Slide 1

Slide 1 text

No content

Slide 2

Slide 2 text

Slow websites SUCK

Slide 3

Slide 3 text

WEB PERFORMANCE IS AN ESSENTIAL PART OF THE USER EXPERIENCE

Slide 4

Slide 4 text

~ SLOW DOWN

Slide 5

Slide 5 text

THROWING SERVERS AT THE PROBLEM

Slide 6

Slide 6 text

MO' MONEY MO' SERVERS MO' PROBLEMS

Slide 7

Slide 7 text

IDENTIFY SLOWEST PARTS

Slide 8

Slide 8 text

OPTIMIZE

Slide 9

Slide 9 text

AFTER A WHILE YOU HIT THE LIMITS

Slide 10

Slide 10 text

CACHING

Slide 11

Slide 11 text

HI, I'M THIJS

Slide 12

Slide 12 text

I'M THE TECH AT VARNISH EVANGELIST

Slide 13

Slide 13 text

No content

Slide 14

Slide 14 text

No content

Slide 15

Slide 15 text

USER VARNISH SERVER

Slide 16

Slide 16 text

Cache-Control: public, max-age=3600

Slide 17

Slide 17 text

Cache-Control: private, no-cache, no-store

Slide 18

Slide 18 text

VARNISH CONFIGURATION LANGUAGE

Slide 19

Slide 19 text

No content

Slide 20

Slide 20 text

vcl 4.1; backend default { .host = "127.0.0.1"; .port = "8080"; } sub vcl_recv { if(req.url ~ "^/admin(/.*|$)") { return(pass); } unset req.http.Cookie; }

Slide 21

Slide 21 text

vcl 4.1; backend default { .host = "127.0.0.1"; .port = "8080"; } sub vcl_backend_response { if (beresp.http.Content-Type ~ "^image/") { set beresp.ttl = 1y; } else { set beresp.ttl = 1h; } }

Slide 22

Slide 22 text

WHAT ABOUT KUBERNETES?

Slide 23

Slide 23 text

$ helm install varnish \ oci://docker.io/varnish/varnish-cache \ --set server.extraEnvs.VARNISH_BACKEND_HOST=example.default.svc.cluster.local \ --set server.extraEnvs.VARNISH_BACKEND_PORT=80

Slide 24

Slide 24 text

$ helm install varnish \ oci://docker.io/varnish/varnish-cache \ --set server.extraEnvs.VARNISH_BACKEND_HOST=example.default.svc.cluster.local \ --set server.extraEnvs.VARNISH_BACKEND_PORT=80 Pulled: docker.io/varnish/varnish-cache:1.1.1 Digest: sha256:48c0f1beaa3f8ea26a618f842ae413233c48c748484bf0b5863ca439d26025d7 NAME: varnish LAST DEPLOYED: Mon May 18 13:40:43 2026 NAMESPACE: default STATUS: deployed REVISION: 1 TEST SUITE: None NOTES: __ __ _ _ \ \ / /_ _ _ __ _ __ (_)___| |__ \ \ / / _` | '__| '_ \| / __| '_ \ \ V / (_| | | | | | | \__ \ | | | \_/ \__,_|_| |_| |_|_|___/_| |_| varnish-cache.org

Slide 25

Slide 25 text

varnish example varnish example Internet

Slide 26

Slide 26 text

Internet varnish example varnish2 example2 varnish example varnish2 example2 varnish3 example3 varnish3 example3

Slide 27

Slide 27 text

Internet varnish example varnish2 example2 varnish example varnish2 example2 varnish3 example3 Varnish3 example3

Slide 28

Slide 28 text

Internet varnish example varnish2 example2 varnish example varnish2 example2 varnish3 example3 varnish3 example3

Slide 29

Slide 29 text

GA TEWA Y

Slide 30

Slide 30 text

n ar .v ay w te ga h is rg .o

Slide 31

Slide 31 text

No content

Slide 32

Slide 32 text

POWERED BY VARNISH 9

Slide 33

Slide 33 text

✓ ✓ Native TLS Dynamic backends Structured JSON logging OpenTelemetry support GeoIP Accept header cleanup Rate limiting & throttling Tag-based cached invalidation JSON parsing & JQ support LUA & ECMAScript support ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ HMAC, message digest & Base64 Local file server Redis interface Response body manipulation Request body capturing Query string manipulation Header manipulation String functions HTTP client g or h. is ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ rn va VARNISH 9

