Skip to main content

Feature Parity with Sonatype Cloud

This page provides an overview of major differences between Sonatype Cloud and the self-hosted versions of Sonatype solutions.

Sonatype Nexus Repository Sonatype Nexus Repository

Feature

Self-Hosted

Sonatype Cloud

Hosting Model

Customer Managed

(On-premise, AWS, Azure, GCP, etc.)

Sonatype Managed

(SaaS, Single-tenant isolation option)

Maintenance & Upgrades

Manual

Customer schedules upgrades, OS patches, and Java updates.

Automated

Zero-downtime updates and patching managed by Sonatype.

High Availability (HA)

Configurable

Requires manual clustering setup and load balancer configuration.

Built-in

Automatic failover and multi-zone redundancy included by default.

Backups

Manual/Scripted

Customer manages database and blob store backup strategies.

Automated

Managed by Sonatype with disaster recovery inclusion.

Format Support

Extensive (20+)

Includes Maven, Docker, npm, PyPI, NuGet, Yum, APT, Go, Helm, etc. See Formats.

All the Same Formats as Self-Hosted

Plus, Sonatype Nexus Repository Cloud deployments are the first to get access to new formats.

Storage Limits

Hardware Dependent

Limited by the provisioned disk/blob store size.

Elastic / Unlimited

Scales automatically with usage (consumption-based).

Cleanup Policies

Available

Fully configurable retention and cleanup rules.

Available

Standard cleanup policies supported to manage storage costs.

User Authentication

Flexible

Local users, LDAP, Active Directory, SAML/SSO, User Token.

Centralized SSO

SSO via Auth0-supported identity provider connectors (more comprehensive than self-hosted); no direct LDAP or local user management.

Realms

Configurable

Users can activate, deactivate, and prioritize security realms from Settings > Security.

Sonatype Managed

Realms are pre-configured by Sonatype; realm configuration is not accessible in Cloud.

Repository Firewall

Integration Available

Requires separate installation/license of IQ Server.

Built-in / Integrated

Can be enabled natively within the SaaS platform (if licensed).

Anonymous Access

Configurable

Can allow unauthenticated read access.

Not Available

All access typically requires authentication for security.

Email Notifications

Available

Fully configurable SMTP server settings for system-generated messages.

Not Available

The Email Server UI and REST API are not accessible in Cloud.

Lifecycle Sonatype Lifecycle, Sonatype Repository Firewall Sonatype Repository Firewall, SBOM Manager Sonatype SBOM Manager

Feature

Self-Hosted

Sonatype Cloud

Deployment & Management

Customer Managed

Initialized and deployed by the customer; system resources managed by the customer.

Sonatype Managed

Initialized, deployed, and system resources fully managed by Sonatype.

Database & Maintenance

Manual

External database recommended; manual upgrades and backups managed by the customer.

Automated

Database, automatic backups, and upgrades are managed by Sonatype.

Server & Data Access

Direct Access

Full customer access to server configuration and data on disk.

Managed Access

Access to configuration, data on disk, and inbound traffic is via Sonatype Support.

System Notice

Configurable

Administrators can configure a System Notice to display information to users.

Not Available

System Notice is not available in Sonatype Lifecycle SaaS.

Logs

Direct Access

Customer direct access to system logs, audit logs, policy evaluation logs.

Direct Access

Customer direct access via API to audit logs, policy evaluation logs.

Integrations & Tooling

Available

Supports SCM onboarding/integrations, CI systems, Jira, CLI, REST APIs, and Webhooks.

Available

Supports SCM onboarding/integrations, CI systems, Jira, CLI, REST APIs, and Webhooks.

Email Notifications

Configurable

Fully configurable SMTP server settings for IQ Server notifications (policy violations, continuous monitoring alerts, and other system-generated messages).

Sonatype Managed

Notifications and verification emails via Twilio SendGrid.