One product, three tiers.
One of them exists.
The action is open source and complete. The hosted control plane is designed and not yet built, so it has no price and nothing to buy. Here is the whole shape, early.
- Previews and deploys run in your own runners, with your own credentials. Sluiceway never holds a cloud credential, in any tier.
- The issue is a view, never the source of truth. Before every deploy the stack is previewed again, and nothing happens unless the fresh preview still matches what was ticked.
- No property value reaches the dashboard unless the repo lists the path. No telemetry from the action.
These are promises, not features. They are the reason a company can adopt Sluiceway without a security review of a third party, so they hold in the free action and in the hosted product alike.
The action. Complete for one repo, forever.
- One issue, one row per stack, tick to deploy
- Narrowed scans on push, full scans on a schedule, a rescan box
- A preview page per pending stack, with nested property paths
- Who may tick: write, maintain, admin, or a list of usernames
- Kill switch, rehearsal mode, ignored stacks, read-only mode
- Step outputs and a result file for your own Slack or metrics steps
The hosted control plane. A GitHub App on the org, talking only to GitHub. Deploys still run in your runners.
- One dashboard across every repo in the org
- History and audit, exportable for SOC 2 and ISO evidence
- Deploy protection rules GitHub itself enforces: a second approver, freezes, windows
- Teams in the tick rule, comment commands, Slack approve
- Lead time, deploy frequency, failure rate and drift, per team
- Not included: SSO and SCIM
Everything in Team, under your own terms.
- SSO and SCIM
- A self-hosted control plane, under a commercial licence
- Audit export to your SIEM, with retention you choose
- Support with an SLA
What you get, line by line
Where a cell says Planned, nothing is built yet. Nothing in the Team or Enterprise column can be bought today.
| What you get | Free | Team | Enterprise |
|---|---|---|---|
| Every tier keeps | |||
| Deploys run in your own runners | Yes | Yes | Yes |
| Sluiceway holds a cloud credential | Never | Never | Never |
| Fresh preview and hash check before every deploy | Yes | Yes | Yes |
| Property values on the dashboard | Only listed paths | Only listed paths | Only listed paths |
| The dashboard | |||
| One issue per repo, tick to deploy | Yes | Yes | Yes |
| A preview page per pending stack | Yes | Yes | Yes |
| One dashboard across every repo | No | Planned | Planned |
| History and audit, exportable | No | Planned | Planned |
| Metrics: lead time, frequency, failure rate, drift | No | Planned | Planned |
| Who may deploy | |||
| Who may tick | Roles or usernames | Planned: teams | Planned: teams |
| A required second approver | No | Planned | Planned |
| Deploy freezes and windows | No | Planned | Planned |
| Enforced by GitHub, not by convention | No | Planned | Planned |
| SSO and SCIM | No | No | Planned |
| Running it | |||
| Kill switch, rehearsal mode, read-only mode | Yes | Yes | Yes |
| A tick shows within a second | After workflow start-up | Planned: webhooks | Planned: webhooks |
| Self-hosted control plane | Not applicable | No | Planned |
| Support | Issues on GitHub | Planned | Planned: SLA |
There will be a free hosted tier
Installing the App on one org will be free up to a small number of active stacks, so that trying it costs nothing. That number is not set, and neither is the per-stack price.
How billing will work
Per active stack per month, not per seat. Most of the people in a repo never tick a box, and charging for them would price the thing by the wrong number. Small teams will pay through the GitHub Marketplace; Enterprise is invoiced.
No price is published because none is decided. When one is, it will appear here before it appears in a bill.
Sluiceway for teams
One issue per repo stops working somewhere around thirty repos. That is what the hosted control plane is for: one dashboard across the org, a history you can hand an auditor, and deploy rules GitHub itself enforces.
No hosted product is on sale today. The free action is complete, Apache-2.0, and stays that way.