Terraform Operations #6 Execution Platforms Compared: Plain CI, HCP Terraform, Atlantis, and Spacelift

4 min read

Look back at what we built from #1 through #4: PR plan comments, apply automation, concurrency control, scanning, cost display — all assembled by hand on top of GitHub Actions. There is a market segment that sells this assembly as a product: Terraform execution platforms. This part is a comparison of “what we built versus what you can buy,” and the conclusion up front is that for many teams the hand-built assembly is enough, and a platform is something you buy when a specific pain is real. What those pains are is the subject of this part.

The limits of hand-built (plain CI) #

The strengths of the GitHub Actions approach are clear: no extra cost, a tool you already know, everything under your own control. The weaknesses surface as the team grows.

  • Run history is a pile of logs: the answer to “what got applied to prod last week” is a search through Actions logs. As stacks multiply, there is no screen that shows the whole picture at a glance.
  • The permission model is coarse: fine-grained control like “this team can only apply this stack” has to be hand-assembled from GitHub permissions and IAM.
  • Policy depends on code review: rules like “production resources must be tagged” or “this region is forbidden” can only be enforced so far by scanner rules and reviewers’ eyes.
  • The assembly itself is a maintenance burden: the plan comment script, the concurrency setup, the scanner integration — all of it is code we have to fix.

Managed: HCP Terraform #

HashiCorp’s managed platform (better known by its old name, Terraform Cloud; the self-hosted edition is Terraform Enterprise). It gives you remote execution, state storage, PR integration, a run history UI, and RBAC out of the box, and its differentiator is policy as code with Sentinel. Rules like “instance types only from this list” or “no applies on Friday afternoon” can be enforced as policy code. Since it doubles as a state store, the S3 backend setup from Basics #9 becomes unnecessary altogether — another distinctive point. There is a free tier, so small teams can start at no cost, and the paid tiers bill by resource count. Exact prices and tier boundaries change often, so plan on checking the official page at adoption time; the evaluation lens should be “are policy, RBAC, and the history UI worth that price to us?”

Self-hosted OSS: Atlantis #

Atlantis is an open-source server that drives Terraform through PR comments. Comment atlantis plan or atlantis apply on a PR and the server runs it and replies with the result as a comment. It is essentially the finished form of the workflow we built in #1, delivered as an installable. It is free and your data never leaves your infrastructure; in exchange, the Atlantis server itself becomes a highly privileged piece of infrastructure you have to operate. It is especially favored by organizations that cannot hand credentials to an external SaaS.

Commercial specialist platforms: the Spacelift family #

Commercial platforms like Spacelift and env0 target the same territory as HCP Terraform, differentiating on multi-tool support (Terraform and OpenTofu, of course, but also Pulumi and Ansible), OPA-based policy, and flexible workflows. Think of them as the shortlist that organizations with dozens of stacks or more put next to HCP Terraform when requesting quotes.

Selection criteria #

SituationReasonable choice
A few stacks, small teamPlain CI (this series’ setup)
Organization that cannot hand credentials to an external partyAtlantis
Scale where policy enforcement, RBAC, and a history UI are neededCompare quotes: HCP Terraform or the Spacelift family
OpenTofu adoption or a multi-tool organizationThe Spacelift family

The deciding axis is ultimately the same as in #5: is the pain real? When the time spent digging through logs for run history, the risk of a permissions incident, and the frequency of policy violations slipping past review start to be felt, it is time to request platform quotes; before that, the workflow you assembled yourself is the cheapest and most transparent answer. You may have noticed OpenTofu appearing in the table — the historical background that made “which tool to execute” a choice in itself is what the next part covers.

Recap #

What we covered in this post:

  • Plain CI assembly has four limits: run history visualization, fine-grained permissions, policy enforcement, and maintaining the assembly itself
  • HCP Terraform is a managed platform offering remote execution, state storage, and Sentinel policies; pricing is by resource count, so check it at adoption time
  • Atlantis is a PR-comment-driven self-hosted OSS — the answer for organizations that cannot send credentials outside
  • The Spacelift family of commercial platforms differentiates on multi-tool support and OPA policies
  • The selection criterion is not the tool but whether the pain is real. Until you feel it, plain CI is the cheapest and most transparent

The next post (#7 OpenTofu and the License) is the final part of the track. It traces the BSL transition and the fork, the landscape after the IBM acquisition, and the criteria for choosing between Terraform and OpenTofu, wrapping up the series.

X