Slide 1

Slide 1 text

No content

Slide 2

Slide 2 text

Slow websites SUCK

Slide 3

Slide 3 text

WEB PERFORMANCE IS AN ESSENTIAL PART OF THE USER EXPERIENCE

Slide 4

Slide 4 text

SLOW ~ DOWN

Slide 5

Slide 5 text

No content

Slide 6

Slide 6 text

No content

Slide 7

Slide 7 text

No content

Slide 8

Slide 8 text

THROWING SERVERS AT THE PROBLEM

Slide 9

Slide 9 text

MO' MONEY MO' SERVERS MO' PROBLEMS

Slide 10

Slide 10 text

IDENTIFY SLOWEST PARTS

Slide 11

Slide 11 text

OPTIMIZE

Slide 12

Slide 12 text

AFTER A WHILE YOU HIT THE LIMITS

Slide 13

Slide 13 text

CACHE

Slide 14

Slide 14 text

HI, I'M THIJS

Slide 15

Slide 15 text

I'M AN EVANGELIST AT

Slide 16

Slide 16 text

No content

Slide 17

Slide 17 text

No content

Slide 18

Slide 18 text

+-5,000,000 WEBSITES 20% OF THE TOP 10K WEBSITES

Slide 19

Slide 19 text

No content

Slide 20

Slide 20 text

I'M @THIJSFERYN

Slide 21

Slide 21 text

No content

Slide 22

Slide 22 text

BEYOND BASIC WEB ACCELERATION?

Slide 23

Slide 23 text

BASIC

Slide 24

Slide 24 text

CONTENT DELIVERY CHALLENGES

Slide 25

Slide 25 text

HEAVY COMPUTING

Slide 26

Slide 26 text

NETWORK CAPACITY

Slide 27

Slide 27 text

SERVER CAPACITY

Slide 28

Slide 28 text

IMPACT ON YOUR SERVERS

Slide 29

Slide 29 text

DON’T RECOMPUTE IF THE DATA HASN’T CHANGED

Slide 30

Slide 30 text

REVERSE CACHING PROXY

Slide 31

Slide 31 text

NORMALLY USER SERVER

Slide 32

Slide 32 text

WITH REVERSE CACHING PROXY USER PROXY SERVER

Slide 33

Slide 33 text

No content

Slide 34

Slide 34 text

WHY NOT USE A CDN?

Slide 35

Slide 35 text

VARNISH IS CDN SOFTWARE!

Slide 36

Slide 36 text

VARNISH CAN BE THERE TO PROTECT YOUR SERVERS FROM YOUR CDN

Slide 37

Slide 37 text

CDNS WITH MANY POINTS OF PRESENCE WILL DDOS YOUR ORIGIN

Slide 38

Slide 38 text

WHY IS VARNISH SO POWERFUL?

Slide 39

Slide 39 text

WHY IS VARNISH SO POWERFUL? ✓ EXTREMELY LOW RESOURCE ✓ EXTREMELY STABLE ✓ 100 GBIT PER SERVER ✓ NO DISK ACCESS AT RUNTIME ✓ REQUEST COALESCING ✓ VARNISH CONFIGURATION LANGUAGE ✓ VMODS ✓ COMPLIES TO HTTP BEST PRACTICES ✓ ENTERPRISE FEATURES*

Slide 40

Slide 40 text

ORIGIN VARNISH REQUEST COALESCING

Slide 41

Slide 41 text

POWER THE REASON WHY PEOPLE TRUST VARNISH

Slide 42

Slide 42 text

HTTP THE REASON WHY PEOPLE USE VARNISH

Slide 43

Slide 43 text

VCL THE REASON WHY PEOPLE ❤ VARNISH

Slide 44

Slide 44 text

HTTP

Slide 45

Slide 45 text

HTTP CACHING MECHANISMS Expires: Sat, 09 Sep 2017 14:30:00 GMT Cache-control: public, max-age=3600, s-maxage=86400 Cache-control: private, no-cache, no-store

