Slide 1

Slide 1 text

Speed up your CI/CD pipelines by caching build & runtime artifacts By Thijs Feryn

Slide 2

Slide 2 text

Your software supply chain has never been more critical

Slide 3

Slide 3 text

Modern software is composed & assembled, not written from scratch

Slide 4

Slide 4 text

No content

Slide 5

Slide 5 text

The list goes on and on

Slide 6

Slide 6 text

Modern software delivery is automated & orchestrated

Slide 7

Slide 7 text

More artifacts than ever ✓ Microservices ✓ Developer sprawl ✓ CI/CD ✓ Agentic AI

Slide 8

Slide 8 text

Organizations depend on artifact registries

Slide 9

Slide 9 text

No content

Slide 10

Slide 10 text

No content

Slide 11

Slide 11 text

Their availability, performance, security & integrity make or break the software supply chain

Slide 12

Slide 12 text

https://xkcd.com/303/

Slide 13

Slide 13 text

Your software supply chain has never been under more pressure

Slide 14

Slide 14 text

Rate limits

Slide 15

Slide 15 text

Rate limits & outages. Slow GitHub Actions pipelines.

Slide 16

Slide 16 text

License cost, egress charges, scalability issues

Slide 17

Slide 17 text

Cloud outages impact availability of registries

Slide 18

Slide 18 text

More commits, more PRs, more builds, more artifact fetches, more API calls

Slide 19

Slide 19 text

No content

Slide 20

Slide 20 text

An update on GitHub availability The main driver is a rapid change in how software is being built. Since the second half of December 2025, agentic development workflows have accelerated sharply. By nearly every measure, the direction is already clear: repository creation, pull request activity, API usage, automation, and large-repository workloads are all growing quickly. https://github.blog/news-insights/company-news/an-update-on-github-availability/

Slide 21

Slide 21 text

Challenging

Slide 22

Slide 22 text

Hi, I'm Thijs

Slide 23

Slide 23 text

No content

Slide 24

Slide 24 text

No content

Slide 25

Slide 25 text

User Varnish Server

Slide 26

Slide 26 text

CI/CD Varnish Registry

Slide 27

Slide 27 text

– 20 40% of total CI/CD pipeline time consumed by dependency downloads

Slide 28

Slide 28 text

Why cache artifacts? ✓ Faster delivery ✓ Scalability ✓ Cost reduction ✓ Resilience

Slide 29

Slide 29 text

Varnish Virtual Registry

Slide 30

Slide 30 text

No content

Slide 31

Slide 31 text

https://varni.sh/vvr

Slide 32

Slide 32 text

$ docker run -p 80:80 varnish/orca

Slide 33

Slide 33 text

$ helm install varnish-orca -f values.yaml oci://docker.io/ varnish/orca-chart

Slide 34

Slide 34 text

varnish: http: - port: 80 virtual_registry: config.yaml registries: - name: docker default: true remotes: - url: https://docker.io - name: pypi remotes: - url: https://pypi.org/simple - name: npm remotes: - url: https://registry.npmjs.org

Slide 35

Slide 35 text

Using Varnish Virtual Registry docker pull docker.localhost/library/ubuntu npm install express --registry=http://npm.localhost GOPROXY=http://go.localhost go mod tidy helm pull oci://ghcr.localhost/prometheus-community/ charts/prometheus --plain-http git clone http://github.localhost/varnish/varnish.git

Slide 36

Slide 36 text

Hyperlocalization

Slide 37

Slide 37 text

Cache miss $ time docker pull docker.localhost/library/node:latest latest: Pulling from library/node 635135721e54: Pull complete f28313c8eaf1: Pull complete 39feea71264a: Pull complete 2882152811f6: Pull complete fd264eb324d0: Pull complete 203fdd9313dd: Pull complete c2f1a73884c0: Pull complete Digest: sha256:e3ffe0cbaeebdcddbfe1ee7bca9b564a92863a8386d5b99a3d72677b3667b61d Status: Downloaded newer image for docker.localhost/library/node:latest docker.localhost/library/node:latest What's next: View a summary of image vulnerabilities and recommendations → docker scout quickview docker.localhost/library/node:latest docker pull docker.localhost/library/node:latest 0,22s user 0,28s system 0% cpu 1:29,97 total

