Caddy: Reduce IP addresses in access logs
Caddy offers current filters directly in the logging system. This can be used to delete fields or mask IP addresses.
Requirements
You need access to the caddy file and should save the existing logging configuration before making changes.
IP masking
example.de {
log {
format filter {
request>remote_ip ip_mask 16 32
request>client_ip ip_mask 16 32
request>headers>X-Forwarded-For delete
request>headers>Cookie delete
}
}
}
Test
After a test call, check the access log generated: Visitor IP, forwarded IP and cookies may no longer appear in plain text in the selected fields.
Deconstruction
In case of problems, restore the previous logblock from the backed up caddy configuration and revalidate the configuration.
Since Caddy 2.7, remote_ip and client_ip are relevant; for trusted proxies, client_ip can contain the determined real client address. For maximum data minimization, an unneeded access log is still better than mere masking.
Other log levels
Setting this level alone does not exclude other logs. In addition, What does my hosting provider store about website visitors? and check web server, proxy/CDN, security and provider separately.
Related guides
Sources and verification
This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.
Important: IP processing is not IP storage
An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.