Slide 34

Slide 34 text

example Internet GA TEWA Y example

Slide 35

Slide 35 text

No content

Slide 36

Slide 36 text

Watches Gateway API resources Operator - Gateway - HTTPRoute - GatewayClass - GatewayClassParameters Creates/updates gateway, routing.json file & main.vcl to ConfigMap ROUTING IN MEMORY, NO VCL RECOMPILE Varnish pod Varnish + ghost module Logs varnishlog-json Reloads Watches Chaperone Watches EndpointSlices ConfigMaps - main.vcl - routing.json

Slide 37

Slide 37 text

$ kubectl apply -f https://github.com/kubernetes-sigs/gateway-api/releases/ download/v1.5.0/standard-install.yaml $ helm install varnish-gateway oci://ghcr.io/varnish/charts/varnish-gateway \ --namespace varnish-gateway-system \ --create-namespace

Slide 38

Slide 38 text

$ kubectl apply -f https://github.com/kubernetes-sigs/gateway-api/releases/ download/v1.5.0/standard-install.yaml $ helm install varnish-gateway oci://ghcr.io/varnish/charts/varnish-gateway \ --namespace varnish-gateway-system \ --create-namespace

Slide 39

Slide 39 text

Watches Gateway API resources Operator - Gateway - HTTPRoute - GatewayClass - GatewayClassParameters CREATED BY HELM INSTALL, RUNS CLUSTER WIDE Varnish + ghost module Logs - varnishlog-json Varnish pod Reloads Watches Chaperone Watches EndpointSlices ConfigMaps - main.vcl - routing.json

Slide 40

Slide 40 text

$ kubectl get all -n varnish-gateway-system NAME pod/varnish-gateway-operator-5b9c4c9dd-gfs7v READY 1/1 NAME service/varnish-gateway-operator-metrics TYPE ClusterIP NAME deployment.apps/varnish-gateway-operator READY 1/1 NAME replicaset.apps/varnish-gateway-operator-5b9c4c9dd STATUS Running RESTARTS 0 CLUSTER-IP 10.43.121.125 UP-TO-DATE 1 DESIRED 1 EXTERNAL-IP AVAILABLE 1 CURRENT 1 AGE 19m AGE 19m READY 1 AGE 19m PORT(S) 8080/TCP AGE 19m

Slide 41

Slide 41 text

--apiVersion: gateway.networking.k8s.io/v1 kind: Gateway metadata: name: varnish-gateway namespace: default annotations: cert-manager.io/issuer: letsencrypt spec: gatewayClassName: varnish listeners: - name: http protocol: HTTP port: 80 allowedRoutes: namespaces: from: All - name: https-todo port: 443 protocol: HTTPS hostname: "todo.demo.artifactcache.com" tls: mode: Terminate certificateRefs: - name: demo-artifactcache-com-tls allowedRoutes: namespaces: from: All

Slide 42

Slide 42 text

$ kubectl apply -f varnish-gateway.yaml gateway.gateway.networking.k8s.io/varnish-gateway created $ kubectl get gateways NAME varnish-gateway CLASS varnish ADDRESS 172.31.44.22 PROGRAMMED True AGE 58m

Slide 43

Slide 43 text

Watches Gateway API resources Operator - Gateway - HTTPRoute - GatewayClass - GatewayClassParameters Creates/updates routing.json file & main.vcl to ConfigMap Varnish pod Varnish + ghost module Logs varnishlog-json Reloads Watches Chaperone Watches EndpointSlices ConfigMaps - main.vcl - routing.json

Slide 44

Slide 44 text

--apiVersion: gateway.networking.k8s.io/v1 kind: HTTPRoute metadata: name: todo-http-route namespace: default spec: parentRefs: - name: varnish-gateway hostnames: - todo.demo.artifactcache.com rules: - backendRefs: - name: todo port: 80

