Slide 1

Slide 1 text

Speed up your CI/CD pipelines by caching build & runtime artifacts By Thijs Feryn

Slide 2

Slide 2 text

Your software supply chain has never been more critical

Slide 3

Slide 3 text

Modern software is composed & assembled, not written from scratch

Slide 4

Slide 4 text

No content

Slide 5

Slide 5 text

The list goes on and on

Slide 6

Slide 6 text

Modern software delivery is automated & orchestrated

Slide 7

Slide 7 text

More artifacts than ever ✓ Microservices ✓ Developer sprawl ✓ CI/CD ✓ Agentic AI

Slide 8

Slide 8 text

Organizations depend on artifact registries

Slide 9

Slide 9 text

No content

Slide 10

Slide 10 text

No content

Slide 11

Slide 11 text

Their availability, performance, security & integrity make or break the software supply chain

Slide 12

Slide 12 text

https://xkcd.com/303/

Slide 13

Slide 13 text

Your software supply chain has never been under more pressure

Slide 14

Slide 14 text

Rate limits

Slide 15

Slide 15 text

Rate limits & outages. Slow GitHub Actions pipelines.

Slide 16

Slide 16 text

License cost, egress charges, scalability issues

Slide 17

Slide 17 text

Cloud outages impact availability of registries

Slide 18

Slide 18 text

More commits, more PRs, more builds, more artifact fetches, more API calls

Slide 19

Slide 19 text

No content

Slide 20

Slide 20 text

An update on GitHub availability The main driver is a rapid change in how software is being built. Since the second half of December 2025, agentic development workflows have accelerated sharply. By nearly every measure, the direction is already clear: repository creation, pull request activity, API usage, automation, and large-repository workloads are all growing quickly. https://github.blog/news-insights/company-news/an-update-on-github-availability/

Slide 21

Slide 21 text

No content

Slide 22

Slide 22 text

Challenging

Slide 23

Slide 23 text

Hi, I'm Thijs

Slide 24

Slide 24 text

No content

Slide 25

Slide 25 text

Can accelerate anything that speaks http

Slide 26

Slide 26 text

No content

Slide 27

Slide 27 text

User Varnish Server

Slide 28

Slide 28 text

CI/CD Varnish Registry

Slide 29

Slide 29 text

$ docker pull ubuntu Using default tag: latest latest: Pulling from library/ubuntu b380bbd43752: Pulling fs layer 5a5bd11a791e: Pulling fs layer d4d1cd1a70f3: Pulling fs layer b380bbd43752: Download complete d4d1cd1a70f3: Download complete 5a5bd11a791e: Download complete b380bbd43752: Pull complete 5a5bd11a791e: Pull complete d4d1cd1a70f3: Pull complete Digest: sha256:72f6db1e83b7a178d32b6a73a1cfda5f2cb236d25844b76b1af68cd8c47e4c1a Status: Downloaded newer image for ubuntu:latest docker.io/library/ubuntu:latest

Slide 30

Slide 30 text

$ docker pull ubuntu Using default tag: latest latest: Pulling from library/ubuntu b380bbd43752: Pulling fs layer 5a5bd11a791e: Pulling fs layer d4d1cd1a70f3: Pulling fs layer b380bbd43752: Download complete d4d1cd1a70f3: Download complete 5a5bd11a791e: Download complete b380bbd43752: Pull complete 5a5bd11a791e: Pull complete d4d1cd1a70f3: Pull complete Digest: sha256:72f6db1e83b7a178d32b6a73a1cfda5f2cb236d25844b76b1af68cd8c47e4c1a Status: Downloaded newer image for ubuntu:latest docker.io/library/ubuntu:latest Uses HTTP Can be slow Can be cached

Slide 31

Slide 31 text

– 20 40% of total CI/CD pipeline time consumed by dependency downloads

Slide 32

Slide 32 text

Why cache artifacts? ✓ Faster delivery ✓ Cost reduction ✓ Scalability ✓ Resilience

Slide 33

Slide 33 text

Varnish Virtual Registry (Orca)

