Skip to main content

Plan the Control Path First

SafeSquid becomes a production control only when the proxy is sized, reachable, monitored, and able to preserve enforcement evidence. Poor planning causes dropped sessions, weak audit trails, certificate failures, and emergency routing changes during rollout. This page is the map. Each stage links to the page that carries the detail.

Work the stages in order

Decisions made out of order tend to be remade. Sizing before the architecture is chosen, or policy design before the licence tier is settled, produces rework that surfaces during rollout rather than during planning.

Choose the deployment scenario

1

Choose new appliance deployment

New VM or hardware appliance

Use the Appliance Builder when a dedicated disk and bootable ISO workflow are approved.
Confirm the appliance has approved CPU, RAM, disk, NIC, and rebuild ownership.If the disk cannot be dedicated, choose cloud or managed Linux instead.
2

Choose cloud or hybrid egress

Cloud or hybrid egress

Use cloud deployment when security groups, route tables, snapshots, and egress paths are owned.
Confirm security groups, routes, snapshots, and egress paths have named owners.If egress ownership is unclear, pause deployment until network ownership is assigned.
3

Choose managed Linux server

Existing managed Linux server

Use Linux install only when OS hardening, dependencies, monitoring, and rollback are already owned.
Confirm OS lifecycle and rollback are approved by the server owner.If dependency drift is likely, use Appliance Builder for a cleaner baseline.
4

Choose cluster or DR design

Cluster or DR design

Add HA or DR planning when uptime requirements need failover, configuration sync, and tested restore.
Confirm RTO, RPO, failover, restore, and configuration-sync requirements are documented.If HA ownership is missing, keep the first deployment single-node until DR controls are approved.

Capture planning evidence

Store these artifacts before installation begins:
  • Sizing worksheet or change record.
  • Network placement diagram.
  • Firewall and routing approval.
  • Log retention target.
  • Activation key storage reference.
  • Rollout and rollback plan.
  • DR or rebuild assumptions.
Detailed evidence lists live with each stage. This is the set that must exist before an installer runs.

Troubleshoot planning gaps

Next steps