Enterprise rollout
Monitor, audit, enforce. Ship in four weeks.
Enforcement goes on per rule, per team, at your pace, so no developer loses a build.
The schedule
Four weeks, ≈ 40 platform-engineering hours
Every rule can stay in monitor as long as you want before you flip it.
-
Week 1
Deploy, point one pilot team
≈ 8 platform-eng hours
-
Week 2
Monitor mode, org-wide
≈ 8 platform-eng hours
-
Week 3
Enforce the low-risk rules
≈ 12 platform-eng hours
-
Week 4
Enforce the high-risk rules
≈ 12 platform-eng hours
Every step, week by week
Week 1 · Deploy, point one pilot team
- Stand up Chainsaw on your cloud or managed SaaS. Docker Compose for dev; Kubernetes or ECS for prod.
- Provision the control-plane database and (optional) Redis for webhook delivery at scale.
- Issue scoped client credentials to one pilot team's CI and laptops.
- Confirm installs flow through the proxy. No policy active yet; everything passes with an audit record.
Week 2 · Monitor mode, org-wide
- Roll out the baseline policy template (CVE floor, license allowlist, and every supply-chain attack signal your proxied ecosystems support) in monitor mode.
- Point the remaining teams at the proxy. Nothing breaks because monitor mode logs without blocking.
- Review the daily monitor report. Every legitimate install that trips a rule is a candidate for exception or rule tuning.
- Assign owners for exceptions: one reviewer per team, tracked in the dashboard with expiry dates.
Week 3 · Enforce the low-risk rules
- Flip known-malware, dependency-confusion, and hidden-Unicode rules to block. Each fires on coordinate-exact or byte-level evidence, so a refusal names the specific thing it found.
- Flip typosquat to block, and budget for exceptions. It infers from name similarity, so it refuses some real packages: measured on 24,206 real packages held outside the popularity corpus, 1.02% are refused. Each clears in one command, per coordinate, offline: an exception, not an outage.
- Flip the Docker malware feed and per-layer image enforcement to block for new image builds.
- Coordinate one short announcement: developers know what now fails and who owns the exception path.
- Shift monitor reports to weekly cadence once the signal is steady.
Week 4 · Enforce the high-risk rules
- Flip CVE floor, license allowlist, install-script exfiltration, publisher-changed, and publish-velocity rules to block or quarantine.
- Wire SIEM stream (Splunk HEC, Microsoft Sentinel, or IBM QRadar) if you're on Enterprise.
- Document your rollout and exception process. That doc feeds your SOC 2 / ISO evidence pack.
- Move to steady state: weekly review of new exceptions, quarterly policy review, rule additions as new attack patterns land.
Availability
What "HA" means in practice
Two proxy replicas behind a health check, and failover is automatic.
| Proxy tier | stateless; scales horizontally, no sticky sessions |
|---|---|
| Control plane | your RDS, Cloud SQL or self-managed database |
| Blob-store cache | local disk for dev, S3-compatible for prod |
| Degraded data source | fails open with an audit row; CHAINSAW_COVERAGE_MODE=closed refuses anything not fully evaluated against your mandatory sources |
| Upstream registry outage | served from cache |
| Observability | 50+ Prometheus counters, opt-in OpenTelemetry |
| RTO / RPO | follows your control-plane failover; Chainsaw recovers in seconds once the DB is reachable |
Migration
Front your existing registry
No dual-publish, no cut-over day.
| Artifactory / Nexus | Keep them. Public installs route through Chainsaw. |
|---|---|
| Cloudsmith / JFrog SaaS | Chainsaw's upstream points at Cloudsmith. |
| Verdaccio / internal npm mirror | Chainsaw replaces the public-upstream hop. .npmrc unchanged. |
| Snyk / SCA scanners | Run both. Chainsaw decides what enters; SCA reports on what's there. |
Hardening levels
Four levels, one rollout path
Most teams start at Level 1 and stop at Level 2. Each level is additive.
| Level | Adds | Needs |
|---|---|---|
| L1 · Monitor only | Audit every install, block nothing | proxy + dashboard |
| L2 · Admission webhook | Cluster-side enforcement on Kubernetes | K8s admission controller |
| L3 · Network egress allowlist | Block direct registry access at the network edge | network egress policy |
| L4 · MDM payloads | Lock the developer machine | MDM profile, checksum-verified CLI |
On Team and Enterprise, the /onboarding/hardening wizard generates the manifests, firewall snippets and MDM payloads.
Ready to brief your rollout?
Book a 30-minute working session
We walk through your environment and hand back a rollout plan you can share with your team.