Slide 46

Slide 46 text

CACHE VARIATIONS Vary: Accept-Language

Slide 47

Slide 47 text

CONDITIONAL REQUESTS HTTP/1.1 200 OK Host: localhost Etag: 7c9d70604c6061da9bb9377d3f00eb27 Content-type: text/html; charset=UTF-8 Hello world output GET / HTTP/1.1 Host: localhost

Slide 48

Slide 48 text

CONDITIONAL REQUESTS HTTP/1.1 304 Not Modified Host: localhost Etag: 7c9d70604c6061da9bb9377d3f00eb27 GET / HTTP/1.1 Host: localhost If-None-Match: 7c9d70604c6061da9bb9377d3f00eb27

Slide 49

Slide 49 text

IN AN IDEAL WORLD

Slide 50

Slide 50 text

✓STATELESS ✓WELL-DEFINED TTL ✓CACHE / NO-CACHE PER RESOURCE ✓CACHE VARIATIONS ✓CONDITIONAL REQUESTS ✓PLACEHOLDERS FOR NON-CACHEABLE CONTENT IN AN IDEAL WORLD

Slide 51

Slide 51 text

REALITY SUCKS

Slide 52

Slide 52 text

No content

Slide 53

Slide 53 text

No content

Slide 54

Slide 54 text

TIME TO LIVE

Slide 55

Slide 55 text

CACHE VARIATIONS

Slide 56

Slide 56 text

LEGACY

Slide 57

Slide 57 text

VARNISH CONFIGURATION LANGUAGE

Slide 58

Slide 58 text

DOMAIN-SPECIFIC LANGUAGE, COMPILED TO C

Slide 59

Slide 59 text

HOOKS INTO FINITE STATE MACHINE

Slide 60

Slide 60 text

INFLUENCE CACHING BEHAVIOR

Slide 61

Slide 61 text

INFLUENCE CACHING BEHAVIOR ✓ WHAT TO CACHE ✓ WHAT NOT TO CACHE ✓ HOW LONG TO CACHE ✓ HOW TO CACHE ✓ HOW TO EMPTY THE CACHE ✓ CHANGE REQUEST/RESPONSE/PAYLOAD

Slide 62

Slide 62 text

THE VARNISH FLOW

Slide 63

Slide 63 text

No content

Slide 64

Slide 64 text

No content

Slide 65

Slide 65 text

sub vcl_recv { if (req.url ~ "^/status\.php$" || req.url ~ "^/update\.php$" || req.url ~ "^/admin$" || req.url ~ "^/admin/.*$" || req.url ~ "^/flag/.*$" || req.url ~ "^.*/ajax/.*$" || req.url ~ "^.*/ahah/.*$") { return (pass); } } URL blacklist example

Slide 66

Slide 66 text

sub vcl_recv { if (req.url ~ "^/some-page" return (hash); } } URL whitelist example

Slide 67

Slide 67 text

vcl 4.0; sub vcl_recv { if (req.http.Cookie) { set req.http.Cookie = ";" + req.http.Cookie; set req.http.Cookie = regsuball(req.http.Cookie, "; +", ";"); set req.http.Cookie = regsuball(req.http.Cookie, ";(SESS[a-z0-9]+|SSESS[a-z0-9]+|NO_CACHE)=", "; \1="); set req.http.Cookie = regsuball(req.http.Cookie, ";[^ ][^;]*", ""); set req.http.Cookie = regsuball(req.http.Cookie, "^[; ]+|[; ]+$", ""); if (req.http.Cookie == "") { unset req.http.Cookie; } else { return (pass); } } } Cookie example

Slide 68

Slide 68 text

sub vcl_recv { if (req.http.Cookie) { set req.http.Cookie = ";" + req.http.Cookie; set req.http.Cookie = regsuball(req.http.Cookie, "; +", ";"); set req.http.Cookie = regsuball(req.http.Cookie, ";(language)=", "; \1="); set req.http.Cookie = regsuball(req.http.Cookie, ";[^ ][^;]*", ""); set req.http.Cookie = regsuball(req.http.Cookie, "^[; ]+|[; ]+$", ""); if (req.http.cookie ~ "^\s*$") { unset req.http.cookie; return(pass); } return(hash); } } sub vcl_hash { hash_data(regsub( req.http.Cookie, "^.*language=([^;]*);*.*$", "\1" )); } Cookie cache variation

