Feature Parity with Sonatype Cloud

Feature Parity with Sonatype Cloud

This page provides an overview of major differences between Sonatype Cloud and the self-hosted versions of Sonatype solutions.

Sonatype Nexus Repository

Feature Self-Hosted Sonatype Cloud
Hosting Model Customer Managed
(On-premise, AWS, Azure, GCP, etc.)
Sonatype Managed
(SaaS, Single-tenant isolation option)
Maintenance & Upgrades Manual
Customer schedules upgrades, OS patches, and Java updates.
Automated
Zero-downtime updates and patching managed by Sonatype.
High Availability (HA) Configurable
Requires manual clustering setup and load balancer configuration.
Built-in
Automatic failover and multi-zone redundancy included by default.
Backups Manual/Scripted
Customer manages database and blob store backup strategies.
Automated
Managed by Sonatype with disaster recovery inclusion.
Format Support Extensive (20+)
Includes Maven, Docker, npm, PyPI, NuGet, Yum, APT, Go, Helm, etc. See Formats.
All the Same Formats as Self-Hosted
Plus, Sonatype Nexus Repository Cloud deployments are the first to get access to new formats.
Storage Limits Hardware Dependent
Limited by the provisioned disk/blob store size.
Elastic / Unlimited
Scales automatically with usage (consumption-based).
Cleanup Policies Available
Fully configurable retention and cleanup rules.
Available
Standard cleanup policies supported to manage storage costs.
User Authentication Flexible
Local users, LDAP, Active Directory, SAML/SSO, User Token.
Centralized SSO
SSO via Auth0-supported identity provider connectors (more comprehensive than self-hosted); no direct LDAP or local user management.
Realms Configurable
Users can activate, deactivate, and prioritize security realms from Settings > Security.
Sonatype Managed
Realms are pre-configured by Sonatype; realm configuration is not accessible in Cloud.
Repository Firewall Integration Available
Requires separate installation/license of IQ Server.
Built-in / Integrated
Can be enabled natively within the SaaS platform (if licensed).
Anonymous Access Configurable
Can allow unauthenticated read access.
Not Available
All access typically requires authentication for security.
Email Notifications Available
Fully configurable SMTP server settings for system-generated messages.
Not Available
The Email Server UI and REST API are not accessible in Cloud.

Sonatype Lifecycle, Sonatype Repository Firewall, Sonatype SBOM Manager

Feature Self-Hosted Sonatype Cloud
Deployment & Management Customer Managed
Initialized and deployed by the customer; system resources managed by the customer.
Sonatype Managed
Initialized, deployed, and system resources fully managed by Sonatype.
Database & Maintenance Manual
External database recommended; manual upgrades and backups managed by the customer.
Automated
Database, automatic backups, and upgrades are managed by Sonatype.
Server & Data Access Direct Access
Full customer access to server configuration and data on disk.
Managed Access
Access to configuration, data on disk, and inbound traffic is via Sonatype Support.
Logs Direct Access
Customer direct access to system logs, audit logs, policy evaluation logs.
Direct Access
Customer direct access via API to audit logs, policy evaluation logs.
Integrations & Tooling Available
Supports SCM onboarding/integrations, CI systems, Jira, CLI, REST APIs, and Webhooks.
Available
Supports SCM onboarding/integrations, CI systems, Jira, CLI, REST APIs, and Webhooks.
Email Notifications Configurable
Fully configurable SMTP server settings for IQ Server notifications (policy violations, continuous monitoring alerts, and other system-generated messages).
Available
Notifications and verification emails via Twilio SendGrid.