A Varnish Cache On Loopback With A PURGE ACL

Varnish from AppStream as a loopback HTTP cache with health-probed backends and PURGE limited to the addresses you list. Its VCL is checked before it lands, with -j none because the compiler cannot read root's temp files, and reloaded so the cache survives. The live test sees MISS then HIT with one origin request, a working purge and a refused one. Original role, live-tested on Rocky Linux 10.

ansibleWeb & App Servers

Verification

Live-tested

Really deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.

Conformance

  • Static validation (yamllint · ansible-lint)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-10-02 · podman 4.9.3 · ansible 2.21.4 · how we verify

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/ansible-varnish/badge)](https://www.iac-bazaar.com/catalog/ansible-varnish?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Ansible role 1.0.0, live-tested on IaC Bazaar: [A Varnish Cache On Loopback With A PURGE ACL](https://www.iac-bazaar.com/catalog/ansible-varnish?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```yaml
# A Varnish Cache On Loopback With A PURGE ACL: https://www.iac-bazaar.com/catalog/ansible-varnish (download from your IaC Bazaar account)
```

Preview:IaC Bazaar: live-tested

Documentation

varnish

Varnish from AppStream: an HTTP cache in front of your origin servers, round-robin with health probes, listening on loopback (behind a TLS terminator, which the PROXY-protocol listener is for), with PURGE allowed only from the addresses you list. Original role for EL 10, live-tested with podman on Rocky Linux 10.

No download, and no version to pin. EL 10 packages varnish, so the role installs it by name and takes what the distribution ships: a security update arrives through dnf, not through a new release of this role. What the role owns is the configuration and the proof that the service works.

The distribution's unit, our configuration. The role installs varnish, writes the configuration the package leaves open, and enables the unit the package ships: systemctl cat varnish shows the distribution's own unit, not one this role invented. The listener is 127.0.0.1:6081 by default, for a proxy that authenticates or a client on the same host; the live test reads the listening sockets and expects loopback only.

A drop-in that forgets -P never starts. The packaged unit is Type=forking with a PIDFile=, so an ExecStart= override without -P %t/%N/varnishd.pid makes systemd wait for a PID file that never appears: measured, the start timed out. The role's drop-in keeps it, and moves the listener and the admin interface to loopback - the package listens on :6081, every interface - while keeping its PROXY-protocol listener for a TLS terminator in front.

Reload, not restart. A VCL change is checked with varnishd -C before it lands (a misspelt subroutine is refused, measured) - with -j none, because varnishd compiles as its jail user, which cannot read the file Ansible checks under root's home ("Permission denied", measured) - and loaded with varnishreload, which kept the cached object in the lane; a restart would have emptied the cache. Unit changes restart, after a daemon reload.

Proven by the cache. The live test serves a page from the default backend and sees MISS then HIT with ONE origin request, a PURGE from 127.0.0.1 accepted and the next request a MISS, a PURGE from 127.0.0.2 refused (405), and the admin interface answering its secret and refusing a wrong one.

License

Commercial - IaC Bazaar EULA. (c) IaC Bazaar.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Variables
  • Test

Related modules

Live-tested

ansible-httpd-tls

httpd with mod_ssl from AppStream on EL 10: one TLS site, an explicit protocol floor and cipher list, HSTS, and the plain port doing nothing but redirecting. The live test reads the site with the certificate the role installed, checks the headers, and is refused when it asks for a cipher outside the list. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-caddy-https

Caddy with HTTPS on: the package serves plain HTTP with a Server header and an admin API any local process can use. This role gives private names a certificate from Caddy's own CA (public ones get Let's Encrypt), redirects HTTP, sends HSTS and the security headers, drops Server, turns the admin API off, and serves files or proxies an upstream. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-nginx

Verified wrapper around geerlingguy.nginx pinned at 3.3.0 plus an IaC Bazaar hardening overlay (server_tokens off, security headers, default-vhost removal); live-tested for idempotence and functionally verified: systemd unit active, HTTP 200, headers present, no version leak.

View module
Live-tested

ansible-php-fpm

php-fpm from AppStream on EL 10: one pool on a unix socket, open_basedir closed around its own tree, and the process-spawning functions removed. The live test runs PHP through the socket, is refused a read outside the tree, watches a call to a removed function stop the request, and finds nothing listening on TCP. Original role, live-tested on Rocky Linux 10.

View module