Terms and policies

Learn more about Chainguard policies and our legal documents.

CHAINGUARD CONTAINERS JUMPSTART- PUBLIC SECTOR

Summary of Chainguard Jumpstart - Public Sector

Last Update: August 14, 2026

This Chainguard Jumpstart - Public Sector brief (the “Jumpstart Brief”) describes certain initial onboarding services for the public sector (“Chainguard Jumpstart”) made available by Chainguard, Inc. (“Chainguard”) for purchase by customers pursuant to an Order entered into by and between Chainguard and the customer identified on such Order (“Customer”), governed by the separate and binding agreement in effect between the parties for the provision of Chainguard’s products and services to Customer, or if no such agreement is in effect, Chainguard’s online Master Services and License Agreement (as applicable, the “Agreement”). Capitalized terms used, but not defined in this Jumpstart Brief have the meanings ascribed in the Agreement. 

If selected by Customer, services identified as Chainguard Jumpstart - Public Sector or Jumpstart- Public Sector  will be indicated on Customer’s Order and in such case, (i) the activities included therein are as set forth below, and (ii) all such activities and services expire and will be null and void upon expiration of the Jumpstart Term (as defined below).

Chainguard Jumpstart Objective and Overview

Chainguard Jumpstart is a structured engagement designed to accelerate customer-adoption of Chainguard’s Products known as Chainguard Containers. Through a combination of guided workshops, technical deep-dives, and ongoing office hours, Chainguard’s solutions architect team will advise and support Customer in connection with its initial migration of a limited number of Chainguard Containers (as further described below)  into Customer’s  production environment.

  1. Scope of Services

During the Jumpstart Term, Chainguard will perform the activities set forth in this Jumpstart Brief to assist Customer in its deployment of two  (2) Chainguard Containers selected by Customer and designated as an “application” image,  and one (1) Chainguard Container selected by Customer and designated as a “base” image,  in each case, pursuant to the terms of the applicable Order, into Customer’s production environment (“Jumpstart Scope”). If Customer has not purchased a base image among the Chainguard Containers purchased under the applicable Order, the Jumpstart Scope shall  be deemed to include Chainguard Jumpstart service activities for a third (3rd) image selected by Customer and designated as an “application image” pursuant to the terms of such Order. Likewise, if Customer has  not purchased either one (1) or two (2) application images under the applicable Order, the Jumpstart Scope shall  be deemed to include one (1) additional hour of Office Hours (as defined below) per month, for each application image not so purchased. Each of the aforementioned Jumpstart Scope adjustments ensures that Customer is able to continue receiving equivalent value for Chainguard Jumpstart through extended access to such Chainguard Jumpstart services hereunder. All Chainguard Containers that are in-scope for Chainguard Jumpstart and any eligible adjustments to the Jumpstart Scope hereunder, must be identified and agreed upon by the parties at the start of the applicable Order engagement (i.e., upon the Order Effective Date (as defined in the Order)). Once identified, in-scope images cannot be changed or substituted during the given Jumpstart Term. All services provided under this Jumpstart Brief will be delivered exclusively by U.S. citizens.

In the event Customer seeks assistance or requests Chainguard Jumpstart to include services extraneous to the Jumpstart Scope (including as may be duly adjusted in accordance with the above), Customer will be required to purchase additional services for such images, subject to Chainguard’s current offerings and as may be set forth in the applicable Order Form. 

Jumpstart Activity

Description

Initial Registry Setup

Create, configure and enable access to Customer’s private Chainguard image registry instance.

Kick-off Call

Conduct an initial call (“Kick-off Call”) designed to align the parties on Chainguard Jumpstart goals (via the Mutual Action Plan (as defined below)); introduce team members; and review the key value drivers for the engagement.

Customer Environment Deep Dive

In depth session conducted between Chainguard solutions architect and Customer teams to understand Customer container environments and operational requirements .

Chainguard 101 Workshop

Foundational overview of Chainguard Containers covering essential topics, including the differences between dev and distroless image variants, container migration strategies, best practices for building and debugging minimal images, and security fundamentals unique to Chainguard’s approach. 

SSO and IAM Setup

Guide Customer through integration of organization’s identity provider with Chainguard. The session covers establishing Single Sign-On (SSO) for both the Chainguard console and CLI, configuring granular IAM roles and role-bindings for access control, and setting up secure Docker pull tokens for automated systems and CI pipelines.

Image Mirroring / Pull Through

Provide Customer with practical strategies for getting Chainguard Container images into internal environments by covering two core approaches: configuring pull-through proxies for on-demand image caching and setting up automated or event-driven full image mirroring to internal registries. 

Consuming Chainguard Images

Guide Customer on aligning Chainguard’s rapid update cadence with release cycles. Includes primer on Chainguard’s versioning and lifecycles approach, use of “epoch” tags for patched releases, and the six-month End-of-Life (EOL) Grace Period which extends updates for eligible images past official upstream support.