Slide 69

Slide 69 text

THE VMOD ECOSYSTEM HTTPS://VARNISH-CACHE.ORG/VMODS/ HTTPS://DOCS.VARNISH-SOFTWARE.COM/VARNISH-CACHE-PLUS/VMODS/

Slide 70

Slide 70 text

NEXT LEVEL

Slide 71

Slide 71 text

NOT JUST A CACHE NOT JUST "TAKE IT OR LEAVE IT"

Slide 72

Slide 72 text

AN HTTP LOGIC BOX

Slide 73

Slide 73 text

DECISION MAKING IN THE EDGE

Slide 74

Slide 74 text

CONTENT TRANSFORMATION IN THE EDGE

Slide 75

Slide 75 text

CACHING THE UNCACHEABLE

Slide 76

Slide 76 text

VARNISH DOESN'T JUST ACCELERATE WEB PAGES

Slide 77

Slide 77 text

WEB/API CDN STREAMING

Slide 78

Slide 78 text

ONLINE VIDEO STREAMING

Slide 79

Slide 79 text

OVERTTHETOP

Slide 80

Slide 80 text

No content

Slide 81

Slide 81 text

PACKAGING

Slide 82

Slide 82 text

HTTP VIDEO PACKAGING FORMATS ✓ HLS ✓ MPEG-DASH ✓ CMAF

Slide 83

Slide 83 text

HTTP LIVE STREAMING (HLS)

Slide 84

Slide 84 text

VIDEO.MP4 STREAM.M3U8 STREAM_01.TS STREAM_02.TS STREAM_03.TS ENCODING & PACKAGING VIDEO: H264 AUDIO: AAC

Slide 85

Slide 85 text

#EXTM3U #EXT-X-VERSION:3 #EXT-X-TARGETDURATION:6 #EXT-X-MEDIA-SEQUENCE:0 #EXT-X-PLAYLIST-TYPE:VOD #EXTINF:6.000000, stream_00.ts #EXTINF:6.000000, stream_01.ts #EXTINF:6.000000, stream_02.ts #EXTINF:6.000000, stream_03.ts #EXTINF:6.000000, stream_04.ts #EXTINF:6.000000, stream_05.ts #EXTINF:6.000000, stream_06.ts #EXTINF:6.000000, stream_07.ts #EXTINF:6.000000, stream_08.ts #EXTINF:6.000000, stream_09.ts #EXTINF:5.280000, stream_010.ts #EXT-X-ENDLIST STREAM.M3U8

Slide 86

Slide 86 text

PLAYER NEEDS TO SUPPORT HLS

Slide 87

Slide 87 text

Slide 88

Slide 88 text

LIVE ✓ LOW LATENCY ✓ CONSTANT PLAYLIST UPDATES ✓ LOW TTL ON PLAYLISTS ✓ ONLY THE LAST X SEGMENTS ARE REQUIRED ✓ SEGMENT SIZE TRADEOFF

Slide 89

Slide 89 text

VOD ✓ NO PLAYLIST UPDATES ✓ HIGH TTL ON PLAYLISTS ✓ ALL SEGMENTS ARE REQUIRED ✓ STORAGE REQUIREMENTS ✓ PRE-FETCHING POSSIBLE

Slide 90

Slide 90 text

MORE VIDEO FEATURES ✓ GEOIP ✓ DIGITAL RIGHTS MANAGEMENT ✓ AUTHENTIATION ✓ THROTTLING & RATE LIMITING ✓ ADAPTIVE BITRATE FILTERING ✓ NO MORE ORIGIN

