Sign inSign up

christianmaier/base-caddy

By christianmaier

•Updated 1 day ago

Caddy built from source with CrowdSec bouncer, Coraza WAF (OWASP CRS) and GeoIP: proxy of base 2

Image
Web servers
0

2.0K

christianmaier/base-caddy repository overview

⁠base-caddy

The reverse proxy of base 2: Caddy built from source with a current Go toolchain on Alpine, plus the platform's configuration. Not meant as a general-purpose Caddy image.

⁠What is inside

  • Caddy 2.11.6, built with xcaddy
  • CrowdSec bouncer (caddy-crowdsec-bouncer v0.14.1): turns away addresses the CrowdSec engine (base-crowdsec) has banned, with 403
  • Coraza WAF (coraza-caddy v2.6.1) with the OWASP Core Rule Set 4.25.0 compiled in, running in detection mode
  • GeoIP (caddy-geoip2 v1.3.0): the country of every request, from a DB-IP country database the platform mounts at /var/lib/geoip (not part of the image); used to close connections from a list of countries and to log the country
  • The platform configuration under /etc/caddy, including the countries and the list of addresses whose connections it closes

⁠Build

  • Multi-arch (linux/amd64, linux/arm64), cross-compiled without emulation
  • Every release passes a Trivy gate: no fixable HIGH or CRITICAL finding without a documented, time-limited exception
  • Runs as an unprivileged user (10001) without capabilities

⁠Tags

One tag per release of base 2 (e.g. 2.9.0). Deployments pull by digest.

IP geolocation by DB-IP⁠, CC BY 4.0, where the platform uses it; the image itself contains no database.

Tag summary

Content type

Image

Digest

sha256:eee0ef39b…

Size

23.7 MB

Last updated

1 day ago

docker pull christianmaier/base-caddy:2.9.4