Let's Encrypt HTTPS on an IP Address With FrankenPHP (2026)

In the ever-evolving world of web security and hosting, a recent development has sparked excitement and curiosity among self-hosters and developers alike. The ability to enable HTTPS for IP addresses without the need for DNS is a game-changer, and it's all thanks to a combination of innovative technologies.

The Power of Let's Encrypt and FrankenPHP

At the heart of this breakthrough is Let's Encrypt, a certificate authority that has made significant strides in making secure connections more accessible. By offering short-lived certificates and IP-address certificates, they've opened up new possibilities for self-hosters and teams with unique hosting needs.

The serversideup/php Docker images, built on the serversideup/docker-php repo, have integrated this functionality with the CADDYACMEPROFILE variable. This variable allows users to select Let's Encrypt's short-lived certificate profile, enabling real HTTPS connections without the need for a domain name.

Breaking Free from DNS Dependencies

One of the most significant implications of this development is the freedom it offers from DNS dependencies. Self-hosters and teams often encounter scenarios where a server is only reachable by IP address, especially during the initial setup or for temporary environments. In such cases, the traditional approach of using a self-signed certificate or a reverse proxy can be cumbersome and less secure.

With Let's Encrypt's short-lived certificates, these temporary or internal servers can now enjoy the benefits of HTTPS encryption without the hassle of DNS configuration. This is a huge step forward for those who value security and ease of use.

The Role of Caddy and FrankenPHP

Caddy, a powerful HTTP/2 web server, plays a crucial role in implementing this feature. It supports certificate profile selection and IP identifiers, which are then embedded into FrankenPHP. FrankenPHP, an innovative PHP runtime, integrates Caddy (currently v2.11.4) to provide this seamless HTTPS experience for IP addresses.

Configuring for Success

To enable this feature, users need to pin the Docker image to the beta version and set the necessary environment variables. The CADDYAUTOHTTPS variable turns on Caddy's automatic HTTPS, while SSLMODE: "full" ensures the app is served over HTTPS. The CADDYHTTPSSERVERADDRESS variable specifies the IP address, and CADDYGLOBALOPTIONS provides a fallback identity for connections without an SNI.

It's important to note that this feature is still in beta, so it's recommended to test it thoroughly before relying on it for critical applications. Additionally, IPv6 support should be tested separately, as Caddy's IPv6 handling for IP certificates was implemented later than its IPv4 support.

Beyond IP Certificates

The v4.6.0-beta1 release also brings other improvements. The TRUSTED_PROXY behavior is now consistent across FrankenPHP, NGINX, and Apache, ensuring request()->ip() always returns the visitor's IP. This simplifies configuration when running behind proxies or CDNs.

FrankenPHP also introduces a caddyfile-global.d directory, allowing users to drop their own global config. This adds flexibility for advanced users who need custom configurations.

A Step Towards a More Secure Web

This development showcases the power of open-source collaboration and innovation. By combining the efforts of Let's Encrypt, Caddy, and FrankenPHP, we're moving towards a web where security is more accessible and less dependent on complex infrastructure.

As an enthusiast, I find it fascinating how these projects come together to solve real-world problems. It's a reminder of the potential for positive change when developers collaborate and push the boundaries of what's possible.

While there's still work to be done, especially in testing and refining these features, the future looks bright for self-hosters and developers who value security and simplicity.

Let's Encrypt HTTPS on an IP Address With FrankenPHP (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Lidia Grady

Last Updated:

Views: 6412

Rating: 4.4 / 5 (65 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Lidia Grady

Birthday: 1992-01-22

Address: Suite 493 356 Dale Fall, New Wanda, RI 52485

Phone: +29914464387516

Job: Customer Engineer

Hobby: Cryptography, Writing, Dowsing, Stand-up comedy, Calligraphy, Web surfing, Ghost hunting

Introduction: My name is Lidia Grady, I am a thankful, fine, glamorous, lucky, lively, pleasant, shiny person who loves writing and wants to share my knowledge and understanding with you.