How to Configure Varnish Cache as a Caching Reverse Proxy with Vcl Rules and Cache Purging on Ubuntu Server

Learning how to configure Varnish Cache as a caching reverse proxy with VCL rules and cache purging on Ubuntu Server is one of the best ways to dramatically speed up your web applications. Varnish sits in front of your web server and stores copies of your pages in memory. When a visitor requests a page, Varnish serves it directly without touching your backend. This cuts response times from hundreds of milliseconds to just a few. The result is a faster site, lower server load, and happier users.

In this tutorial, you will install Varnish on Ubuntu Server, configure it as a reverse proxy in front of Apache or Nginx, write custom VCL rules to control caching behavior, and set up cache purging so your content stays fresh. By the end, you will have a production-ready Varnish setup that handles real traffic efficiently.

Prerequisites and Requirements for Configuring Varnish Cache

Before you start, make sure you have the following in place.

Required software and access:

  • Ubuntu Server 20.04 or 22.04 (fresh install recommended)
  • Root or sudo access to the server
  • Apache or Nginx installed and serving a working website
  • A basic understanding of Linux command-line usage
  • Port 80 and 6081 available on your server

Assumed knowledge level: You should be comfortable running commands in a terminal. You don’t need to be a Linux expert, but knowing how to edit files with nano or vim helps.

Estimated time: 30 to 45 minutes for a clean setup.

Your backend web server must listen on a non-standard port before you begin. Varnish will take over port 80. You will move Apache or Nginx to port 8080. This is a key part of the configuration, so plan for a brief moment of downtime during the switch.

How to Configure Varnish Cache as a Caching Reverse Proxy on Ubuntu

For a related walkthrough, see: How to Configure Prometheus Alertmanager with Alert Rules and Email Notifications on Ubuntu Server

Follow these steps carefully. Each one builds on the last.

Step 1: Update your system and install Varnish

Start by updating your package list. Then install Varnish from the official repository.

sudo apt update && sudo apt upgrade -y
sudo apt install varnish -y

Verify the installation worked correctly.

varnishd -V

You should see the version number printed in your terminal.

Step 2: Move your backend web server to port 8080

Varnish needs to own port 80. Move Apache or Nginx to port 8080 first.

For Apache, open the ports configuration file.

sudo nano /etc/apache2/ports.conf

Change Listen 80 to Listen 8080. Then update your virtual host file to use port 8080 as well. Restart Apache when done.

sudo systemctl restart apache2

For Nginx, edit your server block and change listen 80 to listen 8080. Then restart Nginx.

sudo systemctl restart nginx

Step 3: Configure Varnish to listen on port 80

Edit the Varnish systemd service file to change the listening port.

sudo nano /lib/systemd/system/varnish.service

Find the ExecStart line. Change -a :6081 to -a :80. Save the file. Reload the systemd daemon and restart Varnish.

sudo systemctl daemon-reload
sudo systemctl restart varnish

Step 4: Write your VCL configuration file

VCL (Varnish Configuration Language) controls how Varnish handles requests and caching. Open the default VCL file.

sudo nano /etc/varnish/default.vcl

Replace the contents with this configuration. It points Varnish at your backend and sets smart caching rules.

vcl 4.0;

backend default {
    .host = "127.0.0.1";
    .port = "8080";
}

sub vcl_recv {
    # Remove cookies for static files
    if (req.url ~ ".(css|js|png|jpg|gif|ico|woff|woff2)$") {
        unset req.http.Cookie;
    }

    # Allow cache purging from localhost only
    if (req.method == "PURGE") {
        if (client.ip != "127.0.0.1") {
            return (synth(405, "Not allowed"));
        }
        return (purge);
    }
}

sub vcl_backend_response {
    # Cache static assets for 1 day
    if (bereq.url ~ ".(css|js|png|jpg|gif|ico|woff|woff2)$") {
        set beresp.ttl = 1d;
        unset beresp.http.Set-Cookie;
    }

    # Cache HTML pages for 5 minutes
    if (beresp.http.content-type ~ "text/html") {
        set beresp.ttl = 5m;
    }
}

sub vcl_deliver {
    # Add a header to show cache status
    if (obj.hits > 0) {
        set resp.http.X-Cache = "HIT";
    } else {
        set resp.http.X-Cache = "MISS";
    }
}

Save the file and restart Varnish.

sudo systemctl restart varnish

Step 5: Test that Varnish is caching correctly

Use curl to check the cache status header you added.

curl -I http://your-server-ip/

Look for the X-Cache header in the response. The first request shows MISS. The second request shows HIT. That confirms Varnish is working.

Step 6: Set up cache purging

Cache purging lets you clear cached content on demand. This is critical for WordPress sites when you publish new posts. Send a PURGE request like this from the server itself.

curl -X PURGE http://127.0.0.1/your-page-url

For WordPress, install the Varnish HTTP Purge plugin. It automatically sends PURGE requests when you update posts or pages. This keeps your cached content in sync with your database without any manual effort.

Step 7: Enable Varnish to start on boot

Make sure Varnish starts automatically after a server reboot.

sudo systemctl enable varnish

Troubleshooting Common Varnish Cache Issues

Even a clean setup can hit a few snags. Here are the most common problems and how to fix them.

Varnish won’t start after editing the service file: Run sudo systemctl status varnish to read the error. A syntax mistake in your VCL file is the most common cause. Check your VCL with sudo varnishd -C -f /etc/varnish/default.vcl before restarting.

All requests show MISS and nothing is being cached: Your backend is probably sending Cache-Control: no-cache or Set-Cookie headers. Varnish won’t cache responses with those headers by default. Add unset beresp.http.Set-Cookie; in your vcl_backend_response block for the affected content types.

Port 80 is already in use: Another process is holding port 80. Find it with sudo ss -tlnp | grep :80 and stop it before starting Varnish.

PURGE requests return 405: Your PURGE request is coming from an IP that isn’t whitelisted. The VCL above only allows purges from 127.0.0.1. Adjust the IP check in vcl_recv if you need to purge from a different machine.

For deeper configuration options, check the official Varnish VCL documentation. It covers advanced topics like grace mode, health checks, and load balancing across multiple backends.

Conclusion: Next Steps After Configuring Varnish Cache

You now know how to configure Varnish Cache as a caching reverse proxy with VCL rules and cache purging on Ubuntu Server. Your site now serves cached pages at memory speed, handles traffic spikes more gracefully, and automatically clears stale content when needed. This setup works well for WordPress sites, static sites, and custom web applications alike.

From here, consider adding SSL termination in front of Varnish using Nginx or HAProxy. You can also explore Varnish grace mode, which serves stale content while your backend refreshes. Monitoring your cache hit rate with varnishstat is a great next step too. A high hit rate means your VCL rules are working well and your server load stays low.

Similar Posts