Feature Parity with Sonatype Cloud
Feature Parity with Sonatype Cloud
This page provides an overview of major differences between Sonatype Cloud and the self-hosted versions of Sonatype solutions.
Sonatype Nexus Repository
| Feature | Self-Hosted | Sonatype Cloud |
|---|---|---|
| Hosting Model | Customer Managed (On-premise, AWS, Azure, GCP, etc.) |
Sonatype Managed (SaaS, Single-tenant isolation option) |
| Maintenance & Upgrades | Manual Customer schedules upgrades, OS patches, and Java updates. |
Automated Zero-downtime updates and patching managed by Sonatype. |
| High Availability (HA) | Configurable Requires manual clustering setup and load balancer configuration. |
Built-in Automatic failover and multi-zone redundancy included by default. |
| Backups | Manual/Scripted Customer manages database and blob store backup strategies. |
Automated Managed by Sonatype with disaster recovery inclusion. |
| Format Support | Extensive (20+) Includes Maven, Docker, npm, PyPI, NuGet, Yum, APT, Go, Helm, etc. See Formats. |
All the Same Formats as Self-Hosted Plus, Sonatype Nexus Repository Cloud deployments are the first to get access to new formats. |
| Storage Limits | Hardware Dependent Limited by the provisioned disk/blob store size. |
Elastic / Unlimited Scales automatically with usage (consumption-based). |
| Cleanup Policies | Available Fully configurable retention and cleanup rules. |
Available Standard cleanup policies supported to manage storage costs. |
| User Authentication | Flexible Local users, LDAP, Active Directory, SAML/SSO, User Token. |
Centralized SSO SSO via Auth0-supported identity provider connectors (more comprehensive than self-hosted); no direct LDAP or local user management. |
| Realms | Configurable Users can activate, deactivate, and prioritize security realms from Settings > Security. |
Sonatype Managed Realms are pre-configured by Sonatype; realm configuration is not accessible in Cloud. |
| Repository Firewall | Integration Available Requires separate installation/license of IQ Server. |
Built-in / Integrated Can be enabled natively within the SaaS platform (if licensed). |
| Anonymous Access | Configurable Can allow unauthenticated read access. |
Not Available All access typically requires authentication for security. |
| Email Notifications | Available Fully configurable SMTP server settings for system-generated messages. |
Not Available The Email Server UI and REST API are not accessible in Cloud. |
Sonatype Lifecycle, Sonatype Repository Firewall, Sonatype SBOM Manager
| Feature | Self-Hosted | Sonatype Cloud |
|---|---|---|
| Deployment & Management | Customer Managed Initialized and deployed by the customer; system resources managed by the customer. |
Sonatype Managed Initialized, deployed, and system resources fully managed by Sonatype. |
| Database & Maintenance | Manual External database recommended; manual upgrades and backups managed by the customer. |
Automated Database, automatic backups, and upgrades are managed by Sonatype. |
| Server & Data Access | Direct Access Full customer access to server configuration and data on disk. |
Managed Access Access to configuration, data on disk, and inbound traffic is via Sonatype Support. |
| Logs | Direct Access Customer direct access to system logs, audit logs, policy evaluation logs. |
Direct Access Customer direct access via API to audit logs, policy evaluation logs. |
| Integrations & Tooling | Available Supports SCM onboarding/integrations, CI systems, Jira, CLI, REST APIs, and Webhooks. |
Available Supports SCM onboarding/integrations, CI systems, Jira, CLI, REST APIs, and Webhooks. |
| Email Notifications | Configurable Fully configurable SMTP server settings for IQ Server notifications (policy violations, continuous monitoring alerts, and other system-generated messages). |
Available Notifications and verification emails via Twilio SendGrid. |