this post was submitted on 22 Sep 2026
33 points (78.9% liked)

Selfhosted

62398 readers
742 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

Recently it's come to my attention that Caddy has an AI sponsor so I have been looking at moving away from Caddy.

I'm currently looking for another reverse proxy to use in place of Caddy. For TLS I am looking into using CertBot and it appears there's a module (https://github.com/desec-io/certbot-dns-desec) I can use that works for https://desec.io/ to handle my certs.

I have two questions, the first is about CertBot. Since Caddy is handling my certs automatically, how often would I want to renew my certs? Desec.io has this command to obtain a cert:

certbot certonly \
     --authenticator dns-desec \
     --dns-desec-credentials /etc/letsencrypt/secrets/$DOMAIN.ini \
     -d "$DOMAIN" \
     -d "*.$DOMAIN"

Would I be required to run the same command periodically to renew my cert?

My second question is a bit more open ended. I am looking to hear any suggestions or experiences about different reverse proxies that are preferably free of AI. There is a list here with some suggested alternatives: https://codeberg.org/ethical-foss/open-slopware#web-servers

you are viewing a single comment's thread
view the rest of the comments
[–] forbiddenlake@lemmy.world 9 points 1 week ago (2 children)

Your stance rules out all the big and mature software. No judgement on the stance, but you are asking a difficult question.

Off that alternatives list, the only one I've heard of is lighttpd, and it's news to me that lighty can do reverse proxying. But I would try that.

I expect it to be a lot more difficult to find documentation and support for anything more obscure than lighty. Which may be fine for you, just know what you're getting in to.

As for certbot, iirc you need to add a renew command to cron, but otherwise certbot will take care of it. I'm sure the cron is in the documentation.

I definitely expect this path to be a bit of a challenge

I was looking at lighttpd as well. That was the only one on the list that sounded familiar to me. I may check it out and see if it can fit me needs. I do run a very minimal setup so I might just be enough.

[–] rako@tarte.nuage-libre.fr 3 points 1 week ago

This list https://noai.starlightnet.work/list.html has a long list of projects explicitly rejecting AI and there are some in there I would place in the "big and mature" bucket