Slide 34

Slide 34 text

No content

Slide 35

Slide 35 text

https://www.varnish-software.com/orca

Slide 36

Slide 36 text

$ docker run -p 80:80 varnish/orca

Slide 37

Slide 37 text

varnish: http: - port: 80 virtual_registry: config.yaml registries: - name: dockerhub default: true remotes: - url: https://docker.io - url: https://mirror.gcr.io - name: ghcr remotes: - url: https://ghcr.io - name: npmjs remotes: - url: https://registry.npmjs.org

Slide 38

Slide 38 text

services: orca: image: varnish/orca ports: - "80:80" volumes: - ./config.yaml:/app/config.yaml:ro command: --config /app/config.yaml $ docker compose up

Slide 39

Slide 39 text

$ helm install varnish-orca -f values.yaml oci://docker.io/ varnish/orca-chart

Slide 40

Slide 40 text

Using Varnish Orca docker pull docker.localhost/library/ubuntu npm install express --registry=http://npmjs.localhost GOPROXY=http://go.localhost go mod tidy helm pull oci://ghcr.localhost/prometheus-community/ charts/prometheus --plain-http git clone http://github.localhost/varnish/varnish.git

Slide 41

Slide 41 text

Hyperlocalization

Slide 42

Slide 42 text

No content

Slide 43

Slide 43 text

Cache miss $ time docker pull docker.localhost/library/node:latest latest: Pulling from library/node 635135721e54: Pull complete f28313c8eaf1: Pull complete 39feea71264a: Pull complete 2882152811f6: Pull complete fd264eb324d0: Pull complete 203fdd9313dd: Pull complete c2f1a73884c0: Pull complete Digest: sha256:e3ffe0cbaeebdcddbfe1ee7bca9b564a92863a8386d5b99a3d72677b3667b61d Status: Downloaded newer image for docker.localhost/library/node:latest docker.localhost/library/node:latest What's next: View a summary of image vulnerabilities and recommendations → docker scout quickview docker.localhost/library/node:latest docker pull docker.localhost/library/node:latest 0,13s user 0,15s system 1% cpu 24,909 total

Slide 44

Slide 44 text

Cache hit $ time docker pull docker.localhost/library/node:latest latest: Pulling from library/node 635135721e54: Pull complete f28313c8eaf1: Pull complete 39feea71264a: Pull complete 2882152811f6: Pull complete fd264eb324d0: Pull complete 203fdd9313dd: Pull complete c2f1a73884c0: Pull complete Digest: sha256:e3ffe0cbaeebdcddbfe1ee7bca9b564a92863a8386d5b99a3d72677b3667b61d Status: Downloaded newer image for docker.localhost/library/node:latest docker.localhost/library/node:latest What's next: View a summary of image vulnerabilities and recommendations → docker scout quickview docker.localhost/library/node:latest docker pull docker.localhost/library/node:latest 0,11s user 0,13s system 1% cpu 12,727 total

Slide 45

Slide 45 text

No content

Slide 46

Slide 46 text

$2M cost reduction

Slide 47

Slide 47 text

Reduce developer wait time 15 min 3 min Daily wait time saved per developer by caching artifacts in the CI/CD pipeline

Slide 48

Slide 48 text

Virtual Registry capabilities Artifact-aware acceleration Authentication preservation Origin shielding Failover Multi-registry routing Persistence Request coalescing Observability

Slide 49

Slide 49 text

Your software supply chain has never been more vulnerable

Slide 50

Slide 50 text

Trusted registries deliver compromised packages

Slide 51

Slide 51 text

- - 2026 Software Supply Chain Attacks ✓ 20 40 major Supply Chain Campaigns ✓ 20,000+ malicious packages were discovered ✓ 1000+ packages were directly compromised in high-profile incidents ✓ 10 20 million estimated malicious packages were downloaded

