Skip to content

Arena

Infrastructure as Code arenaInfrastructure as Code

Tools for declaring, previewing, and applying cloud infrastructure as code, judged on plan/apply workflows, state management, module and provider ecosystems, policy-as-code, testing, licensing openness, and how safely an agent can author and apply changes headlessly.

54 user stories · 216 judged cells · updated 2026-09-16 · Evidence as of 2026-09-15

Buyer checklist →Procurement report →

Leaderboard — every product ranked by evidenceLeaderboard

Rank by

Best by user type — persona-weighted winnersBest by user type

Per persona, the product with the highest persona-weighted coverage over just that persona's stories — not the same ranking as the overall PA Score leaderboard above.

Best for platform-engineer

Pulumi logo

Pulumi

60/100

Runner-up: OpenTofu logo OpenTofu (51/100)

7 platform-engineer stories scored

Best for developer

Pulumi logo

Pulumi

60/100

Runner-up: OpenTofu logo OpenTofu (38/100)

10 developer stories scored

Best for devops-lead

OpenTofu logo

OpenTofu

60/100

Runner-up: Pulumi logo Pulumi (44/100)

4 devops-lead stories scored

Best for ai-native

Pulumi logo

Pulumi

41/100

Runner-up: OpenTofu logo OpenTofu (35/100)

33 ai-native stories scored

Story matrix — every product × every judged storyStory matrix

54/54 stories shown · legend

Agenticness — how well agents can access and operate the productAgenticness

Agent access

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
Agenticness — how well agents can access and operate the productPoint an agent at llms.txt or agent-oriented docsai-native
partialT
3/10
fullT
8/10
none
0/10
none
0/10
Agenticness — how well agents can access and operate the productRun the product headlessly / in CI for automationai-native
fullT
9/10
fullT
9/10
fullT
9/10
partialT
6/10
Agenticness — how well agents can access and operate the productPlug MCP servers into this product so it can use their toolsai-native
n/a
none
0/10
n/a
n/a
Agenticness — how well agents can access and operate the productConnect an agent via an official MCP serverai-native
fullT
8/10
fullT
9/10
n/a
none
0/10
Agenticness — how well agents can access and operate the productUse an official CLIai-native
fullT
8/10
fullT
9/10
fullT
9/10
partialT
6/10
Agenticness — how well agents can access and operate the productDrive the product through a documented public APIai-native
partialT
6/10
partialT
6/10
partialT
5/10
fullT
7/10
Agenticness — how well agents can access and operate the productIssue scoped/least-privilege API credentials for an agentai-native
none
0/10
none
0/10
n/a
partialC
4/10
Agenticness — how well agents can access and operate the productBuild against official SDKsai-native
partialC
4/10
fullT
9/10
none
0/10
none
0/10
Agenticness — how well agents can access and operate the productSubscribe to events via webhooksai-native
none
0/10
none
0/10
n/a
none
0/10

Agentic features

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
Agenticness — how well agents can access and operate the productGet AI-generated insights and suggestions from my data inside the productai-native
none
0/10
partialX
6/10
n/a
none
0/10
Agenticness — how well agents can access and operate the productSet up automations that run autonomously in the backgroundai-native
partialC
5/10
partialT
6/10
partialT
4/10
partialC
5/10
Agenticness — how well agents can access and operate the productDelegate tasks to a built-in AI assistant inside the productai-native
none
0/10
fullC
6/10
n/a
n/a
Agenticness — how well agents can access and operate the productOperate the product with natural-language commandsai-native
partialT
4/10
partialT
7/10
none
0/10
none
0/10

Api quality

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examplesai-native
none
0/10
none
0/10
none
0/10
none
0/10
Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent)ai-native
none
0/10
none
0/10
none
0/10
none
0/10
Agenticness — how well agents can access and operate the productTest against a sandbox environment without touching production dataai-native
partialC
6/10
partialT
7/10
partialT
5/10
partialT
4/10
Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policyai-native
none
0/10
none
0/10
none
0/10
none
0/10

Automation depth — how much of the product can run unattendedAutomation depth

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
Automation depth — how much of the product can run unattendedPerform bulk operations across many items at onceai-native
partialT
6/10
partialT
6/10
partialC
6/10
none
0/10
Automation depth — how much of the product can run unattendedDefine rules that trigger actions automatically on eventsai-native
none
0/10
none
0/10
none
0/10
partialC
6/10
Automation depth — how much of the product can run unattendedSchedule recurring jobs or workflowsai-native
none
0/10
none
0/10
n/a
n/a
Automation depth — how much of the product can run unattendedVersion, review, and roll back my automationsai-native
partialX
6/10
partialT
6/10
partialT
5/10
partialX
6/10

Import migration — stories about import migration in this arenaImport migration

Import

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
Import migration — stories about import migration in this arenaImport existing cloud resources under management and generate matching configuration codeplatform-engineer
disputedD
4/10
fullC
9/10
partialX
6/10
none
0/10

