What is our primary use case?
We faced a problem whereby our databases were not being encrypted, and we wanted a solution that could help us. We had to search for a few options and we went with CloudQuery. CloudQuery gives us a central way of managing our cloud infrastructure. We use it to collect information from our cloud accounts and query that information to identify our security issues, compliance, and configuration issues. For example, we normally use it to check whether production databases are encrypted. That was the reason why we purchased it. If there is any storage issue which is publicly accessible, as someone working in the banking environment, our information is too sensitive. If we don't encrypt it, then we are going to face issues. Because we deal with sensitive customer financial information, we have to use it to give us an option to have DevSecOps and governance over our cloud infrastructure.
What is most valuable?
The feature which is called Cloud Asset Inventory is what I like most about CloudQuery, and I use it daily. It gives us that central view of all our cloud resources, even across all different accounts we have and also the environments we have. It gives us that option whereby we know exactly what infrastructure we have. Sometimes we may be having a lot of cloud accounts, a lot of environments, and we're not sure that some exist. CloudQuery gives us that way to see cloud environments we have.
The SQL-based querying is another feature I use as a software engineer. Its role allows us to ask specific questions about our environment so it can give us feedback about it. If we query a database, it can give us an answer if our database is encrypted or if it is not encrypted, if it is publicly accessible or if it is not publicly accessible.
From the compliance perspective, I saw that we can define rules and also the identity resources, so we don't have to manually trace them every day. We just set them and we're all good to go. CloudQuery SQL compatibility database feature helps us to analyze information about our cloud infrastructure. The resources can be from a central location, and it helps us to analyze that information. In the banking environment where I work, we mainly use it to answer questions about production databases which are not encrypted and storage resources which are publicly accessible or not, and also the resources that are missing required ownership tags.
CloudQuery itself gives metrics and provides insights about the cloud environment. It can give us the number and type of resources we have, identity security and compliance issues we have in the cloud environment, and it can also track the changes across the infrastructure.
CloudQuery is customizable, and it is valuable when we're defining the rules and compliance. The solution can adapt queries and adapt to policies we set and also the monitoring rules. For example, in the banking environment, we can customize it to correspond to the policies we have. We can create custom SQL queries and policies for requirements like encryption, access control, resource tagging, and internal security standards. We can customize how we monitor and how we report the infrastructure issues.
What needs improvement?
I find CloudQuery more complicated to use, especially when starting to use it, because it uses the documentation it has, but it is not well documented to the fullest. It also lacks video tutorials that can help us onboard for the first time. Additionally, CloudQuery should be made easier for non-SQL users. It is very hard for someone who doesn't have knowledge about CloudQuery and SQL to use it. I would like to see more ready-made compliance policies, especially for our financial regulation, because we spend a lot of time creating these custom policies.
For how long have I used the solution?
We started using CloudQuery two years ago.
What do I think about the stability of the solution?
For stability, I give CloudQuery a 10 out of 10. It has been very stable because it continuously collects our data and organizes the cloud infrastructure without us having to manually check every environment. It hasn't experienced any downtime in two years.
What do I think about the scalability of the solution?
I rate the scalability of CloudQuery as almost a 10. Every month, at the end of every quarter, we add more applications, more cloud resources, and the accounts increase. CloudQuery has been stable because it continuously collects all the infrastructure data. We do not have to rely on manual checks for each environment. CloudQuery has been scalable because we have added more cloud resources and applications, but we haven't seen it crashing or having downtime because of scaling.
How are customer service and support?
I have interacted with technical support a few times since we started using CloudQuery. I mostly interacted with them when we were setting up. CloudQuery has some documentation addressing basic issues we can encounter. The few times we have escalated the issues to customer support, it has been generally positive. When we have questions about configuration, integration, or want to troubleshoot, the support team provides us technical guidance and helps us resolve the issues very fast. I would rate it a 9 out of 10. The support portal is not good enough, which is why I've deducted one.
Which solution did I use previously and why did I switch?
My experience comparing CloudQuery with other solutions or other vendors is that it is good. Initially, we were using AWS Config to monitor our cloud resources. However, as our environment grew, we needed better and central visibility and more flexible querying. CloudQuery was actually better in terms of cost and infrastructure.
How was the initial setup?
The deployment was not all that easy. It took us more than two weeks to deploy it across our infrastructure. The complex part came on connecting the cloud accounts and also configuring the permissions. Since we work in a regulated environment, it was not all that easy to integrate and also to set up the appropriate permissions, so it took time on that. With the help of customer support, we were able to navigate through.
What about the implementation team?
Around 15 to 20 users use CloudQuery.
What's my experience with pricing, setup cost, and licensing?
The pricing is not cheap in general. It is reasonable. When we consider the time it saved for us during the security and infrastructure team, it is reasonable, although it is a little bit expensive.
What other advice do I have?
I would recommend CloudQuery to any person, individual, organization, or company that needs better visibility and control over their cloud infrastructure. I find it especially useful for organizations with multiple cloud accounts or environments where manually tracking resources can become difficult. I give this review a rating of 8 out of 10.