Slide 91

Slide 91 text

vcl 4.1; import http; import std; backend default { .host = "origin"; .port = "80"; } sub vcl_recv { if (req.url ~ "^/vod/.+\.ts$") { http.init(0); http.req_set_max_loops(0,1); http.req_copy_headers(0); http.req_set_method(0, "HEAD"); set req.http.x-next-url = http.prefetch_next_url(); std.log("Prefetching " + req.http.x-next-url); http.req_set_url(0, req.http.x-next-url); http.req_send_and_finish(0); } }

Slide 92

Slide 92 text

vcl 4.1; import file; sub vcl_init { new root = file.init("/var/www/html/"); } sub vcl_backend_fetch { set bereq.backend = root.backend(); } sub vcl_backend_response { if(bereq.url ~ "^/live/stream_[0-9]+\.m3u8$" || bereq.url == "/live/master.m3u8") { set beresp.grace = 0s; set beresp.ttl = 1s; } }

Slide 93

Slide 93 text

CACHING THE UNCACHEABLE

Slide 94

Slide 94 text

STATE

Slide 95

Slide 95 text

COOKIES

Slide 96

Slide 96 text

sub vcl_recv { if (req.http.Authorization || req.http.Cookie) { /* Not cacheable by default */ return (pass); } }

Slide 97

Slide 97 text

sub vcl_backend_response { if (bereq.uncacheable) { return (deliver); } else if (beresp.ttl <= 0s || beresp.http.Set-Cookie || beresp.http.Surrogate-control ~ "(?i)no-store" || (!beresp.http.Surrogate-Control && beresp.http.Cache-Control ~ "(?i:no-cache|no-store|private)") || beresp.http.Vary == "*") { # Mark as "Hit-For-Miss" for the next 2 minutes set beresp.ttl = 120s; set beresp.uncacheable = true; } return (deliver); }

Slide 98

Slide 98 text

TAKE IT OR LEAVE IT SITUATION

Slide 99

Slide 99 text

PLACEHOLDERS

Slide 100

Slide 100 text

CACHING THE UNCACHEABLE

Slide 101

Slide 101 text

ORIGIN VARNISH SESSION STORE EXPOSE TEMPLATE PARSE & CACHE TEMPLATE FETCH DATA FROM SESION STORE RETURN PERSONALIZED OUTPUT

Slide 102

Slide 102 text

Welcome {{ name }}

You have {{ shopping-cart-items }} items in your shopping cart Contains session data

Slide 103

Slide 103 text

_sf2_attributes|a:2:{s:4:"name";s:11:"Thijs Feryn";s:19:"shopping- cart-items";i:6;}_sf2_meta|a:3:{s:1:"u";i:1558952585;s:1:"c";i: 1558952585;s:1:"l";s:1:"0";} PHP serialized session data

Slide 104

Slide 104 text

vcl 4.1; import cookieplus; import memcached; import edgestash; backend default { .host = "origin"; .port = "80"; } sub vcl_init { memcached.servers("--SERVER=memcached:11211"); } sub vcl_recv { if(cookieplus.get("PHPSESSID") !~ "[a-z0-9]+") { return(pass); } return(hash); } sub vcl_backend_response { if (req.url == "/") { edgestash.parse_response(); } if(cookieplus.setcookie_get("PHPSESSID") ~ "[a-z0-9]+") { set beresp.http.x-session-id = cookieplus.setcookie_get("PHPSESSID"); cookieplus.setcookie_delete("PHPSESSID"); } }

Slide 105

Slide 105 text

sub vcl_deliver { if (edgestash.is_edgestash() && req.url == "/") { set resp.http.x-session-raw = memcached.get("sf2s" + cookieplus.get("PHPSESSID", "")); set resp.http.x-session-base = regsuball(resp.http.x-session-raw,"_sf2_attributes\|a:[0-9]+:\{",""); set resp.http.x-session-base = regsuball(resp.http.x-session-base,";}_sf2_meta\|a:.+",""); set resp.http.x-name = regsuball(resp.http.x-session-base,"^([^;]+;)*s:4:\x22name\x22;s:[0-9]+: \x22([^\x22]+)\x22.+$","\2"); set resp.http.x-shopping-cart-items = regsuball(resp.http.x-session-base,"^([^;]+;)*s:19:\x22shopping-cart- items\x22;i:([0-9]+).*$","\2"); edgestash.add_json({" { "name": ""} + resp.http.x-name + {"", "shopping-cart-items": ""} + resp.http.x-shopping-cart-items + {"" } "}); edgestash.execute(); unset resp.http.x-session-raw; unset resp.http.x-session-base; unset resp.http.x-name; unset resp.http.x-shopping-cart-items; if(resp.http.x-session-id ~ "[a-z0-9]+") { cookieplus.setcookie_add("PHPSESSID", resp.http.x-session-id, 30d, req.http.Host, "/"); cookieplus.setcookie_write(); unset resp.http.x-session-id; } } }