Custom Assembly Overview

Advise Customer how to tailor Chainguard Container images by adding approved packages without the need for complex manual builds or apk add steps. 

Chainguard Image Provenance

Advise Customer how to  validate the integrity and transparency of Chainguard Container images. Includes  how to verify the provenance and signatures of such images during ingest using tools like Sigstore and Cosign, as well as how to retrieve and inspect Software Bills of Materials (SBOMs) associated with such images.

Application Images Best Practices

Guide Customer through adopting Chainguard application images by reviewing migration best practices, highlighting minimal differences from legacy or branded images, and focusing on practical steps for updating deployment configurations and migrating to iamguarded Helm charts. Additionally,  demonstrations using tools to review image specs and providing troubleshooting advice. 

Base Images Best Practices

Advise Customer on base image best practices, differences from traditional base images, how to select the right Chainguard image for a given workload. Additionally, review comprehensive migration resources including playbooks for languages like Node.js, Python, Java, Go, and PHP

After the above foundational Chainguard Jumpstart activities are complete, Chainguard’s solutions architect will provide Customer additional support for up to four   (4) business hours per month of open office hours (“Office Hours”) across two pre-scheduled sessions  until the engagement is complete (i.e., conclusion of the Jumpstart Term). Office Hours can be used for the following type of example activities:

  • Additional Migration Support

    • Troubleshooting Chainguard Container migration issues 

    • Reviewing Dockerfiles, Helm charts, or deployment manifests for Chainguard best practices

    • Assisting with Custom Assembly requests

  • Additional Enablement

    • FIPs Overview

    • Global image modifications

    • Private APK repo

  • Customer-Specific Scenarios

    • Evaluating migration strategies for in-scope application or base images

    • Advising on advanced use cases (multi-arch images, private APK repos, custom tagging, etc.

  • Open Q&A

    • Answering questions about Chainguard Containers, best practices, or related security/operational topics

    • Providing guidance on where to find resources, documentation, or examples about Chainguard specific topics

2. Chainguard Jumpstart Timeline

In furtherance of Customer’s instance of Chainguard Jumpstart, a mutual action plan designed and jointly agreed by the parties (“Mutual Action Plan”) is required. During the Kickoff Call, Chainguard and Customer will jointly complete a Mutual Action Plan, which will include target dates for key activities. This plan establishes shared accountability and provides a clear path to achieving the engagement’s outcomes. By collaborating on the Mutual Action Plan from the outset, both teams align on priorities, timelines, and success metrics,  setting the foundation for a smooth and successful engagement. See Exhibit A, attached hereto, for a sample Mutual Action Plan that the parties may use for reference.

Chainguard Jumpstart services commence as of the Order Effective Date indicated on the applicable Order and conclude on the twelfth (12th) month anniversary of such Order Effective Date  (“Jumpstart Term”). 

If Customer needs to adjust any dates or activities contained in the Mutual Action Plan, Customer must notify Chainguard in writing as soon as reasonably possible, and any such changes shall be subject to the parties’ mutual written agreement. Notwithstanding the foregoing, Chainguard will make commercially reasonable efforts to accommodate any requested scheduling changes; provided that Customer understands and agrees that, significant delays or repeated changes may impact the overall timelines, scope, and attainability of the Chainguard Jumpstart services and objectives. 

Additionally, Customer is required to notify Chainguard in writing and without delay, once any Chainguard Jumpstart in-scope images have been deployed into Customer’s production environment. This notification enables Chainguard to document production deployment activities and provide appropriate ongoing support.

Additional Terms 

  1. Out-Of-Scope

Customer acknowledges and agrees that the scope of activities included in Chainguard Jumpstart is explicitly limited to this Jumpstart Brief, and that any other configurations, ongoing support, or consulting services, are outside the scope of Chainguard Jumpstart.  For the avoidance of doubt, Chainguard Jumpstart shall not include, involve or require any work to be performed by Chainguard staff on Customer’s virtual or physical environment. 

2. Project Team

No later than five (5) business days following the applicable Order Effective Date, Chainguard will staff team members having the skills and experience needed in furtherance of the activities comprising Chainguard Jumpstart. The resources assigned shall be experienced in deploying such activities, but for clarity are not dedicated full-time to Customer, and Chainguard reserves the right to replace, remove or add resources as it deems reasonably necessary. Should this occur, Chainguard will work to minimize any potential inconvenience to Customer.

3. Customer Responsibilities & Assumptions

Successful deployment of Chainguard Jumpstart is contingent on certain Customer responsibilities and assumptions set forth below. Notwithstanding anything to the contrary, Customer acknowledges and agrees that:

  • Any materials shared by Chainguard that Chainguard makes available to similarly situated customers (by way of example only, training materials, Help Center articles, etc.) are for illustrative purposes only, and Customer is solely responsible for the use, performance, maintenance, and risks associated with such materials.

