Installation
Requirements: Go 1.25+ only if building from source. All other methods ship a static binary (CGO_ENABLED=0) for Linux / macOS / Windows on amd64, arm64, arm. Verify each method right after install.
Quick verify (all methods)
caddy-analyze --version should print v0.6.1 (or newer). If you see command not found, check PATH or re-open the terminal.Linux / macOS — install.sh
Detects OS/arch, downloads tar.gz + checksums.txt, verifies SHA256 and optional cosign.
curl -sSfL https://raw.githubusercontent.com/lenny-ts/caddy-analyzer/main/install.sh | bash
Verify
caddy-analyze --version
which caddy-analyze
# expected: /usr/local/bin/caddy-analyze and v0.6.1
If /usr/local/bin is not writable, the script uses sudo mv. The installer currently installs to /usr/local/bin; use the release archive or go install when you need a user-local location.
Windows — install.ps1
iwr -useb https://raw.githubusercontent.com/lenny-ts/caddy-analyzer/main/install.ps1 | iex
Verify
caddy-analyze --version
# close and re-open PowerShell if PATH was updated
Get-Command caddy-analyze | Format-List
# expected: Source C:\Users\YOU\AppData\Local\caddy-analyze\caddy-analyze.exe
Note
Requires PowerShell 5.1+. The script prepends %LOCALAPPDATA%\caddy-analyze to your User PATH — reopen the terminal to pick it up.Go toolchain
go install github.com/lenny-ts/caddy-analyzer/cmd/caddy-analyze@latest
Verify
caddy-analyze --version
# if "command not found", add Go bin to PATH:
export PATH="$HOME/go/bin:$PATH"
go env GOPATH
# expected: .../go/bin/caddy-analyze
Docker
No Go needed. Image: ghcr.io/lenny-ts/caddy-analyzer (Alpine, non-root caddy user).
docker pull ghcr.io/lenny-ts/caddy-analyzer:latest
# analyze a file
docker run --rm -v /var/log/caddy:/logs ghcr.io/lenny-ts/caddy-analyzer /logs/access.log
# stream from Docker
docker run --rm -v /var/run/docker.sock:/var/run/docker.sock ghcr.io/lenny-ts/caddy-analyzer docker://caddy
Verify
docker run --rm ghcr.io/lenny-ts/caddy-analyzer --version
docker images ghcr.io/lenny-ts/caddy-analyzer --format "{{.Tag}} {{.Size}}"
Pre-built binaries
Download from GitHub Releases. Each *.tar.gz (or .zip on Windows) contains caddy-analyze + checksums.txt + cosign .sig/.pem.
# example Linux amd64 — replace v0.6.1 with latest
curl -sSfL https://github.com/lenny-ts/caddy-analyzer/releases/download/v0.6.1/caddy-analyzer_v0.6.1_linux_amd64.tar.gz -o /tmp/caddy.tgz
curl -sSfL https://github.com/lenny-ts/caddy-analyzer/releases/download/v0.6.1/checksums.txt -o /tmp/checksums.txt
grep caddy-analyzer_v0.6.1_linux_amd64.tar.gz /tmp/checksums.txt | (cd /tmp && sha256sum -c)
tar -xzf /tmp/caddy.tgz -C /tmp && sudo mv /tmp/caddy-analyze /usr/local/bin/
Verify
caddy-analyze --version
ls -l /usr/local/bin/caddy-analyze
# optional cosign: cosign verify-blob --certificate-identity ... --signature checksums.txt.sig checksums.txt
Systemd (guard daemon)
For guard as a service. Requires root for iptables.
sudo tee /etc/systemd/system/caddy-guard.service >/dev/null <<'EOF'
[Unit]
Description=caddy-analyzer Security Guard Daemon
After=network.target caddy.service
[Service]
Type=simple
ExecStart=/usr/local/bin/caddy-analyze guard --limit 50 --window 1m /var/log/caddy/access.log
Restart=always
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
sudo systemctl daemon-reload
sudo systemctl enable --now caddy-guard
Verify
systemctl status caddy-guard --no-pager
journalctl -u caddy-guard -n 20 --no-pager
# should show "guard started" and no "permission denied" on /var/log/caddy/access.log
Update
caddy-analyze update --check # check without installing
caddy-analyze update # install latest (cosign + SHA256 verified)
caddy-analyze update --version v0.6.1 --force # pin / downgrade
Troubleshooting
curl: command not found→sudo apt-get install curlor use the binary download.permission deniedon log →sudo caddy-analyze …orsudo usermod -aG caddy $USERthen re-login.- Corporate proxy → set
https_proxybefore curl.