A Varnish 6.x container for Docker and Kubernetes optimized for Wordpress and Drupal
10K+

Flight Deck Varnish is a minimalist Varnish container for Drupal sites on Kubernetes and Docker. You can use it both for local development and production.
Features:
There are several tags available for this container, each with different Solr and module support:
| Tags | Varnish version |
|---|---|
| stable, latest | 6.6 |
| edge, develop | 6.6 |
| x.y.z | 6.6 |
Instead of a large number of environment variables, this container relies on a file to perform all runtime configuration, flightdeck-varnish.yml. Inside the file, create following:
---
flightdeck_varnish: {}
All configuration is done as items under the flightdeck_varnish variable. See the following sections for details as to particular configurations.
You can provide this file in one of three ways to the container:
/config/web/flightdeck-varnish.yml inside the container using a bind mount, configmap, or secret.FLIGHTDECK_CONFIG_FILE environment variable to the path of the file.flightdeck-varnish.yml as base64 and assign the result to the FLIGHTDECK_CONFIG environment variable.---
flightdeck_varnish:
secret: "secretish"
hostPort: "6081"
controlPort: "6082"
memSize: "256m"
storageFile: "/var/lib/varnish/storage.bin"
storageSize: "1024m"
Where:
6081.6082.256m./var/lib/varnish/storage.bin.1024m.Varnish acts as a caching reverse HTTP proxy. You can specify one or more backends by defining the flightdeck_varnish.backends list:
---
flightdeck_varnish:
backends:
- name: "default"
host: "web"
port: "80"
For each item:
80.Sometimes, you may wish to keep certain credentials in separate files from the rest of the configuration. One such case is if you want to keep flightdeck-varnish.yml in a Kubernetes configmap, but keep the database passwords in secrets instead.
---
flightdeck_varnish:
secretFile: "/config/varnish-secret/secret.txt"
Where:
Depending on your application, you may need to specify a particular series of timeouts in order for Varnish to consider your backend "healthy". You can specify these per backend:
---
flightdeck_varnish:
backends:
- name: "default"
host: "web"
port: "80"
firstByteTimeout: "300s"
connectTimeout: "5s"
betweenBytesTimeout: "2s"
Where:
Varnish can routinely check the health of the backend through a "probe".
---
flightdeck_varnish:
backends:
- name: "default"
host: "web"
port: "80"
probe: no
probeHost: "www.example.com"
probeHeaders:
- name: "X-Forwarded-Proto"
value: "https"
probeInterval: "15s"
probeTimeout: "5s"
probeThreshold: 3
probeWindow: 5
Where:
yes) or disables (no) probe behavior. Optional, default is no.localhost.Some paths, such administration paths, key user interaction paths should not be cached by varnish. If the user login page is cached, for example, you may not be able to login, as Varnish would return the un-logged in HTML each time.
You can configure which items always bypass the cache in the configuration file:
---
flightdeck_varnish:
skipCache:
- "/status\\.php"
- "/update\\.php"
- "/install\\.php"
- "/wp-login\\.php"
- "/apc\\.php"
- "/admin"
- "/admin/.*"
- "/user"
- "/user/.*"
- "/users/.*"
- "/info/.*"
- "/flag/.*"
- "/wp-admin/.*"
- ".*/ahah/.*"
- "/system/files/.*"
Where:
Note: Avoid use of regex line beginning (^) and line ending ($) patterns as they do not match as expected.
Often, you may wish to skip caching based on the presence of key cookies. You can configure which ones using keepCookies:
---
flightdeck_varnish:
keepCookies:
- "SESS[a-z0-9]+"
- "SSESS[a-z0-9]+"
- "NO_CACHE"
- "XDEBUG_SESSION"
- "wordpress_logged_in_[a-z0-9]+"
- "wordpress_sec_[a-z0-9]+"
- "wp-settings-[0-9]+"
- "wp-settings-time-[0-9]+"
Where:
By default, any responses from the backend will be cached in accordance with the max-age header. There are two additional parmeters which allows you to control caching:
---
flightdeck_varnish:
grace: "6h"
staticTtl: "15m"
Where:
Often, you may wish to skip caching based on the presence of key cookies. You can configure which ones using keepCookies:
---
flightdeck_varnish:
errorPage: |
<html>
<body>
Something is broken!
</body>
</html>
Where:
Use the ten7.flightdeck_cluster role on Ansible Galaxy to deploy DB as a statefulset:
flightdeck_cluster:
namespace: "example-com"
configMaps:
- name: "flightdeck-varnish"
files:
- name: "flightdeck-varnish.yml"
content: |
flightdeck_varnish:
secret: "secretish"
hostPort: "6081"
controlPort: "6082"
memSize: "256m"
storageFile: "/var/lib/varnish/storage.bin"
storageSize: "1024m"
backends:
- name: "default"
host: "web"
port: "80"
web:
replicas: 1
configMaps:
- name: "flightdeck-varnish"
path: "/config/varnish"
Create the flightdeck-varnish.yml file relative to your docker-compose.yml. Define the varnish service mounting the file as a volume:
version: '3'
services:
varnish:
image: ten7/flightdeck-varnish-6
ports:
- 6081:6081
- 6082:6082
volumes:
- ./flightdeck-varnish.yml:/config/varnish/flightdeck-varnish.yml
This container is part of the Flight Deck library of containers for Drupal local development and production workloads on Docker, Swarm, and Kubernetes.
Flight Deck is used and supported by TEN7.
If you need to get verbose output from the entrypoint, set flightdeck_debug to true or yes in the config file.
---
flightdeck_debug: yes
This container uses Ansible to perform start-up tasks. To get even more verbose output from the start up scripts, set the ANSIBLE_VERBOSITY environment variable to 4.
If the container will not start due to a failure of the entrypoint, set the FLIGHTDECK_SKIP_ENTRYPOINT environment variable to true or 1, then restart the container.
Flight Deck is licensed under GPLv3. See LICENSE for the complete language.
Content type
Image
Digest
sha256:278123310…
Size
121.2 MB
Last updated
over 2 years ago
docker pull ten7/flightdeck-varnish-6