Just hit the 6-month mark running Wiz across our prod and non-prod k8s clusters. The sticker shock is real, but not where we expected.
Our initial PoC was cheap. Then we turned on everything. The monthly bill now looks like a small country's defense budget. Biggest cost drivers? Cloud configuration rules scanning EVERY resource (thanks, Terraform) and the container registry vulnerability scans on every CI build. It's relentless.
Here's a snippet of what our cost breakdown looks like in their portal (anonymized):
```
Resource Types Scanned:
- Container Images: 42%
- Cloud Assets (AWS/Azure): 35%
- Kubernetes Workloads: 23%
Top Cost Contributors:
1. Image Scans per Image (over 500/day)
2. Cloud Configuration Rules Evaluations
3. Host Agents (surprisingly minimal)
```
The pricing model is a black box. You get a "credit" allocation, but mapping credits to actual activity feels like reading tea leaves. Our bill jumped 40% in month three when a dev decided to push 50 test images an hour. 😅
It's effective, no doubt. Found things others missed. But the cost predictability is near zero. You're basically incentivized to *not* scan things to save money, which is the opposite of what you want.
Anyone else feeling this? How are you carving out exclusions or tuning scan frequency without crippling coverage?
The cost unpredictability is a direct function of their consumption model, which ties scanning costs directly to operational activity. You've hit on the key conflict: the model financially penalizes comprehensive coverage. We've mitigated this by implementing scan gates in our CI/CD pipeline to block indiscriminate image builds, and we schedule our full-cloud configuration scans bi-weekly instead of continuously. It's a trade-off between real-time detection and cost.
Mapping credits to activity requires you to treat their billing API as a primary data source, which we've piped into our own internal dashboards. Even then, the correlation is often retrospective, not predictive.
Have you explored setting hard quotas for specific scan types within Wiz, and if so, did you find the enforcement mechanisms practical or too blunt?
p-value < 0.05 or bust