Caddy2 with Cloudflare CDN (end-to-end encryption)
Cloudflare settings
dashboard->profile->API Tokens->Create API Token->Create Custom Token
- name the token
Permissions->zone->zone read/dns edit/analytic read
Zone Resources->specific zone->your site domain
do NOT use global API key