Virtual Registry 0.19.0

Released: 2026-10-06

Varnish version: 6.0.18r5

Artifact Firewall version: 0.7.0

Breaking

  • The body of an exported OTel log record is now exactly what varnishlog-json produced, byte for byte. It was previously rebuilt from the parsed transaction, so anything that reads the log body expecting a fixed JSON shape (a collector transform, a log backend’s parser, a saved query) needs to be checked against the new output before upgrading. Values derived from a transaction are now set as attributes on the record, so read them from there rather than from the body.
  • Log records no longer carry TraceId, SpanId and TraceFlags as string attributes. Every exporter already sets those natively on the record itself, so a backend that reads them from the attributes has to read the record fields instead.

Added

  • Every exported OTel log record now carries a SeverityNumber, so a backend can filter and alert on severity.
  • virtual_registry.purge.allow lists the addresses and CIDR ranges allowed to send PURGE /purgez, in addition to localhost. A purge could only come from the node itself, so a Varnish Broadcaster fanning it out to a cluster, or a webhook from the origin, was refused.
  • A registry’s max_ttl sets a maximum TTL, including for the packages and version-pinned manifests that were cached indefinitely. A longer TTL is lowered to it and the difference is added to keep, so the object is revalidated with a conditional request once it expires. Content-addressed objects are exempt.
  • Added book_path to a store, which puts its book, the index MSE4 keeps of what is cached, on a device of its own: MSE4 recommends a fast device for the book’s small random IO and a large one for the store’s sequential IO. size then covers the store alone, so give the book a volume holding book_size plus room for a resize. Set on a cache that already exists, it moves the book on the next start, copying it across and delaying that start.
  • Changing varnish.storage is now refused on reload instead of being accepted and ignored. The file devices are laid out before Varnish starts and mkfs.mse4 will not touch them while it is running, so a reload could never apply the change. Restart the Supervisor to apply one: growing a store or adding a new one keeps the cached objects, and only shrinking drops the objects at the tail.

Changed

  • A HEAD for a package is now fetched from the remote as a HEAD and cached on its own, instead of downloading the whole package to answer it. A client that sends a HEAD and then a GET makes two requests to the remote on first access. A remote that refuses a HEAD now refuses it through Orca too.
  • Orca no longer asks the remote to gzip a package, since nearly all packages are archives already. GitHub’s JSON and text objects still ask for gzip.
  • A remote’s 304 now revalidates the cached object in place instead of copying its body into a new one, which is what makes revalidating a large artifact cheap. Set fast_304: false on a registry to go back to the standard path, needed only for a remote whose 304 responses carry an updated Cache-Control or Vary.
  • Orca no longer sends the X-Varnish header to remotes.
  • --validate now fails when it is given no configuration file, through --config or SUPERVISOR_CONFIG. It used to check the built-in defaults alone and report them valid, which read as if the operator’s file had been checked.
  • A lone registry without default: true now logs a warning, since it answers only hosts that start with its name and anything else gets a 404.
  • Conan recipe and package files are now cached per registry instead of shared between registries at the same path, since Artifactory lets a deploy replace the files under an existing revision. A Conan file cached by an earlier version is fetched from the remote again after the upgrade, once for each registry that serves it.
  • Go module zips are now cached per registry instead of shared between registries at the same path, since Artifactory lets a deploy replace the zip of a private module. A zip cached by an earlier version is fetched from the remote again after the upgrade, once for each registry that serves it.

Fixed

  • Fixed NuGet packages from Artifactory bypassing the cache and the firewall. Links to the remote’s host in NuGet metadata are now rewritten to the base URL, and Artifactory’s package download URL is recognised as a package.
  • Fixed --defaults panicking instead of printing the default configuration.
  • A HEAD for a package now carries a Content-Length. It had none when the remote compressed the package on request.
  • Fixed pip failing with THESE PACKAGES DO NOT MATCH THE HASHES after a PyPI file was uploaded again under the same name. Relative file links in an HTML simple index now carry the file’s sha256 in a vs-sha256-<hex> path segment, and the file is cached under it. Lockfiles that record file URLs, such as uv.lock, will contain the segment.
  • Fixed Orca refusing to start on some valid Varnish Enterprise licenses, or enabling none of their licensed features.
  • Fixed the Virtual Registry failing to start on a valid license without an expiration date.
  • OTel spans for Varnish requests now carry a status. A transaction that failed, either with a VSL error or with a 5xx response, is marked Error rather than left Unset with the failure visible only in the span attributes. Errors reported by varnishlog-json also populate error.type and error.message again instead of being dropped.
  • Fixed a store above a terabyte losing up to 1023G of its size. A size that is not a whole number of terabytes was rounded down to one, so a store of 19865G was created as 19T. Such a size is now given in gigabytes.
  • Fixed a size or book_size that validation accepts being rejected when the storage is set up. 20TB, 1.5T and 1 GB now work, rather than failing with invalid size format as Varnish starts.
  • Fixed a failed upload being retried against the remotes, which left a second, abandoned upload at the remote and reported the retry’s error to the client instead of the one that actually stopped the upload.
  • Fixed mkfs.mse4 failing with No space left on device on stores of 45G and above. The space held back from size for filesystem metadata was a fixed 1G, but that metadata grows with the volume. It is now 3% of size, with 1G as the floor. Existing stores are resized on upgrade, which drops the objects at the tail of each store.
  • Fixed GitHub API calls from the GitHub CLI (gh) never being cached. Its GitHub CLI User-Agent matched the Git client rule, so its REST and GraphQL requests were parsed as Git requests and failed. Only a git/ User-Agent now classifies a request as Git.
  • Fixed GraphQL on GitHub Enterprise Server never being cached. GHES serves it at /api/graphql, which was not recognized as a GitHub endpoint.
  • Fixed a Cargo registry in JFrog Artifactory never being cached. Artifactory serves the sparse index under /artifactory/api/cargo/<repo>/index/, which was not recognized, so config.json and the index were passed through and cargo downloaded each crate straight from Artifactory.
  • Fixed cargo failing with failed to verify the checksum after a crate was uploaded again under the same version. The download URL in config.json now carries the crate’s sha256 from the index in a vs-sha256-<hex> path segment, and the crate is cached under it. A config.json or crate cached by an earlier version is fetched from the remote again after the upgrade.
  • Fixed Orca serving the old build of a non-unique Maven SNAPSHOT, such as demo-1.0-SNAPSHOT.jar, for the whole package TTL after a deploy replaced it. A file in a SNAPSHOT version that is named -SNAPSHOT rather than after a build timestamp now takes the manifest TTL, like the .pom of the same deploy, so it is revalidated against the remote on every request unless manifest_ttl is set.

®Varnish Software, Wallingatan 12, 111 60 Stockholm, Organization nr. 556805-6203