v0.7.4 · updated · GitHub

Installation

Requirements: Go 1.25+ only if building from source. All other methods ship a static binary (CGO_ENABLED=0) for Linux / macOS / Windows on amd64, arm64, arm. Verify each method right after install.

Quick verify (all methods)
caddy-analyze --version should print v0.6.1 (or newer). If you see command not found, check PATH or re-open the terminal.

Linux / macOS — install.sh

Detects OS/arch, downloads tar.gz + checksums.txt, verifies SHA256 and optional cosign.

curl -sSfL https://raw.githubusercontent.com/lenny-ts/caddy-analyzer/main/install.sh | bash

Verify

caddy-analyze --version
which caddy-analyze
# expected: /usr/local/bin/caddy-analyze  and  v0.6.1

If /usr/local/bin is not writable, the script uses sudo mv. The installer currently installs to /usr/local/bin; use the release archive or go install when you need a user-local location.

Windows — install.ps1

iwr -useb https://raw.githubusercontent.com/lenny-ts/caddy-analyzer/main/install.ps1 | iex

Verify

caddy-analyze --version
# close and re-open PowerShell if PATH was updated
Get-Command caddy-analyze | Format-List
# expected: Source  C:\Users\YOU\AppData\Local\caddy-analyze\caddy-analyze.exe
Note
Requires PowerShell 5.1+. The script prepends %LOCALAPPDATA%\caddy-analyze to your User PATH — reopen the terminal to pick it up.

Go toolchain

go install github.com/lenny-ts/caddy-analyzer/cmd/caddy-analyze@latest

Verify

caddy-analyze --version
# if "command not found", add Go bin to PATH:
export PATH="$HOME/go/bin:$PATH"
go env GOPATH
# expected: .../go/bin/caddy-analyze

Docker

No Go needed. Image: ghcr.io/lenny-ts/caddy-analyzer (Alpine, non-root caddy user).

docker pull ghcr.io/lenny-ts/caddy-analyzer:latest
# analyze a file
docker run --rm -v /var/log/caddy:/logs ghcr.io/lenny-ts/caddy-analyzer /logs/access.log
# stream from Docker
docker run --rm -v /var/run/docker.sock:/var/run/docker.sock ghcr.io/lenny-ts/caddy-analyzer docker://caddy

Verify

docker run --rm ghcr.io/lenny-ts/caddy-analyzer --version
docker images ghcr.io/lenny-ts/caddy-analyzer --format "{{.Tag}} {{.Size}}"

Pre-built binaries

Download from GitHub Releases. Each *.tar.gz (or .zip on Windows) contains caddy-analyze + checksums.txt + cosign .sig/.pem.

# example Linux amd64 — replace v0.6.1 with latest
curl -sSfL https://github.com/lenny-ts/caddy-analyzer/releases/download/v0.6.1/caddy-analyzer_v0.6.1_linux_amd64.tar.gz -o /tmp/caddy.tgz
curl -sSfL https://github.com/lenny-ts/caddy-analyzer/releases/download/v0.6.1/checksums.txt -o /tmp/checksums.txt
grep caddy-analyzer_v0.6.1_linux_amd64.tar.gz /tmp/checksums.txt | (cd /tmp && sha256sum -c)
tar -xzf /tmp/caddy.tgz -C /tmp && sudo mv /tmp/caddy-analyze /usr/local/bin/

Verify

caddy-analyze --version
ls -l /usr/local/bin/caddy-analyze
# optional cosign: cosign verify-blob --certificate-identity ... --signature checksums.txt.sig checksums.txt

Systemd (guard daemon)

For guard as a service. Requires root for iptables.

sudo tee /etc/systemd/system/caddy-guard.service >/dev/null <<'EOF'
[Unit]
Description=caddy-analyzer Security Guard Daemon
After=network.target caddy.service
[Service]
Type=simple
ExecStart=/usr/local/bin/caddy-analyze guard --limit 50 --window 1m /var/log/caddy/access.log
Restart=always
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
sudo systemctl daemon-reload
sudo systemctl enable --now caddy-guard

Verify

systemctl status caddy-guard --no-pager
journalctl -u caddy-guard -n 20 --no-pager
# should show "guard started" and no "permission denied" on /var/log/caddy/access.log

Update

caddy-analyze update --check   # check without installing
caddy-analyze update           # install latest (cosign + SHA256 verified)
caddy-analyze update --version v0.6.1 --force  # pin / downgrade

Troubleshooting

  • curl: command not found → sudo apt-get install curl or use the binary download.
  • permission denied on log → sudo caddy-analyze … or sudo usermod -aG caddy $USER then re-login.
  • Corporate proxy → set https_proxy before curl.