// Engineering Log
Caddy vs HAProxy vs Nginx vs Traefik: Performance Comparison 2026
Published on 2026-09-22
// Fast route
This article belongs to the topic Servers and infrastructure.
Caddy, Traefik, HAProxy, Nginx and Apache solve overlapping problems — they accept HTTP requests, terminate TLS and forward traffic to applications — but they are built differently and are good in different places. Below is a comparison by what actually affects the choice, and separate analyses of the most common pairs: HAProxy or Nginx, Caddy or Traefik. Detailed posts about each server are in separate parts of the series: Nginx, HAProxy, Caddy, Traefik.
Briefly about each
- Caddy — web server and reverse proxy with automatic HTTPS by default. Apache 2.0 license, version 2.11 (2026).
- Traefik — reverse proxy that takes routes from Docker, Kubernetes and other sources. MIT license, version 3.7 (2026).
- HAProxy — specialized HTTP and TCP load balancer. GPL license, long-term branches 3.2 and 3.4.
- Nginx — web server, reverse proxy and cache, the most common “front” in front of an application. BSD license.
- Apache HTTP Server — classic modular web server with per-directory configuration (
.htaccess). Apache 2.0 license, branch 2.4.
Comparison by key criteria
| Criterion | Caddy | Traefik | HAProxy | Nginx | Apache |
|---|---|---|---|---|---|
| Main role | web server and proxy | proxy for containers | load balancer | web server, proxy, cache | web server |
| Configuration | Caddyfile or JSON API | container labels, CRD, files | haproxy.cfg | nginx.conf | httpd.conf, .htaccess |
| Automatic certificates | built-in, enabled by default | built-in (certificate resolvers) | since 3.2, experimental: only HTTP-01, single balancer | separate module ngx_http_acme_module (package nginx-module-acme) or certbot | module mod_md shipped since 2.4.30 (status “experimental”) or certbot |
| Changing routes without restart | configuration reload, API | automatic from providers | reload, Runtime API | reload | graceful reload |
| TCP proxying | not out of the box | TCP and UDP | TCP | TCP and UDP (module stream) | no |
| Static file serving | yes | no | no | yes | yes |
| Barrier to entry | low | medium | medium | medium | medium |
Until recently the certificates line was the main distinction of Caddy and Traefik from the others. Now ACME clients exist for Apache, nginx, and HAProxy too, but only Caddy and Traefik have it working out of the box without separate modules and experimental directives.
HAProxy or Nginx
Both can proxy HTTP and TCP and both are fast. The difference is what they emphasize.
HAProxy was built as a load balancer. It has advanced active health checks for servers (HTTP requests checking responses, database protocol checks), tables for rate limiting and sticky sessions, a Runtime API to take a server out of service without restarting, a detailed stats page and logs with timing for each stage of the request. It does not serve static files and is not a cache in the full sense.
Nginx is first and foremost a web server: it serves static files, works with PHP-FPM, caches responses, supports compression, URL rewriting and a rich set of modules. It can do load balancing too, but in the free version health checks are passive: a server is removed after failed user requests (max_fails), and active checks are only available in NGINX Plus.
How to choose:
- many application servers, health checks, rate limits and visibility of each request are important — HAProxy;
- a single server that needs to both serve static files and proxy the application — Nginx;
- large projects often use both: HAProxy at the edge distributes load, Nginx behind it serves static files and handles the application.
Caddy or Traefik
Both obtain certificates themselves and are well suited for small teams. The difference is the source of configuration.
Caddy is configured with a file: one or two lines per site. It’s a full web server — serves static files, works with PHP via php_fastcgi, compresses responses. Convenient on a VPS with several permanent sites and services.
Traefik is configured via container labels and Kubernetes objects. It notices when a container starts or stops and rebuilds routes. It does not serve static files — you need a separate web server in a container for those.
How to choose:
- the set of sites changes rarely, you want a simple configuration file — Caddy;
- services live in containers and constantly appear and disappear, you have Kubernetes — Traefik.
What actually affects performance
Synthetic benchmarks where one server is “twice as fast” as another say little about your load. On a typical site the bottleneck is almost always the application or the database, not the proxy. The most noticeable factors that affect the front-end speed are:
- TLS settings — session resumption, HTTP/2, modern cipher suites;
- persistent connections to application servers — without keepalive each request opens a new TCP connection;
- buffering — for streaming responses (SSE, WebSocket) it’s disabled, for regular responses it offloads the application;
- logs — writing every request to a slow disk limits throughput;
- compression and cache — serving a ready response from cache is faster than asking the application again.
If performance is critical, compare candidates with your own requests and identical TLS settings.
When to choose what
| Task | Choice |
|---|---|
| Several sites on one VPS, need HTTPS without extra setup | Caddy |
| Docker host or Kubernetes with frequently changing services | Traefik |
| Load balancing across many servers, health checks, TCP services and databases | HAProxy |
| Static files, PHP-FPM, caching, classic “front” in front of an app | Nginx |
Old app using .htaccess and Apache modules, shared hosting | Apache |
None of the five is better than the others at everything. A good setup often combines two: a load balancer at the edge and a web server behind it, or Traefik for containers and nginx for static files inside them.
// Similar task
If you are dealing with something similar
This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.
Article topic
Servers and infrastructure
VPS, Linux, web stack, migrations, hosting, databases, and core operations.
Typical tasks behind this topic
- Move a site or service to a new server
- Set up Linux, Nginx, databases, and backups
- Figure out why the system behaves unstably
// Next step
If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.
Open services// Reviews
Related reviews
Mikhail is an outstanding professional! You can tell he has a great deal of experience. The work was done precisely and on time. We had to tinker a bit because the project installed on the server wasn't perfect, but Mikhail carefully and thoughtfully guided us on what to do and how. In the end, everything worked! I recommend him to anyone who values quality.
Mikhail is an excellent performer! You can tell he has a wealth of experience. The work was done precisely and on time. We had to tinker due to imperfections in the project that was being installed on the server, but …
// Contact
Need help?
Get in touch with me and I'll help solve the problem
I reply within one business day (03:00-13:00 GMT)
Или оставьте заявку здесь:
// Related