Slide 52

Slide 52 text

https://www.codeant.ai/blogs/shai-hulud-npm-supply-chain-attack

Slide 53

Slide 53 text

No content

Slide 54

Slide 54 text

Artifact Firewall

Slide 55

Slide 55 text

Enforcement at request time

Slide 56

Slide 56 text

No content

Slide 57

Slide 57 text

id: my-ruleset rules: - id: GHSA-c35v-qwqg-87jc match: - purl: pkg:npm/express-basic-auth version: vers:npm/<1.1.7 severity: 3.1 reason: "express-basic-auth timing attack" - id: hello-world-npm action: hide reason: "Hide v1.1.1 of hello-world-npm for testing" match: - purl: pkg:npm/hello-world-npm version: vers:npm/=1.1.1 - id: faker-npm match: - purl: pkg:npm/faker.js action: deny reason: "faker.js is broken" my-ruleset.yaml

Slide 58

Slide 58 text

id: my-ruleset rules: - id: GHSA-c35v-qwqg-87jc match: - purl: pkg:npm/express-basic-auth version: vers:npm/<1.1.7 severity: 3.1 reason: "express-basic-auth timing attack" - id: hello-world-npm action: hide reason: "Hide v1.1.1 of hello-world-npm for testing" match: - purl: pkg:npm/hello-world-npm version: vers:npm/=1.1.1 - id: faker-npm match: - purl: pkg:npm/faker.js action: deny reason: "faker.js is broken"

Slide 59

Slide 59 text

id: my-ruleset rules: - id: GHSA-c35v-qwqg-87jc match: - purl: pkg:npm/express-basic-auth version: vers:npm/<1.1.7 severity: 3.1 reason: "express-basic-auth timing attack" - id: hello-world-npm action: hide reason: "Hide v1.1.1 of hello-world-npm for testing" match: - purl: pkg:npm/hello-world-npm version: vers:npm/=1.1.1 - id: faker-npm match: - purl: pkg:npm/faker.js action: deny reason: "faker.js is broken"

Slide 60

Slide 60 text

No content

Slide 61

Slide 61 text

varnish: http: - port: 80 virtual_registry: registries: - name: npmjs default: true remotes: - url: https://registry.npmjs.org firewall: default_action: allow default_quarantine_days: 2 severity_deny_threshold: 9.0 severity_allow_threshold: 4.0 rulesets: - path: /rulesets/my-ruleset.yaml - git: name: npm-osv-rules url: https://github.com/varnish/osv-rules.git sub_path: rulesets/npm/all.yaml Orca config file

Slide 62

Slide 62 text

varnish: http: - port: 80 virtual_registry: registries: - name: npmjs default: true remotes: - url: https://registry.npmjs.org firewall: default_action: allow default_quarantine_days: 2 severity_deny_threshold: 9.0 severity_allow_threshold: 4.0 rulesets: - path: /rulesets/my-ruleset.yaml - git: name: npm-osv-rules url: https://github.com/varnish/osv-rules.git sub_path: rulesets/npm/all.yaml

Slide 63

Slide 63 text

varnish: http: - port: 80 virtual_registry: registries: - name: npmjs default: true remotes: - url: https://registry.npmjs.org firewall: default_action: allow default_quarantine_days: 2 severity_deny_threshold: 9.0 severity_allow_threshold: 4.0 rulesets: - path: /rulesets/my-ruleset.yaml - git: name: npm-osv-rules url: https://github.com/varnish/osv-rules.git sub_path: rulesets/npm/all.yaml

Slide 64

Slide 64 text

fi High pro le attacks where all listed on OSV.dev in 48h

Slide 65

Slide 65 text

$ npm install faker-js --registry=http://npmjs.localhost --prefer-online npm error code E403 npm error 403 403 Forbidden - GET http://npmjs.localhost/faker-js - package blocked by firewall (rule "faker-npm", ruleset "my-ruleset") npm error 403 In most cases, you or one of your dependencies are requesting npm error 403 a package version that is forbidden by your security policy, or npm error 403 on a server you do not have access to.

Slide 66

Slide 66 text

https://www.varnish-software.com/orca

Slide 67

Slide 67 text

Meet us outside