Slide 106

Slide 106 text

Welcome Thijs Feryn

You have 6 items in your shopping cart END RESULT

Slide 107

Slide 107 text

FANCY REDIS?

Slide 108

Slide 108 text

import redis; sub vcl_init { new db = redis.db( location="redis:6379", type=master, connection_timeout=500, shared_connections=false, max_connections=1); } sub vcl_deliver { db.command("GET"); db.push("sf_s" + cookieplus.get("PHPSESSID")); db.execute(); set resp.http.x-session-raw = db.get_reply(); set resp.http.x-session-base = regsuball(resp.http.x-session-raw,"_sf2_attributes\|a: [0-9]+:\{",""); set resp.http.x-session-base = regsuball(resp.http.x-session-base,";}_sf2_meta\|a:. +",""); .... }

Slide 109

Slide 109 text

Link: ; rel=prefetch Pre-fetch CSS file

Slide 110

Slide 110 text

vcl 4.0; import http; sub vcl_recv { // Store Varnish's local address for later use set req.http.X-prefetch = http.varnish_url("/"); } sub vcl_backend_response { if (beresp.http.Link ~ "<.+>.*(prefetch|next)") { // Pull out the Link URL set bereq.http.X-link = regsub(beresp.http.Link, "^.*<([^>]*)>.*$", "\1"); set bereq.http.X-prefetch = regsub(bereq.http.X-prefetch, "/$", bereq.http.X-link); // Prefetch the Link URL back thru Varnish http.init(0); http.req_copy_headers(0); http.req_set_url(0, bereq.http.X-prefetch); http.req_send_and_finish(0); } }

Slide 111

Slide 111 text

vcl 4.0; import xbody; sub vcl_backend_response { xbody.regsub("www.example.com", "test.example.com"); xbody.regsub("[email protected]", "[email protected]"); } Body replacements

Slide 112

Slide 112 text

•Accept •Akamai connector •Body access & transformation •Cookieplus •Device atlas •Edgestash •File •Geolocation •HTTP communication •JSON parser •Key-value store •Synthetic backends •Encryption •Rate limiting •Throttling •Xkey •Abtest •Authentication •Cookie •Digest •DNS •I18n •LDAP •LUA •Memcached •Redis •OTP •SOAP •UUID

Slide 113

Slide 113 text

No content

Slide 114

Slide 114 text

VARNISH ENTERPRISE ✓ CLIENT SSL TERMINATION ✓ BACKEND SSL CONNECTIONS ✓ PARALLEL ESI ✓ MASSIVE STORAGE ENGINE ✓ ENCRYPTION ✓ THROTTLING ✓ RATE LIMITING ✓ PREFETCHING ✓ GEOLOCATION ✓ AUTHENTICATION ✓ EDGESTASH ✓ CUSTOM STATISTICS ✓ ADMIN MODULE ✓ SUPPORT ✓ HIGH AVAILABILITY ✓ MOBILE APP

Slide 115

Slide 115 text

HTTPS://AWS.AMAZON.COM/QUICKSTART/ARCHITECTURE/VARNISH/

Slide 116

Slide 116 text

No content

Slide 117

Slide 117 text

No content

Slide 118

Slide 118 text

HTTPS://FERYN.EU HTTPS://TWITTER.COM/THIJSFERYN HTTPS://INSTAGRAM.COM/THIJSFERYN