  • All activities detailed in the Chainguard Jumpstart are provided remotely via videoconferencing or via Chainguard’s customer support portal and in English.

  • Customer understands that Chainguard’s ability to perform the activities described in this Jumpstart Brief depends upon Customer’s timely cooperation and collaborative participation with Chainguard.

  • Customer will ensure that the appropriate resources (including, without limitation, the necessary business stakeholders, subject matter experts, and/or IT personnel for functional requirements gathering and implementation) attend and participate in all meetings, working sessions, training, and testing.

  • Customer is responsible for any organizational change management activities needed to support deployment of the activities comprising Chainguard Jumpstart.

  • Customer is responsible for the performance of its employees and agents, including any contribution they make to Chainguard Jumpstart activities, and for the accuracy and completeness of all data, information, and materials provided by any of the foregoing to Chainguard.

  • The activities performed by Chainguard in furtherance of Chainguard Jumpstart may include advice and recommendations from Chainguard, but Customer understands that all decisions in connection with the implementation of such advice and recommendations will be the responsibility of, and made solely by, Customer.

  • A delay impacting Chainguard Jumpstart activities caused by any third-party vendor providing services or products to Customer will be considered Customer’s responsibility.

  • Customer will obtain, at its own cost and expense, all third-party software, licenses, warranties, required hardware, and maintenance.

  • Customer is responsible for overall project management, template rationalization, business process design, testing, end user training, change management, and any integration build not explicitly listed or defined in this Jumpstart Brief.

  • Customer shall not provide Chainguard any personal data (or similarly regulated data) as part of the activities provided under this Jumpstart Brief  other than the personal data that Chainguard collects in the ordinary course of business, as further detailed in its Privacy Notice (e.g., business contact information of Customer’s employees, users, etc.).

4. Chainguard Jumpstart Fee

The fee for Chainguard Jumpstart shall be as set forth in the Order Form. 

5. Order of Precedence

In the event of any conflict between the terms of this Jumpstart Brief, the Agreement, and the applicable Order, the following order of precedence shall govern: (i) first, this Jumpstart Brief (only with respect to the subject matter hereof); (ii) second, the Agreement; and (iii) third, the applicable Order (unless clearly specified as intended to modify the Agreement). Chainguard reserves the right to update this Jumpstart Brief  from time to time, but only to the extent that the update does not materially and adversely diminish the Customer’s rights as provided as of the date of the applicable Order.

Exhibit A

SAMPLE: Mutual Action Plan 

(To be filled out during Kick-off Call)

Mutual Action Plan, Segmented by Implementation Phase

Mutual Action Plan - Executive Summary

Phase

Success Criteria

Target Date

Mutual Action Plan Development

Build a MAP to execute against

Implementation of Kick-off

Walk through the CG Approach

Foundational Readiness

Workshops delivered and environments ready for migration

Application Image Migrations & Deployment

2 application images deployed to production

Base Image Migration  & Deployment

1 base image deployed to production

Implementation Close Out

MAP Review and alignment

Phase: Foundational Readiness

Activity

Success Criteria

Target Date

Customer Environment Deep Dive

Understanding of the  deployment environments and operational requirements

Environment Ready for Configuration

Target Deployment Environments Ready for configuration and Teams Aligned for CG image deploys

Chainguard 101 Workshop & SSO and IAM Implementation

Workshop Delivered

Image Mirroring / Pull Through

Workshop Delivered

Consuming Chainguard Images & 

Custom Assembly Overview

Workshop Delivered

Chainguard Image Provenance

Workshop Delivered

Environment Configuration Complete

Target Deployment Environments and the path to Production are ready for migrations

Identify Pilot Groups for App Image Migration

Groups identified and ready for migration

Identify Pilot Groups for Base Image Migrations

Groups identified and ready for migration

Phase: Application Images Migration & Deployment

Activity

Success Criteria

Target Date

App Images Kickoff

Confirm scope for two image migrations. 

Application Images Best Practices

Workshop Delivered

First Application Image Migration & Deployment

Application Image migrated and deployed to Production 

Second Application Image Migration & Deployment

Application Image migrated and deployed to Production 

Phase: Base Image Migration & Deployment

Activity

Success Criteria

Target Date

Base Images Kickoff Overview

Confirm the scope for one image migration. 

Base Images Best Practices

Workshop Delivered

Base  Image Migration & Deployment

Base Image migrated and deployed to Production

Phase: Implementation Closeout

Activity

Success Criteria

Target Date

Implementation Close Out

Confirm MAP requirements have been

completed

Handover to CSM & Technical Support