How to Use Varnish Cache as Secured AWS S3 Gateway
info.varnish-software.com
info.varnish-software.com
Not to rag on Varnish, I love it, I just don't really see this use case. Personally, I would never route plain S3 data through Varnish.
S3 bandwidth is pretty expensive. Even Akamai will give you less expensive bandwidth and their target market is enterprise media companies (e.g. ESPN) with deep pockets.
For someone with bandwidth costs issues who wants to use S3 as storage, they can put Varnish in front of it and serve the data with less expense.
What do you lose out on? HTTP/2, SSL, etc. unless you put another HTTP server in front of varnish.
Amazon S3 is essentially more expensive than a CDN for outgoing bandwidth even though it has only one PoP by default.
That's surprising since the typical case was that the CDN would be more expensive, and increasing the # of PoP you used in CDN would make it more expensive (e.g. there's a huge jump in pricing if you use Asia/Australia nodes).
http://charlesleifer.com/blog/nginx-a-caching-thumbnailing-r...
It works great, but it really bugs me that we had to do that. The default download speeds from our buckets on S3 are atrocious. We store big datafiles in S3, and our development flow involves downloading them lot. If Amazon had an upgrade to S3 so downloads by chosen users weren't throttled or slow, we'd pay for it in a heartbeat.
I'd still use CloudFront instead, which gives you these features plus the advantage of having global edge servers, and support for TLS/SSL (not sure about the http/2 part).
Although the one advantage this has is the cache can stop you from having to leave your external network to return a file (vs going to CloudFront or S3). That can be useful.
Another commenter pointed out that Varnish won't support TLS either, which is correct. The funny part about that is while they have long had the "why not SSL?" FAQ page espousing the terribleness of OpenSSL, they DO offer that feature on their paid product Varnish Plus. That not being a basic feature is a tad crazy.
[1] Why no ssl? https://www.varnish-cache.org/docs/4.1/phk/ssl.html
[2] http://info.varnish-software.com/blog/how-implement-ssltls-v...
This combined Varnish+Stunnel so that the varnish would redo keep-alives & stunnel could put it back over SSL.
So there was a web-app (PHP) -> varnish:8081 (cheap-alive) -> stunnel:8080 (reverse ssl) -> api.fb:443.
VCL makes Varnish much more of a programming language than a configuration system - but in total, skipping SSL negotiation in the PHP web-app and holding onto sessions via stunnel got APIs down from the 800ms -> 240ms range.