Hi everyone, I'm in the middle of planning a pretty big migration for some of our legacy containerized apps to AWS. Security scanning is a huge part of the checklist, and I'm trying to nail down the tooling and, honestly, the budget.
My team has been looking at both Snyk Container and the native tools like AWS ECR image scanning. On the surface, ECR scanning seems like the obvious integrated choice, and the pricing is per scan, which feels straightforward. But I've heard from a few folks that Snyk can actually be cheaper at scale, especially if you're scanning a lot across dev, CI/CD, and runtime.
I'm nervous about missing hidden costs. Could anyone share their real-world experience comparing these costs? I'm thinking about things like:
- How does Snyk's per-developer pricing model compare when you have a large dev team but a moderate number of actual production containers?
- Does scanning in multiple places (local, CI, registry) with Snyk multiply costs, or is it covered under the same license?
- What about the operational cost of managing another tool versus using the cloud-native one that's just... there?
I really need some step-by-step guidance on how to think this through. A realistic timeline for evaluating both would also be super helpful. We're about 3 months out from the big migration push.
One step at a time