- Added service discovery for reverse proxying (DNS SRV) and reusable Caddyfile snippets; introduced 9 new DNS provider plugins for ACME challenges.
- Implemented several breaking changes: swapped SIGTERM/SIGQUIT handling, disallowed conflicting TLS configurations, and now raise TLS alerts when SNI has no matching certificate.
- Enhanced TLS management with shared certificates, stricter OCSP validation, on‑demand certificate approval, and overall efficiency improvements.