Where Does Caddy Store Certificates and Config?
Caddy's Caddyfile path, per OS data and config dirs, and the service storage gotcha.
Last updated
Caddy separates what you write from what it manages. The Caddyfile you author usually sits at /etc/caddy/Caddyfile on distro installs, while certificates, keys and OCSP staples accumulate in a data directory you should treat as precious.
The gotcha is the service user. Under systemd Caddy runs as caddy with home /var/lib/caddy, so live certificates sit below that instead of your own home data dir.
Where Caddy stores this, by platform
/etc/caddy/Caddyfile
Authored config. Live data at /var/lib/caddy/.local/share/caddy for the service user, or ~/.local/share/caddy when run as yourself. Autosaved JSON in the config dir sibling. Docker uses caddy_data:/data and caddy_config:/config volumes.
%APPDATA%\Caddy
Both data and config roots per official conventions when run as your user. Never purge the data dir casually: private keys and managed certificates live there.
~/Library/Application Support/Caddy
Same dual role data plus config root. Root CA for local HTTPS at pki/authorities/local/root.crt below the data dir; install it into browsers that ignore the system store.
Frequently asked questions
Where are Caddy's Let's Encrypt certificates?
Under the data dir: certificates and acme subfolders. For systemd installs that means /var/lib/caddy/.local/share/caddy, not your home folder.
Config dir versus Caddyfile. Which is which?
The Caddyfile is what you write. The config dir holds the autosaved JSON resume copy. Edit the Caddyfile, leave autosave.json to the daemon.
Notice an outdated path? Let us know.