Docs

How to point your package managers and container runtimes at SlowShield, what changes for your builds, and how to check that nothing goes around it. Every page shows the settings for https://slowshield.example.com; your instance's Setup page (/ui/setup) shows the same settings with its own address filled in.

What SlowShield does

Setting it up

  1. Run SlowShield on one host your team and CI can reach: Docker Compose, rootless Podman or the Helm chart (Get started). Use a real host name with HTTPS; the examples here use slowshield.example.com.
  2. Point every tool at it. Four lines in a shell profile cover pip, uv, npm and go. Other tools need a setting each, on the pages above.
  3. Close the way around it. Block the public registries at the firewall for machines that should only use SlowShield, so a forgotten setting fails loudly instead of quietly going around it.

For your shell profile (bash on Linux; the Setup page also has bash on macOS, zsh and fish):

cat >> ~/.bashrc <<'EOF'
export PIP_INDEX_URL=https://slowshield.example.com/pypi/simple/
export UV_DEFAULT_INDEX=https://slowshield.example.com/pypi/simple/
export npm_config_registry=https://slowshield.example.com/npm/
export GOPROXY=https://slowshield.example.com/go
export PIP_UPLOADED_PRIOR_TO=P3D
export npm_config_min_release_age=3
EOF
source ~/.bashrc

Two layers

Most package managers can now refuse brand-new releases themselves. Turn that on as well, a little shorter than SlowShield: 7 days in SlowShield, 3 in the package manager. On a normal day only SlowShield holds anything back. When something gets past it, a laptop without the setup or a brand-new package SlowShield serves because no version is old enough yet, the package manager still waits. Each tool's section shows its setting and the version it needs.

What you see when something is held

More

For agents: this page as Markdown · llms.txt · the SlowShield skill