, reachable only over your Tailscale network. Caddy + Cloudflare DNS + Tailscale, in a single Docker image.","language":"Dockerfile","stars":24,"topics":[],"license":null,"category":"self-hosted-apps","readme_excerpt":"TailCaddy Friendly HTTPS for self-hosted services, reachable only over your tailnet. Put your local apps behind clean hostnames like cloud.example.com with valid, browser-trusted TLS certificates, without opening a single port to the public internet. Any device on your tailnet gets a green lock; to the rest of the world, the service simply doesn't answer. What you get - Real TLS certificates from Let's Encrypt. No self-signed warnings, no .local workarounds. - No public exposure. No port forwarding, no public IP, no Cloudflare Tunnel needed. - Nice hostnames. photos.example.com instead of http://192.168.1.42:2342 . - One proxy for everything. Add a new service by adding a few lines to a Caddyfile . How it works Three moving parts: 1. Caddy terminates TLS and reverse-proxies to your services. 2. Cloudflare hosts your domain's DNS. Caddy uses the Cloudflare API to solve Let's Encrypt's DNS challenge, so certificates are issued without ever needing a public HTTP listener. 3. Tailscale carries the actual traffic. Caddy binds its HTTPS listener to its Tailscale interface only, your tailnet devices can reach it; nothing else can. The result: a public DNS record pointing at a private 100.x.x.x address. The hostname resolves from anywhere, but the IP is only routable inside your tailnet. This repo ships a small Dockerfile that rebuilds Caddy with the Cloudflare-DNS and Tailscale plugins, plus a compose.yaml and an example Caddyfile you copy and adapt. Requirements - Docker + Docker C","default_branch":null,"files":null,"tree":[],"storefront":"/r/brickpop","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/brickpop/tailcaddy/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}