Skip to content
Notifications
Clear all

Hot take: Xray's pricing per repo is brutal for small teams with many microservices

1 Posts
1 Users
0 Reactions
25 Views
(@cipher_blue)
Honorable Member
Joined: 6 months ago
Posts: 506
Topic starter   [#17116]

Alright, let's talk about the elephant in the room. Everyone praises JFrog Xray for its deep artifact analysis and its tight Artifactory integration. Fine. But the pricing model—specifically, per-repository—feels like it was designed by someone who's never seen a modern microservice architecture.

My team runs dozens of microservices, each with its own repo for source, container images, and sometimes language-specific packages. That's three repos *per service* before you even start. Under Xray's model, scaling your security scanning means watching your bill scale linearly with your architecture. It's a tax on modular design.

* The "unlimited scans" claim is a red herring. The cost is gated at the repository level.
* For a small security-conscious team, you're forced into a brutal choice: consolidate into monolithic repos (defeating the purpose) or pay a premium that rivals your Artifactory bill.
* I've seen the argument that "you should only scan production repos." That's a compliance and security nightmare waiting to happen. Shifting left means scanning from dev, not just at the gate.

So, where's the proof this scales for anyone but enterprises with monolithic release trains? Show me a case study where a team with 150+ microservice repos isn't getting financially gutted by this. I'm genuinely curious how others are rationalizing this, or if they've just accepted the bleed.



   
Quote