Reference architecture

Four topologies, one binary, identical policy.

An install-path firewall between your developers, CI and clusters and the sixteen registries they pull from.

Dataflow

Client → proxy → verdict

Cache key: (registry, package, version, bundle-digest).

  1. 01 · Client

    npm, pip, docker, kubelet

    resolves the registry host to the proxy

  2. 02 · chainsaw-proxy

    • authenticate, identify workspace
    • 25 signals beyond CVE
    • Rego bundle
    • Trivy on OCI layers

    cache miss: upstream fetch, then evaluate · hit: verdict from memory

  3. Structured refusal

    signed audit row written

    Bytes streamed

    signed audit row written

K8s admission runs the same bundle against the pod spec and returns admit, warn or deny.

Component map · HA

What runs, and what breaks if it dies

One binary; topology decides where each piece sits.

ComponentOwnsIf it dies
chainsaw-proxyEvaluates the Rego bundle; forwards, serves from cache or refusesStateless; restart costs the cache warm-up
Billy, approval queueException approvals, written as signed rowsRead-only; pending requests never auto-approve
PostgresAudit rows, exceptions, policy versions, RBACReplica failover; block mode refuses rather than emit unrecorded decisions
Blob storeSBOMs, scan artefacts, bundle payloadsSBOM browsing degrades; enforcement continues
NATS policy-busOptional cache invalidation between replicasFalls back to a 15s cache TTL; verdicts unchanged
K8s admission webhookSame bundle against pod and image specsfailurePolicy Ignore in warn, Fail in block
Intel-bundle storeDigest-verified intel bundle, loaded from CHAINSAW_INTEL_BUNDLE_PATH at startFailed verification: previous bundle stays

Topologies

SaaS, VPC, on-premises, air-gapped

Same binary, Rego bundle and audit-row schema across all four.

  • SaaS, Chainsaw-hosted

    Dev / CI developer + CI runners Chainsaw SaaS chainsaw-proxy Postgres Blob store Intel bundle Upstream registries npm / PyPI / Docker
    Figure 1 · SaaS

    Chainsaw runs the control and data plane.

  • VPC-peered

    Customer VPC Dev / CI chainsaw-proxy Postgres Blob store Chainsaw control managed updates Upstream registries npm / PyPI / Docker
    Figure 2 · VPC-peered (dashed: out-of-band control plane)

    Data plane in your cloud; no inbound vendor connection.

  • On-prem, one proxy per BU

    Signed Rego bundle one bundle, distributed by your operators signature verified by each proxy at load BU-A chainsaw-proxy BU-B chainsaw-proxy BU-C chainsaw-proxy BU-D chainsaw-proxy solid: same signed bundle, loaded by each proxy
    Figure 3 · On-prem, one proxy per BU

    A deployment pattern you run: each proxy verifies the same signed Rego bundle, which you distribute.

  • Air-gapped

    Customer perimeter (no outbound) Dev / CI chainsaw-proxy Local cache Postgres Intel bundle (sideloaded) Signed bundle tarball manual transfer no outbound
    Figure 4 · Air-gapped

    Zero outbound: CHAINSAW_OFFLINE=1.

Identity flow

Okta / Entra → SCIM → Rego input

Policies predicate on the directory without re-querying the IdP at evaluation time.

  1. 01 · Identity provider

    Okta or Entra

  2. 02 · SCIM push

    Users and groups into Postgres

  3. 03 · Rego input

    input.actor.groups

Latency budget

Targets on the hot path

Targets, not measurements. Deployments publish observed p50 / p95 to your Prometheus.

PathTargetNote
Cache hit, policy unchangedp50 target < 8 msNo network egress on the hot path
Cache miss, upstream fetch + 25 signals + Rego evalp95 target < 450 msDominated by upstream registry latency
K8s admission decisionp99 target < 250 msLedger write is async

Air-gapped operational lifecycle

Sideload, verify, restart

A failed verify loads nothing; the previous bundle stays.

# manifest, hashes and digest binding (--strict adds Sigstore authenticity)
chainsaw bundle verify ./chainsaw-intel-bundle-2026-05-25.tar.gz
# point the proxy at it and restart; providers pick it up on the next refresh tick
CHAINSAW_INTEL_BUNDLE_PATH=./chainsaw-intel-bundle-2026-05-25.tar.gz
# which registries the loaded bundle can adjudicate
chainsaw doctor --offline

CHAINSAW_OFFLINE_FAIL_MODE is advisory: it refuses nothing on its own, and each policy condition applies its own outage fall-back.

Telemetry surfaces

Scrape, trace, ship to SIEM

OpenTelemetry (OTLP)traces and metrics
Prometheuslatency by verdict, cache hit ratio, bundle age
Golden-signal alerts5xx rate, p99, burn rate, bundle age, NATS lag
Audit-row schemastable JSON for Splunk, Sentinel and QRadar

Security baseline

Defaults you don't negotiate

Container identityuid 10001, non-root, read-only root filesystem, distroless
Verified binarypublished SHA-256 checksum; Sigstore signing and SLSA provenance on the roadmap, not yet live
Signed policy bundleSigstore-verified at load; disabling it needs an explicit, audited workspace flag
HTTP security headersCSP, X-Frame-Options, Referrer-Policy on every admin response

Scope boundary

What Chainsaw is not

It refuses on the install path and composes with the categories below.

Architect review

Walk an engineer through your topology

30 minutes with a Chainsaw engineer. Bring your network diagram; leave with a placement plan.