Skip to content
Artwork for Scalable Stories

Scalable Stories

GetPageSpeed

Welcome to Scalable Stories—the podcast where our hosts explore the nuances of web performance, security, and scalable infrastructures. Learn how to optimize your servers with tools like NGINX modules by GetPageSpeed, Varnish Cache, and leverage platforms like RHEL and Rocky Linux for robust deployments.

Each episode offers insights into enhancing server efficiency, speeding up websites, and fortifying against security threats. Whether you’re a developer, sysadmin, or tech enthusiast, join us to unlock the secrets of scalable and secure web architectures.

Play
  • 17 episodes
  • daily
  • Avg 9 min
  • English

Support the show

Goes straight to the publisher. podnod takes nothing.

  • Yesterday · 10 min

    Parallel ESI for Varnish 6.0 LTS: vmod-pesi Now Packaged

    Technical Briefing: Parallel ESI for Varnish 6.0 LTS via vmod-pesi The Problem: Sequential ESI Fragment Assembly Stock open-source Varnish processes ESI includes sequentially. A page containing two uncached fragments that each take 2 seconds to render th

  • Friday · 9 min

    NGINX QUIC reuseport: HTTP/3 Silently Breaks Without It

    Technical Briefing: NGINX HTTP/3 reuseport, quicbpf, and SELinux The Problem: HTTP/3 Silently Fails Without reuseport With workerprocesses greater than 1, a QUIC listener configured without reuseport shares a single UDP socket across all workers. Because

  • Tuesday · 10 min

    NGINX Certificate Compression: RFC 8879 for Every Browser

    Technical Briefing: RFC 8879 Certificate Compression in NGINX Problem Statement The TLS 1.3 certificate chain dominates the servers first flight and competes with the initial congestion window and QUICs 3x amplification limit. RFC 8879 certificate compre

  • Monday · 9 min

    Post-Quantum NGINX: OpenSSL 3.5 on Debian and Ubuntu

    Technical Briefing: Post-Quantum NGINX with OpenSSL 3.5 on Debian and Ubuntu Problem Statement NGINX packages on Debian and Ubuntu previously linked against each distributions system OpenSSL. On Ubuntu 20.04 (focal), that meant OpenSSL 1.1.1, which reach

  • Monday · 9 min

    OpenSSL 4.0 for NGINX: Why We Ship 3.5 LTS Instead

    Technical Briefing: OpenSSL 3.5 LTS vs. 4.0 for NGINX Packaging Problem Statement The decision between OpenSSL 3.5 and 4.0 for an NGINX fleet is a question of support windows and migration cost, not feature parity. OpenSSL 4.0 shipped in April 2026 but i

  • September 13 · 15 min

    zstd-nginx-module: Maintained, Tested and Packaged

    Technical Briefing: Maintained zstd Module for NGINX — Streaming Fixes, Packaging, and Audit Response Problem Statement The original tokers/zstd-nginx-module (by Alex Zhang) has not seen a release since 2023 and carries bugs in its streaming path that si

  • September 12 · 8 min

    NGINX RADIUS Authentication: No More htpasswd Files

    Technical Briefing: RADIUS Authentication for NGINX Problem Statement NGINX ships with no built-in RADIUS support. Organizations that centralize credentials in FreeRADIUS, Microsoft NPS, Cisco ISE, or Aruba ClearPass have had no way to make NGINX defer t

  • September 11 · 10 min

    ECH Without Padding Is a Lookup Table

    Technical Briefing: Closing the ECH Handshake-Size Side Channel in NGINX Problem Statement Encrypted Client Hello (ECH) encrypts the inner ClientHello—including the real SNI—and pads it. But the servers encrypted handshake flight (EncryptedExtensions, Ce

  • September 9 · 7 min

    NGINX TLS Vulnerability Fixes: BREACH, SWEET32, ROBOT

    Here is the technical briefing based on the provided source summary. --- Technical Briefing: Eliminating Legacy TLS Vulnerabilities and Achieving Post-Quantum Readiness in NGINX Problem Statement Four legacy TLS vulnerabilities—BREACH, Lucky13, SWEET32,

  • September 8 · 7 min

    NGINX proxy_pass: URI Rewriting, Variables, and DNS Gotchas

    NGINX proxypass: URI Rewriting, Variables, and DNS Gotchas — Technical Briefing Problem Statement The proxypass directive in NGINX has several non-obvious behaviors around URI rewriting, DNS resolution, and configuration placement. Misunderstanding these

  • September 7 · 7 min

    NGINX Directive Execution Order: The 11 Request Phases

    NGINX Directive Execution Order: The 11 Request Phases Problem Statement NGINX processes every request through a fixed pipeline of eleven phases. A directive does not run where it is written in the configuration file—it runs when its phase comes up in th

  • August 23 · 7 min

    NGINX Early Hints: HTTP 103 Benchmarked on Enterprise Linux

    Technical Briefing: NGINX Early Hints (HTTP 103) on Enterprise Linux Problem Statement HTTP Early Hints (status code 103) allows a server to send preliminary response headers—such as Link headers for render-blocking resources—before the final response, e

  • August 6 · 4 min

    You’re renting your own kernel

    Technical Briefing on tenantd Problem Statement CloudLinux offers enhanced tenant isolation features for servers, but it requires a forked kernel and incurs a monthly licensing fee. Users must also rely on CloudLinuxs update schedule for kernel patches a

  • Jan 5, 2025 · 14 min

    NGINX, PHP-FPM, and File Permissions

    This podcast discusses **how to set up file permissions for websites running on NGINX and PHP-FPM**. It explains why it’s crucial to use separate user accounts for each website and for the web server. The episode delves into the **correct ownership

  • Dec 19, 2024 · 10 min

    NGINX Security Headers module

    In this episode of Scalable Stories, we take a deep dive into the [NGINX Security Headers module](https://www.getpagespeed.com/server-setup/nginx/nginx-security-headers-module) by GetPageSpeed. Learn how this powerful NGINX module simplifies the process

  • Sep 28, 2024 · 6 min

    NGINX Extras Deep Dive

    Looking for an ultimate web server setup? Let’s deep dive into NGINX Extras by GetPageSpeed

Showing 1–17 of 17 episodes