Cloud Security — hobby stack.
For each requirement below, pick the option that fits your build — recommended first, then free and cheaper alternatives — or skip what your project doesn't need. Tap the info icon next to any requirement to see why it matters.
Container Vulnerability Scanning
Keeps you secure and compliant with regulations. Required for enterprise customers and handling sensitive data.Pricing & free-tier limitsTrivy/Grype: Free OSS unlimited scans self-hosted. Snyk: Free 200 tests/mo, Team $25/dev/mo (~$100/mo for 4 devs), Business $50/dev/mo. Aqua Advance: $50k/yr (~$4166/mo) unlimited registry. Wiz: $30k/yr (~$2500/mo) 1000 containers.
Kubernetes Runtime Security / Threat Detection
Where your code actually runs and serves requests. Picking the right host affects speed, scaling, and how much ops work you do.Pricing & free-tier limitsFalco OSS: Free unlimited events. Tetragon OSS: Free. Sysdig Team: $30k/yr (~$2500/mo) 10 hosts. Sysdig Enterprise: $50k/yr (~$4166/mo) 100 hosts + $15/host/mo overage. Aqua KubeEnforcer: $30k/yr (~$2500/mo). CrowdStrike: $59.99/host/mo.
Secrets Management for Cloud Workloads
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsVault OSS: Free self-hosted. Vault HCP: $0.03/hr (~$21.90/mo per cluster) + $0.03/10k txns. AWS Secrets: $0.40/secret/mo + $0.05/10k API, free 30-day. Doppler Team: Free 5 users 100 secrets, Growth $20/user/mo. Akeyless: $30k/yr (~$2500/mo) unlimited.
Cloud KMS / Key Management Service
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsAWS KMS: Free 20k requests/mo then $1/key/mo + $0.03/10k requests. GCP KMS: $1/key-version/mo + $0.03/10k ops, free first 6 keys. Azure Key Vault: $1/key/mo Standard, $5/key/mo Premium HSM. OpenBao OSS: Free self-hosted unlimited.
Cloud Log Management / Cloud SIEM
Tells you when things break and why. You cannot fix what you cannot see — this is how you keep downtime short.Pricing & free-tier limitsPanther Community: Free self-hosted up to 500GB/mo. Panther SaaS: Free 500GB then $0.10/GB + $0.50/1k alerts. Elastic Cloud Security: $150/mo 8GB/day. Splunk Cloud: $150/GB/mo ingest $2700/mo min. Sentinel: $2.46/GB ingest + retention.
IaC / Misconfiguration Scanning (Terraform/CloudFormation)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsCheckov/tfsec/KICS: Free OSS unlimited. Snyk IaC: Free 200 tests/mo, Team $25/dev/mo, Business $50/dev/mo. Prisma Cloud IaC: $50k/yr (~$4166/mo) includes CSPM 1000 resources. Wiz IaC: Bundled $30k/yr (~$2500/mo).
CSPM - Cloud Security Posture Management
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsProwler/ScoutSuite: Free OSS unlimited accounts. Wiz: $30k/yr (~$2500/mo) 1000 workloads $0.50/workload/mo over. Prisma Cloud Enterprise: $50k/yr (~$4166/mo) 500 resources $0.15/resource/hr over. Orca: $40k/yr (~$3333/mo) 1000 assets.
Certificate Management for Cloud (PKI/ACME)
Encrypts traffic between your users and your servers. Without it browsers flag your site as insecure and you lose trust and search ranking.Pricing & free-tier limitscert-manager + LE: Free unlimited 90-day certs. AWS ACM: Free public certs for AWS resources, Private CA $400/mo per CA + $0.75/cert. Venafi: $25k/yr (~$2083/mo) 1000 certs. Sectigo: $15k/yr (~$1250/mo) unlimited DV.
Cloud Infrastructure Vulnerability Management
Keeps you secure and compliant with regulations. Required for enterprise customers and handling sensitive data.Pricing & free-tier limitsOpenVAS OSS: Free unlimited self-hosted. Tenable.io: Free 16 assets, Team $100/mo 50 assets, Business $300/mo 200 assets + $1.50/asset over. Qualys VMDR: $40k/yr (~$3333/mo) 1000 assets.
Kubernetes Admission Control & Policy Engine
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsGatekeeper/Kyverno: Free OSS. ARMO Platform: Free 2 clusters 10 nodes, Team $250/mo 5 clusters, Enterprise $800/mo 20 clusters. Styra DAS: $40k/yr (~$3333/mo) 10 clusters. Nirmata: $30k/yr (~$2500/mo) 10 clusters.
Container Registry Security & Scanning
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsHarbor+Trivy: Free OSS unlimited. GitHub Advanced Security: $49/user/mo includes secret+container scan. JFrog Xray: $35k/yr (~$2916/mo) 10k artifacts. ECR Enhanced: $0.09/scan per image + $0.01/GB-month + Inspector $0.01/scan first 30d then tiered.
How this hobby cloud security checklist works.
Each requirement below is something a hobby cloud security build typically needs. Pick one of the four researched options — recommended, free, cheaper or paid — add your own with "Other", or skip the requirement if your project doesn't need it. Nothing is mandatory; the plan on the right tracks what you've decided so nothing gets forgotten.
Your picks are saved in this browser automatically, so you can come back anytime. Options are researched per build level and refreshed as vendors change their plans — always verify details on the provider's page before committing.