My main use case for JFrog Container Registry is that we have a central repository where we store all our Git repositories and code bases. If there are other external packages that we need to include in our projects, these are part of JFrog Container Registry.
Day-to-day and week-to-week, there are multiple use cases which vary for JFrog Container Registry. What I do is work on coding new things, new systems, and building new features. JFrog Container Registry helps me fetch specific packages and serves as a source of truth for various JAR files, Node Package Manager packages, and Docker images. It helps me reduce build times through local caching and provides its own vulnerability scanning features, aiding me with dependency resolution in general.
Adoption of JFrog Container Registry has been with both power and casual users. There are individuals who code extensively and individuals who conduct several proof of concepts on new packages and new images. Those people are our power users, and they have specific ingrained accesses and deeper knowledge of JFrog Container Registry, which is limited more or less to the technology department. Not every team or business unit uses it throughout the company, but most of them in the division that I am in do use it.
The best features of JFrog Container Registry include documentation of specific SSOs, custom layouts, and it helps set up charts for Kubernetes. It provides caching of external dependencies locally during deployments and has deeper access controls where some individuals or teams can be given certain accesses while others are not, which is a primary way we use it.
JFrog Container Registry has impacted my organization in a way that is hard to gauge at an organization level because I was not involved in cost analysis or benefit saving analysis. However, for our team, it has been very useful from a security standpoint, as we do not have to manually perform vulnerability scanning of every random open-source package. It provides a central way to install packages and Docker images from.
I cannot provide a cost reduction or efficiency gain, but I can say there is a very large security vulnerability gain we have. We do not get phased out by random packages, malware, or hackware, and monetary losses are generally reduced by not using open-source packages that can create vulnerabilities or have hidden code such as remote code execution. JFrog Container Registry helps us prevent all of that.
JFrog Container Registry has changed how my team collaborates by providing a central repository where we pull in all our packages. Although it is hard to quantify the collaboration impact, it generally helps us collaborate across the organization.
Regarding features I wish it had, if I talk about the free tier provided in one of the smaller organizations that I worked in, I think that was very limited. Unless you have a paid, pro, or enterprise tier, the features you get are somewhat limited and can have some hidden costs. Those are some of the things that could be made better.
I have been familiar with JFrog Container Registry for more than four years.
I do not know any friction points with JFrog Container Registry, as we have been using it very smoothly.
Before landing on JFrog Container Registry, we were using Nexus Sonatype at some stage, and we have also used AWS CodeArtifact before it was phased out.
The decision on JFrog Container Registry specifically over those alternatives was an organization-based decision. I think it is a straightforward tool that provides various different kinds of enterprise and pro-level plans, generally meant for large organizations, which is why it was adopted.
I am not aware of any features that came up during implementation that I am not actually using. I think it has something called X-ray related features, but I am not sure if I have used it or not. I would rate JFrog Container Registry highly on a scale of one to ten, and I have no additional advice to give to someone considering it with a similar workflow to mine. I feel that you have asked great questions, and nothing else needs to be covered. I have assigned this review a rating of nine out of ten.