Slide 38

Slide 38 text

Cache hit $ time docker pull docker.localhost/library/node:latest latest: Pulling from library/node 635135721e54: Pull complete f28313c8eaf1: Pull complete 39feea71264a: Pull complete 2882152811f6: Pull complete fd264eb324d0: Pull complete 203fdd9313dd: Pull complete c2f1a73884c0: Pull complete Digest: sha256:e3ffe0cbaeebdcddbfe1ee7bca9b564a92863a8386d5b99a3d72677b3667b61d Status: Downloaded newer image for docker.localhost/library/node:latest docker.localhost/library/node:latest What's next: View a summary of image vulnerabilities and recommendations → docker scout quickview docker.localhost/library/node:latest docker pull docker.localhost/library/node:latest 0,11s user 0,13s system 1% cpu 12,727 total

Slide 39

Slide 39 text

Direct Virtual Registry 1a48a960533f: 15,000 seconds ccd9dba13ae3: 22,000 seconds ed179c6fab21: 23,000 seconds 8dbc42934ae5: 32,000 seconds 7c56d6189d74: 32,000 seconds afa9d872ae23: 53,000 seconds 509699aefca8: 78,000 seconds 1a48a960533f: 0,000 seconds ccd9dba13ae3: 0,000 seconds ed179c6fab21: 1,000 seconds 8dbc42934ae5: 0,000 seconds 7c56d6189d74: 1,000 seconds afa9d872ae23: 1,000 seconds 509699aefca8: 1,000 seconds Sum of individual layer times: 255,000 seconds Wall-clock until all downloads complete: 78,000 seconds Sum of individual layer times: 4,000 seconds Wall-clock until all downloads complete: 1,000 seconds

Slide 40

Slide 40 text

No content

Slide 41

Slide 41 text

$2M cost reduction

Slide 42

Slide 42 text

Reduce developer wait time 15 min 3 min Daily wait time saved per developer by caching artifacts in the CI/CD pipeline

Slide 43

Slide 43 text

Virtual Registry capabilities Artifact-aware acceleration Authentication preservation Multi-registry routing Observability Origin shielding Failover Persistence Security

Slide 44

Slide 44 text

Your software supply chain has never been more vulnerable

Slide 45

Slide 45 text

Trusted registries deliver compromised packages

Slide 46

Slide 46 text

- - 2026 Software Supply Chain Attacks ✓ 20 40 major Supply Chain Campaigns ✓ 20,000+ malicious packages were discovered ✓ 1000+ packages were directly compromised in high-profile incidents ✓ 10 20 million estimated malicious packages were downloaded

Slide 47

Slide 47 text

https://www.codeant.ai/blogs/shai-hulud-npm-supply-chain-attack

Slide 48

Slide 48 text

No content

Slide 49

Slide 49 text

Artifact Firewall

Slide 50

Slide 50 text

Enforcement at request time

Slide 51

Slide 51 text

No content

Slide 52

Slide 52 text

$ npm install faker-js --registry=http://npm.localhost --prefer-online npm error code E403 npm error 403 403 Forbidden - GET http://npm.localhost/faker-js - package blocked by firewall (rule "faker-npm", ruleset "my-ruleset") npm error 403 In most cases, you or one of your dependencies are requesting npm error 403 a package version that is forbidden by your security policy, or npm error 403 on a server you do not have access to.

Slide 53

Slide 53 text

https://varni.sh/vaf

Slide 54

Slide 54 text

https://varni.sh/vvr

Slide 55

Slide 55 text

No content

Slide 56

Slide 56 text

Meet us outside