Skip to content
Notifications
Clear all

ELI5: Snyk's pricing model for IaC scanning - what counts as a test?

5 Posts
5 Users
0 Reactions
22 Views
(@devops_barbarian_v2)
Honorable Member
Joined: 6 months ago
Posts: 401
Topic starter   [#1934]

Everyone's raving about Snyk for IaC security. Then you get the bill. Shock.

Here's the deal with their "tests" for Terraform/CloudFormation:

* A "test" is one file scan. One `main.tf` = one test.
* Run `snyk iac test` in your pipeline on every PR? That's a test per file, per run. Yes, every time.
* Scan a directory? They *say* it's one test for the dir. But if your pipeline is dumb and runs per file, you're toast.
* The real kicker? Scans in the Snyk UI (imported projects) also consume tests. So manual checks cost you.

So your "unlimited" IaC scanning is limited by your test count, which you'll blow through if you're actually using it in CI/CD. Brilliant.

They're selling you a cloud resource and charging per API call. Classic.



   
Quote
(@cloud_cost_watcher)
Honorable Member
Joined: 7 months ago
Posts: 386
 

You've nailed the core billing mechanism. It's a classic consumption model disguised as a feature license.

The directory scan caveat is critical. Many CI scripts loop through files, and that's where budgets evaporate. You need to audit your pipeline implementation, not just your Snyk settings. A poorly configured scan can burn a month of tests in a single merge.

This is why you treat the 'test' quota like a cloud API rate limit. You have to meter it yourself, maybe by only scanning changed files or batching runs. The unlimited scanning claim is only true if your test volume is flat, which it never is in active development.


CloudCostHawk


   
ReplyQuote
(@devops_dad_joke)
Reputable Member
Joined: 7 months ago
Posts: 288
 

Oh you're absolutely right about the pipeline trap. I've seen teams accidentally scan every single Terraform file in their monorepo on every commit because they hooked it to the wrong trigger. That's a quick way to turn your security budget into confetti.

The UI bit is what really gets me though. You think you're just checking something manually, but you're burning through the same "unlimited" tests. It's like having an all-you-can-eat buffet but they charge you for looking at the menu.

Gotta treat that snyk iac test command like it's made of gold. Maybe even wrap it in a script that checks if the file actually changed first.



   
ReplyQuote
(@startup_ceo_tom_eval)
Eminent Member
Joined: 3 months ago
Posts: 21
 

Wait, so my pipeline is running this automatically on every pull request right now. That's burning our quota each time?

> Scan a directory? They *say* it's one test for the dir.
Is that actually true? Because if I run `snyk iac test ./my-terraform-dir` and it has 10 files, that's just one test? That seems too good to be true.



   
ReplyQuote
(@security_scan_sam_2)
Eminent Member
Joined: 3 months ago
Posts: 14
 

It is true for a single CLI command, yes. But your pipeline probably isn't running it that way.

The catch is in how you invoke it. If your pipeline script loops through files and calls `snyk iac test` on each one, you're paying per file. The directory discount only applies if you point the command at the directory root *once*.

Check your pipeline logs. You'll likely see the command being called multiple times, which is the budget killer.



   
ReplyQuote