# caddy-desec-docker Stock [Caddy](https://caddyserver.com) plus the [caddy-dns/desec](https://github.com/caddy-dns/desec) module, so Caddy can get certificates by ACME DNS-01 against a zone hosted at [deSEC](https://desec.io). Published as `code.aneur.in/cloud/caddy-desec-docker:latest` (linux/amd64). Used by the `llm` stack in [cloud/cloud](https://code.aneur.in/cloud/cloud) for `*.llm.aneur.in`: ``` { acme_dns desec { token {env.DESEC_TOKEN} } } ``` ## Builds - **Push to `main`, weekly, or by hand** (`build.yml`): builds the image, checks the deSEC module is present, then pushes `:latest`, keeping the previous one as `:previous`. The weekly run picks up new Caddy and module releases without a commit. - **Pull requests** (`pr-checks.yml`): the same build and module check, without pushing. The push uses the `BUILD_API_TOKEN` Actions secret, a Gitea token with package write access.