Hello! I have 2 services that are only being accessed locally but require HTTPS so I am using Caddy & DuckDNS w/ DNS-01 to reverse proxy them. In DuckDNS, both subdomains are pointing at the local IP address of Caddy, and my Caddyfile has:

service1.duckdns.org:443 {
        tls {
                dns duckdns {
                        api_token API-TOKEN
                }
        }
        reverse_proxy 192.168.0.51:8080
	}

service2.duckdns.org:443 {
        tls {
                dns duckdns {
                        api_token API-TOKEN
                }
        }
        reverse_proxy 192.168.0.20:8080
	}

The issue is that I can access https://service1.duckdns.org/ (within my home network), but I can't access https://service2.duckdns.org/ (502 Bad Gateway). Caddy is running in a LXC in Proxmox, and Service1 is on a different VM on the same Proxmox machine, while Service2 is on a different machine on my network. I don't see any entries in my router's firewall logs or PiHole that indicates something is blocking it. I enabled logging in Caddy for both services and I am only able to see activity for Service1, so I guess that means something is blocking Service2 from reaching Caddy entirely?

I'm able to access service2 directly from the IP address but I'm a novice in networking so I'm trying to understand and learn what could be causing this. Any help would be appreciated!

all 6 comments

sorted by: hot top controversial new old
[–] 1 point 7 hours ago

tcpdump -nlpiany port 8080

Will show if caddy actually tries to connect the back end.

  • source
  • [–] 6 points 13 hours ago

    I'd say there's likely something wrong with your service. Maybe it refuses serving on a domain it's not configured for? Or there's something wrong with the headers or something like that. Or the internal network. Anyway, the 502 error is sent by the Caddy server. That means everything from your browser to the Caddy server should be fine. You can reach it. There's something wrong with the service or the parts in-between the reverse proxy and the application.

  • source
  • [–] 4 points 12 hours ago

    Take out the entry for service1 first to simplify the problem.

    But from what I can see it looks right. Does service 2 have a self signed ssl certificate? If yes you'll need a TLS setting in that caddy block to ignore validation.

  • source
  • [–] 1 point 11 hours ago

    Seems weird that you're not seeing any logs for service2 in caddy, especially if it's caddy serving the 502. I'd expect at least a message from caddy complaining about being unable to reach the upstream service in that case.

    Verify that the 502 is coming from caddy and not potentially some other gateway that's part of service2.

  • source
  • [–] 1 point 12 hours ago

    Also do an nslookup on the service 2 host name. Make sure it's going to the right IP

  • source
  • [–] -2 points 11 hours ago

    Have you tried NGINX proxy manager? It really simplifies the whole process.

  • source