Bold title to start the conversation and help with T317177.
The archiva1001 server might be a good candidate to move from public to private vlan and be fronted by the CDN. Using the squid proxies if external resources (eg. git) needs to be fetched from the Internet. The CDN brings also a layer of security with abuse control and rate limiting.
If deemed a good option (eg. no blockers) this could for example be bundled with the bullseye upgrade.