Why Caddy Gives 502 When the Backend Works Fine by IP
A 502 usually means the browser-to-Caddy leg worked and the Caddy-to-upstream leg did not.
A 502 usually means the browser-to-Caddy leg worked and the Caddy-to-upstream leg did not.
Stripping a prefix is easy; making the application believe it lives under that prefix is harder.
A synthetic health request measures the service only if it looks like a request the service considers valid.
Internal HTTPS between proxies is useful only when the caller can verify the upstream identity.
Putting MFA in front of each application separately creates duplicated policy; Authelia gives the protected subdomains one identity boundary.