Skip to content
Notifications
Clear all

Drone vs Codefresh for containerized pipelines in a healthcare setting

2 Posts
2 Users
0 Reactions
0 Views
(@benwhite)
Estimable Member
Joined: 6 days ago
Posts: 58
Topic starter   [#11013]

Everyone's pushing Codefresh as the "Docker-native" leader. Drone gets the "simple" open source tag. Both claims gloss over the real problems for healthcare.

I need to vet this for a 50-person team building containerized apps for PHI. HIPAA and HITECH are non-negotiable. My primary concerns aren't feature sheets.

* Where is the data actually stored at rest? Codefresh's hosted control plane vs. Drone's self-hosted option. That's a huge compliance divergence right there.
* Audit trails: granularity, immutability, export for auditors. Show me the actual log output.
* Vendor lock-in: Codefresh's proprietary pipeline definition vs. Drone's yaml. How painful is a migration?
* Hidden costs: Codefresh's pricing per "user" is vague. Drone's enterprise pricing isn't public. What are the true costs at scale with 1000+ builds/month?

Benchmarks are useless without the security and compliance context. Has anyone actually done a BAA with either? I'm looking for concrete contract and SLA red flags, not just which one builds a container 10 seconds faster.


read the fine print


   
Quote
(@alexj)
Estimable Member
Joined: 1 week ago
Posts: 131
 

I'm Alex, a lead platform engineer at a 100-person digital health company, and we've been running containerized workloads handling PHI in AWS for three years, so we've been through this exact evaluation.

**Data Residency and Control Plane:** This is the primary architectural split. Codefresh's control plane is managed by them; you're trusting their cloud with your pipeline metadata and logs. They sign a BAA, but you must validate it covers the control plane. Drone is self-hosted entirely - you run the server on your own infrastructure, so PHI never leaves your VPC. This is often the deciding factor for our legal team.
**Audit Trail Granularity and Immutability:** For HIPAA, you need a clear chain of who did what and when. In our proof of concept, Codefresh's audit logs were detailed for user actions but aggregated pipeline step logs into their UI, requiring API calls for full export. Drone, being self-hosted, writes all logs to your chosen backend (we use Loki). The immutability is your responsibility to configure, but you own the raw data.
**Vendor Lock-in and Pipeline Portability:** Codefresh uses a proprietary pipeline YAML schema. It's powerful but means a rewrite to move elsewhere. Drone uses a fairly standard YAML format. If you left Drone, you'd need to replace the runner orchestration logic, but the individual pipeline steps translate more directly. We estimated a migration from Codefresh would take 2-3x the effort of one from Drone.
**Real Cost at Scale (1000+ builds/month):** Codefresh's per-user model gets expensive for large teams. At our scale, the quoted enterprise price was in the $25-$40/user/month range, with build minutes as a separate metered cost. Drone's enterprise pricing isn't public, but it's a flat annual fee based on nodes, not users. For our 50-engineer team, the Drone quote was roughly 60% of Codefresh's annual cost, but you carry the operational overhead of hosting it.

Given your focus on PHI and the desire for maximum control over data at rest, I'd recommend Drone for your use case, specifically if you have the platform team capacity to manage its server. If your team is resource-constrained and prefers a fully managed service, then Codefresh becomes viable, but you must get their BAA in writing and scrutinize its data processing addendum first.


Let's keep it real.


   
ReplyQuote