Why Caddy Gives 502 When the Backend Works Fine by IP
A 502 usually means the browser-to-Caddy leg worked and the Caddy-to-upstream leg did not.
A 502 usually means the browser-to-Caddy leg worked and the Caddy-to-upstream leg did not.
Keepalive timeout mismatches can fail a request even while proxy and backend are otherwise healthy.
The most common Docker reverse-proxy mistake is technically valid networking aimed at the wrong namespace.
A proxied 5xx status is a response, not automatically a Caddy handler error.
The failing TLS identity may be on the Cloudflare-to-origin leg rather than in Caddy's upstream proxy.