The private section reads files from a folder on your own server over HTTPS, with a user name and password made just for it. Your SSH login and root account are never used by the app and stay as locked down as they are now.
Caddy is a small web server that gets an HTTPS certificate on its own. Connect to the server over SSH the way you always do, and first make sure nothing else is using ports 80 and 443:
sudo ss -ltnp | grep -E ':(80|443) '
If this prints anything, another web server is already running there. Stop and sort that out first — installing Caddy on top would break it.
If it prints nothing, install Caddy:
sudo apt install -y debian-keyring debian-archive-keyring apt-transport-https curl curl -1sLf 'https://dl.cloudsmith.io/public/caddy/stable/gpg.key' | sudo gpg --dearmor -o /usr/share/keyrings/caddy-stable-archive-keyring.gpg curl -1sLf 'https://dl.cloudsmith.io/public/caddy/stable/debian.deb.txt' | sudo tee /etc/apt/sources.list.d/caddy-stable.list sudo chmod o+r /usr/share/keyrings/caddy-stable-archive-keyring.gpg sudo chmod o+r /etc/apt/sources.list.d/caddy-stable.list sudo apt update sudo apt install -y caddy
Everything in this folder will be visible in the app, and nothing outside it. Create it and let Caddy read it:
sudo mkdir -p /srv/files sudo chmod -R a+rX /srv/files
Put your files there the way you usually copy files to the server. After adding new ones, run the second line again.
Run this and type a new password twice. It prints a long line starting with $2a$ — copy it.
caddy hash-password
Make it a new, long password. It is not your root or SSH password, and it opens only this one folder, read-only.
Open the settings file:
sudo nano /etc/caddy/Caddyfile
Delete everything in it and paste the text below. On the first line put your domain; instead of me, any user name you like; instead of the $2a$… line, the one you copied in step 3. Save with Ctrl+O, Enter, and exit with Ctrl+X.
files.example.com {
root * /srv/files
basic_auth {
me $2a$14$PASTE_THE_LINE_FROM_STEP_3
}
file_server browse
}sudo systemctl reload caddy
Within a minute Caddy fetches an HTTPS certificate by itself. To check, open https:// plus your domain in any browser: it should ask for a user name and password, then show your files.
https:// and your domain, for example https://files.example.comEverything travels over HTTPS, so nobody on the network in between can read the password or the files. The app never gets a key to your server: even if someone forced the private section open, all they would reach is this one folder, read-only — not the server.
sudo systemctl status caddy shows what went wrong.