Security and observability are core parts of Varnish Enterprise. Starting with release 6.0.18r5, vmod-ratelimit, vmod-cwt, varnish-otel, vmod-kv and vmod-nodes are included in every Varnish Enterprise license. We are adding these capabilities to your standard toolkit to provide more value out of the box. No add-on or extra line item. If you run Varnish Enterprise, you now have access to them.
vmod-ratelimit: Cluster-wide rate limiting. While vmod-vsthrottle handles per-cache protection on a single node, vmod-ratelimit connects to an external NATS message broker to share state across your deployment, enabling PoP-level or global traffic control and abuse mitigation.
vmod-cwt: CBOR Web Token validation at the edge. Essential for streaming media workflows using Common AccessTokens (CAT), IoT, and binary-token authentication.
vmod-kv: State management for programmable runtimes. Operates as fast local storage or integrates with external distributed data stores like Valkey or Redis, unlocking complex edge compute logic, cluster-wide session state, and dynamic A/B allocation in VCL.
vmod-nodes: Dynamic routing at scale. Define backends via configuration files with live updates, allowing you to reconfigure routing topologies without requiring VCL reloads or restarts.
varnish-otel: OpenTelemetry export for Varnish Enterprise environments. Export logs, metrics, and traces straight into any observability backend like Grafana, Datadog, or Honeycomb.
Enhanced memory allocator: A new experimental payload allocator optimized for Massive Storage Engine to improve memory density and reclaim speeds. This feature is disabled by default but can be enabled via the yalloc_enable parameter.
We believe Varnish is uniquely positioned to enforce security policy at the point where data actually moves: at the edge, in the cache, under load. Our integrated security capabilities in Varnish CDN and Artifact Firewall results in Platform Engineering prove that customers want this from us.
However, for on-prem Enterprise customers, security and observability are not optional add-ons; they are baseline requirements. Bundling these directly into the core license package is the smartest way to strengthen your edge architecture.
Update to release 6.0.18r5 and these features are there, no license change required. Refer to the release notes for information on upgrading, including details of a breaking change: https://docs.varnish-software.com/releases/varnish-enterprise-6.0.18r5/
If you have questions about the upgrade path or want a walkthrough of any of these features, reach out to your account team or contact support.