// Engineering Log

Caddy vs HAProxy vs Nginx vs Traefik: Performance Comparison 2026

Published on 2026-09-22

// Fast route

This article belongs to the topic Servers and infrastructure.

Caddy, Traefik, HAProxy, Nginx and Apache solve overlapping problems — they accept HTTP requests, terminate TLS and forward traffic to applications — but they are built differently and are good in different places. Below is a comparison by what actually affects the choice, and separate analyses of the most common pairs: HAProxy or Nginx, Caddy or Traefik. Detailed posts about each server are in separate parts of the series: Nginx, HAProxy, Caddy, Traefik.

Briefly about each

  • Caddy — web server and reverse proxy with automatic HTTPS by default. Apache 2.0 license, version 2.11 (2026).
  • Traefik — reverse proxy that takes routes from Docker, Kubernetes and other sources. MIT license, version 3.7 (2026).
  • HAProxy — specialized HTTP and TCP load balancer. GPL license, long-term branches 3.2 and 3.4.
  • Nginx — web server, reverse proxy and cache, the most common “front” in front of an application. BSD license.
  • Apache HTTP Server — classic modular web server with per-directory configuration (.htaccess). Apache 2.0 license, branch 2.4.

Comparison by key criteria

CriterionCaddyTraefikHAProxyNginxApache
Main roleweb server and proxyproxy for containersload balancerweb server, proxy, cacheweb server
ConfigurationCaddyfile or JSON APIcontainer labels, CRD, fileshaproxy.cfgnginx.confhttpd.conf, .htaccess
Automatic certificatesbuilt-in, enabled by defaultbuilt-in (certificate resolvers)since 3.2, experimental: only HTTP-01, single balancerseparate module ngx_http_acme_module (package nginx-module-acme) or certbotmodule mod_md shipped since 2.4.30 (status “experimental”) or certbot
Changing routes without restartconfiguration reload, APIautomatic from providersreload, Runtime APIreloadgraceful reload
TCP proxyingnot out of the boxTCP and UDPTCPTCP and UDP (module stream)no
Static file servingyesnonoyesyes
Barrier to entrylowmediummediummediummedium

Until recently the certificates line was the main distinction of Caddy and Traefik from the others. Now ACME clients exist for Apache, nginx, and HAProxy too, but only Caddy and Traefik have it working out of the box without separate modules and experimental directives.

HAProxy or Nginx

Both can proxy HTTP and TCP and both are fast. The difference is what they emphasize.

HAProxy was built as a load balancer. It has advanced active health checks for servers (HTTP requests checking responses, database protocol checks), tables for rate limiting and sticky sessions, a Runtime API to take a server out of service without restarting, a detailed stats page and logs with timing for each stage of the request. It does not serve static files and is not a cache in the full sense.

Nginx is first and foremost a web server: it serves static files, works with PHP-FPM, caches responses, supports compression, URL rewriting and a rich set of modules. It can do load balancing too, but in the free version health checks are passive: a server is removed after failed user requests (max_fails), and active checks are only available in NGINX Plus.

How to choose:

  • many application servers, health checks, rate limits and visibility of each request are important — HAProxy;
  • a single server that needs to both serve static files and proxy the application — Nginx;
  • large projects often use both: HAProxy at the edge distributes load, Nginx behind it serves static files and handles the application.

Caddy or Traefik

Both obtain certificates themselves and are well suited for small teams. The difference is the source of configuration.

Caddy is configured with a file: one or two lines per site. It’s a full web server — serves static files, works with PHP via php_fastcgi, compresses responses. Convenient on a VPS with several permanent sites and services.

Traefik is configured via container labels and Kubernetes objects. It notices when a container starts or stops and rebuilds routes. It does not serve static files — you need a separate web server in a container for those.

How to choose:

  • the set of sites changes rarely, you want a simple configuration file — Caddy;
  • services live in containers and constantly appear and disappear, you have Kubernetes — Traefik.

What actually affects performance

Synthetic benchmarks where one server is “twice as fast” as another say little about your load. On a typical site the bottleneck is almost always the application or the database, not the proxy. The most noticeable factors that affect the front-end speed are:

  • TLS settings — session resumption, HTTP/2, modern cipher suites;
  • persistent connections to application servers — without keepalive each request opens a new TCP connection;
  • buffering — for streaming responses (SSE, WebSocket) it’s disabled, for regular responses it offloads the application;
  • logs — writing every request to a slow disk limits throughput;
  • compression and cache — serving a ready response from cache is faster than asking the application again.

If performance is critical, compare candidates with your own requests and identical TLS settings.

When to choose what

TaskChoice
Several sites on one VPS, need HTTPS without extra setupCaddy
Docker host or Kubernetes with frequently changing servicesTraefik
Load balancing across many servers, health checks, TCP services and databasesHAProxy
Static files, PHP-FPM, caching, classic “front” in front of an appNginx
Old app using .htaccess and Apache modules, shared hostingApache

None of the five is better than the others at everything. A good setup often combines two: a load balancer at the edge and a web server behind it, or Traefik for containers and nginx for static files inside them.

// Similar task

If you are dealing with something similar

This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.

Article topic

Servers and infrastructure

VPS, Linux, web stack, migrations, hosting, databases, and core operations.

Typical tasks behind this topic

  • Move a site or service to a new server
  • Set up Linux, Nginx, databases, and backups
  • Figure out why the system behaves unstably

// Next step

If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.

Open services

// Reviews

Related reviews

N_Konstantin

VPS setup, server setup

2025-10-10 · ★ 5/5

A settled customer

// Contact

Need help?

Get in touch with me and I'll help solve the problem

I reply within one business day (03:00-13:00 GMT)

Или оставьте заявку здесь:

Confirm that you are not a bot.

Write and get a quick reply