Towbar
  • Docs
  • Security
  • Status
Open dashboard
  1. Towbar
  2. Docs
  3. Domains and TLS

Domains and TLS

Caddy routing for direct DNS and Cloudflare orange-cloud hostnames.

DocumentationGetting starteddeployment.ymlSourcesServersSecretsDeploymentsDomains and TLSSecurity

Direct

Use tls.mode: direct when public DNS points directly at the server. Caddy completes the normal ACME HTTP or TLS challenge.

Cloudflare DNS

Use tls.mode: cloudflare-dns for orange-cloud records. Towbar creates or updates its A/AAAA records with proxying enabled, then configures Caddy's Cloudflare DNS challenge so certificate issuance does not depend on an HTTP challenge. A conflicting record that Towbar does not own stops the deployment instead of being overwritten.

Cloudflare settings

Keep SSL/TLS mode at Full (strict) after the origin certificate is ready. The token should be limited to Zone:Read and DNS:Edit for only the required zone.

Towbar

Opinionated manual deployments to Ubuntu servers you own.

© 2026 Towbar
Back to top
Product
DocumentationJSON SchemaStatus
Legal
PrivacyTerms