At a glance
| Status | Live on Oracle Cloud Marketplace |
|---|
| Version | 2.11.4 |
|---|
| Platform | Oracle Linux 9 |
|---|
| Ports open in the host firewall | SSH (22/tcp), 80/tcp, 443/tcp, 443/udp |
|---|
| Category | Networking |
|---|
| Upstream licence | Apache-2.0 |
|---|
| Pricing | Pay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab |
|---|
Quick start
This is the listing's usage information, verbatim.
After launch:
- Connect over SSH as the opc user with the key you supplied at launch:
ssh opc@<public-ip>
- Caddy runs as a systemd service, serving a placeholder page on port 80. Check status:
sudo systemctl status caddy
- Browse to http://<public-ip> to confirm the placeholder page. (Your VCN security list must allow TCP 80/443 — the instance firewall already does.)
- To enable automatic HTTPS, point a DNS name (an A record) at this instance, then edit /etc/caddy/Caddyfile and replace the first line — :80 — with your domain name:
example.com {
root * /usr/share/caddy
file_server
}
- Reload to apply:
sudo systemctl reload caddy
Caddy then obtains and renews the TLS certificate automatically; no other step exists.
- To reverse-proxy an application instead of serving files, replace the site body with: reverse_proxy 127.0.0.1:3000
- Site content lives in /usr/share/caddy. Full Caddyfile reference: https://caddyserver.com/docs/caddyfile
The image is CVE-patched at build time. Apply ongoing updates with:
sudo dnf -y update
What the image provides
- Caddy 2.11.4, installed from the project's official release with its SHA-512 checksum verified at build time, running as a dedicated unprivileged service.
- A working HTTP site out of the box. Point a DNS name at the instance, change one line in /etc/caddy/Caddyfile, and Caddy obtains and renews its own publicly trusted TLS certificates — automatic HTTPS with zero certificate tooling.
- Least privilege for a network service: because ports 80 and 443 are privileged, the service is granted only CAP_NET_BIND_SERVICE and nothing else, with a locked-down systemd sandbox (NoNewPrivileges, ProtectSystem, ProtectHome, PrivateTmp). The admin API stays on its loopback default.
- Security hardening aligned to the Oracle Cloud Marketplace image standards: SELinux enforcing, host firewall default-deny with only SSH, HTTP, and HTTPS permitted, no account with a usable password, no stray keys, and the image fully patched at build time.
Still stuck?
Email support@dcassociatesgroup.com (response within 1 business day) or use the
contact form. Include the listing name, your OCI region, the instance OCID and the
output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.
Caddy is a registered trademark of Stack Holdings GmbH. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the Caddy project or Stack Holdings GmbH.