Feature Parity with Sonatype Cloud
This page provides an overview of major differences between Sonatype Cloud and the self-hosted versions of Sonatype solutions.
Sonatype Nexus Repository
Feature | Self-Hosted | Sonatype Cloud |
|---|---|---|
Hosting Model | Customer Managed (On-premise, AWS, Azure, GCP, etc.) | Sonatype Managed (SaaS, Single-tenant isolation option) |
Maintenance & Upgrades | Manual Customer schedules upgrades, OS patches, and Java updates. | Automated Zero-downtime updates and patching managed by Sonatype. |
High Availability (HA) | Configurable Requires manual clustering setup and load balancer configuration. | Built-in Automatic failover and multi-zone redundancy included by default. |
Backups | Manual/Scripted Customer manages database and blob store backup strategies. | Automated Managed by Sonatype with disaster recovery inclusion. |
Format Support | Extensive (20+) Includes Maven, Docker, npm, PyPI, NuGet, Yum, APT, Go, Helm, etc. See Formats. | All the Same Formats as Self-Hosted Plus, Sonatype Nexus Repository Cloud deployments are the first to get access to new formats. |
Storage Limits | Hardware Dependent Limited by the provisioned disk/blob store size. | Elastic / Unlimited Scales automatically with usage (consumption-based). |
Cleanup Policies | Available Fully configurable retention and cleanup rules. | Available Standard cleanup policies supported to manage storage costs. |
User Authentication | Flexible Local users, LDAP, Active Directory, SAML/SSO, User Token. | Centralized SSO SSO via Auth0-supported identity provider connectors (more comprehensive than self-hosted); no direct LDAP or local user management. |
Realms | Configurable Users can activate, deactivate, and prioritize security realms from Settings > Security. | Sonatype Managed Realms are pre-configured by Sonatype; realm configuration is not accessible in Cloud. |
Repository Firewall | Integration Available Requires separate installation/license of IQ Server. | Built-in / Integrated Can be enabled natively within the SaaS platform (if licensed). |
Anonymous Access | Configurable Can allow unauthenticated read access. | Not Available All access typically requires authentication for security. |
Email Notifications | Available Fully configurable SMTP server settings for system-generated messages. | Not Available The Email Server UI and REST API are not accessible in Cloud. |
Sonatype Lifecycle,
Sonatype Repository Firewall,
Sonatype SBOM Manager
Feature | Self-Hosted | Sonatype Cloud |
|---|---|---|
Deployment & Management | Customer Managed Initialized and deployed by the customer; system resources managed by the customer. | Sonatype Managed Initialized, deployed, and system resources fully managed by Sonatype. |
Database & Maintenance | Manual External database recommended; manual upgrades and backups managed by the customer. | Automated Database, automatic backups, and upgrades are managed by Sonatype. |
Server & Data Access | Direct Access Full customer access to server configuration and data on disk. | Managed Access Access to configuration, data on disk, and inbound traffic is via Sonatype Support. |
System Notice | Configurable Administrators can configure a System Notice to display information to users. | Not Available System Notice is not available in Sonatype Lifecycle SaaS. |
Logs | Direct Access Customer direct access to system logs, audit logs, policy evaluation logs. | Direct Access Customer direct access via API to audit logs, policy evaluation logs. |
Integrations & Tooling | Available Supports SCM onboarding/integrations, CI systems, Jira, CLI, REST APIs, and Webhooks. | Available Supports SCM onboarding/integrations, CI systems, Jira, CLI, REST APIs, and Webhooks. |
Email Notifications | Configurable Fully configurable SMTP server settings for IQ Server notifications (policy violations, continuous monitoring alerts, and other system-generated messages). | Sonatype Managed Notifications and verification emails via Twilio SendGrid. |