Slide 45

Slide 45 text

$ kubectl get svc --field-selector metadata.name=todo NAME todo TYPE NodePort CLUSTER-IP 10.43.78.51 EXTERNAL-IP PORT(S) 80:31666/TCP $ kubectl apply -f todo-gateway-routes.yaml httproute.gateway.networking.k8s.io/todo-http-route created $ kubectl get httproutes NAME todo-http-route HOSTNAMES ["todo.demo.artifactcache.com"] AGE 12s AGE 49m

Slide 46

Slide 46 text

: NO CACHING BY DEFAULT TIMER UPDATES ON REFRESH

Slide 47

Slide 47 text

--apiVersion: gateway.varnish-software.com/v1alpha1 kind: VarnishCachePolicy metadata: name: cache-todo namespace: default spec: targetRef: group: gateway.networking.k8s.io kind: HTTPRoute name: todo-http-route defaultTTL: 1h

Slide 48

Slide 48 text

$ kubectl apply -f varnish-cache-policy-todo.yaml varnishcachepolicy.gateway.varnish-software.com/cache-todo created $ kubectl get varnishcachepolicy NAME cache-todo TARGET KIND HTTPRoute TARGET NAME todo-http-route AGE 28s

Slide 49

Slide 49 text

: CACHING ENABLED TIMER DOES NOT UPDATE ON REFRESH

Slide 50

Slide 50 text

No content

Slide 51

Slide 51 text

apiVersion: gateway.varnish-software.com/v1alpha1 kind: VarnishCachePolicy metadata: name: my-cache-policy namespace: default spec: targetRef: group: gateway.networking.k8s.io kind: HTTPRoute # or Gateway name: my-route # sectionName: my-rule # optional: target a specific named rule defaultTTL: 5m # forcedTTL: 1h grace: 30s # serve stale while revalidating (default: 0) keep: 24h # serve stale when backend is down (default: 0) cacheKey: headers: - Accept-Language queryParameters: include: # allowlist (mutually exclusive with exclude) - page - filter # exclude: # denylist # - utm_source bypass: headers: - name: Authorization - name: Cookie valueRegex: "session_id|admin_token"

Slide 52

Slide 52 text

WANT TO WRITE YOUR OWN VCL?

Slide 53

Slide 53 text

sub vcl_recv { if(req.http.host == "todo.demo.artifactcache.com") { unset req.http.cookie; unset req.http.authorization; if(req.url ~ "^/[0-9a-f]{32}/?$" || (req.method != "GET" && req.method != "HEAD")) { return(pass); } return(hash); } } sub vcl_backend_response { set beresp.ttl = 1h; if(beresp.http.content-type ~ "^text/css") { set beresp.ttl = 1y; } } sub vcl_deliver { if(req.http.host == "todo.demo.artifactcache.com") { if(req.url ~ "^/[0-9a-f]{32}/?$" && resp.status == 404) { set resp.status = 302; set resp.reason = "Found"; set resp.http.Location = "https://todo.demo.artifactcache.com/"; return(deliver); } } }

Slide 54

Slide 54 text

$ kubectl create configmap user-vcl \ -n varnish-gateway-system \ --from-file=../conf/user.vcl gatewayClass: defaultParams: userVCL: enabled: true configMap: name: user-vcl key: user.vcl VARNISH GATEWAY VALUES.YAML - - $ helm install -f ../conf/varnish-gateway-values.yaml varnish-gateway \ oci://ghcr.io/varnish/charts/varnish-gateway \ --namespace varnish-gateway-system \ --create-namespace

Slide 55

Slide 55 text

--apiVersion: gateway.varnish-software.com/v1alpha1 kind: VarnishCacheInvalidation metadata: name: purge-user-pages spec: gatewayRef: name: varnish-gateway type: Purge hostname: todo.demo.artifactcache.com paths: - /

Slide 56

Slide 56 text

https://gateway.varnish.org https://varnish.org https://varnish-software.com https://varnish-cdn.com

Slide 57

Slide 57 text

No content

Slide 58

Slide 58 text

No content