Migration

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
Import migration — stories about import migration in this arenaMigrate an existing Terraform-format codebase and its state into this toolplatform-engineer
n/a
partialC
6/10
fullT
7/10
none
0/10

Licensing governance — stories about licensing governance in this arenaLicensing governance

Licensing

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
Licensing governance — stories about licensing governance in this arenaRely on an open license and open governance so the tool cannot be relicensed out from under my companydevops-lead
disputedD
3/10
none
0/10
fullX
7/10
none
0/10

Stability

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
Licensing governance — stories about licensing governance in this arenaRely on documented compatibility promises and upgrade guides between releasesdeveloper
none
0/10
none
0/10
partialX
5/10
none
0/10

Openness — open source, data portability, and self-hosting storiesOpenness

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
Openness — open source, data portability, and self-hosting storiesDo everything through the API that I can do in the UIai-native
partialT
5/10
partialT
5/10
n/a
fullC
7/10
Openness — open source, data portability, and self-hosting storiesExport all of my data in open formats and leaveai-native
partialX
6/10
partialX
5/10
partialT
6/10
partialC
5/10
Openness — open source, data portability, and self-hosting storiesRead the product's source under an open licenseai-native
partialX
4/10
partialC
4/10
fullX
8/10
none
0/10
Openness — open source, data portability, and self-hosting storiesSelf-host the core productai-native
fullX
8/10
fullT
8/10
fullT
8/10
fullT
9/10

Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply

Agent plan parsing

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyGet machine-readable plan output (JSON) that an agent can parse to reason about a proposed changeai-native
fullC
9/10
fullT
9/10
fullT
9/10
none
0/10

Ai infra ops

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyHave an agent author an infrastructure change, run a plan headlessly, and present the diff for my approvalai-native
partialC
6/10
fullT
8/10
fullT
8/10
partialT
4/10

Automation api

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyDrive deployments programmatically from my own application code rather than only through the CLIdeveloper
none
0/10
fullX
9/10
none
0/10
partialT
5/10

Plan workflow

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyTear down an entire environment cleanly with a destroy operationdeveloper
none
0/10
fullT
9/10
fullT
9/10
none
0/10
Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyRun plan and apply non-interactively in CI using saved plan artifacts and approval flagsdevops-lead
fullC
9/10
partialT
6/10
fullT
9/10
none
0/10
Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPreview exactly what will change — creates, updates, and destroys — before applyingplatform-engineer
fullX
10/10
fullT
9/10
fullT
9/10
none
0/10
Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyTarget or exclude specific resources in a plan or applyplatform-engineer
none
0/10
none
0/10
fullT
8/10
none
0/10

Policy as code — stories about policy as code in this arenaPolicy as code

Ai infra ops

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
Policy as code — stories about policy as code in this arenaLet an agent plan and apply with least-privilege credentials and review gates so it cannot make unapproved changesai-native
partialC
7/10
partialT
5/10
partialT
4/10
partialX
4/10

Policy

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
Policy as code — stories about policy as code in this arenaEnforce policy-as-code checks that block non-compliant infrastructure changes before applydevops-lead
partialC
5/10
fullC
8/10
none
0/10
none
0/10

Privacy posture — data-handling and privacy storiesPrivacy posture

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
Privacy posture — data-handling and privacy storiesChoose where my data is stored (region/residency)ai-native
none
0/10
partialC
5/10
none
0/10
n/a
Privacy posture — data-handling and privacy storiesPrevent my data from being used to train AI modelsai-native
n/a
n/a
n/a
n/a
Privacy posture — data-handling and privacy storiesControl data retention and deletionai-native
none
0/10
partialC
3/10
n/a
n/a
Privacy posture — data-handling and privacy storiesOpt out of telemetry and usage trackingai-native
none
0/10
none
0/10
none
0/10
n/a

Providers modules — stories about providers modules in this arenaProviders modules

Ai authoring

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
Providers modules — stories about providers modules in this arenaGenerate infrastructure code from natural language using AI assistance built into the toolchainai-native
partialT
6/10
fullT
8/10
n/a
none
0/10

Languages

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
Providers modules — stories about providers modules in this arenaDefine infrastructure in a general-purpose programming language with types, loops, and IDE supportdeveloper
none
0/10
fullX
9/10
none
0/10
partialC
4/10

Modules

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
Providers modules — stories about providers modules in this arenaConsume and publish reusable modules or components from a public registrydeveloper
fullC
9/10
partialT
6/10
partialC
6/10
partialC
6/10

Providers

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
Providers modules — stories about providers modules in this arenaManage resources across all major clouds and SaaS providers through a broad provider ecosystemdeveloper
fullX
9/10
fullT
9/10
fullX
9/10
partialX
6/10

Secrets config — stories about secrets config in this arenaSecrets config

Config stacks

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
Secrets config — stories about secrets config in this arenaManage per-environment configuration (dev, staging, prod) as separate stacks or workspacesdeveloper
partialC
5/10
fullT
7/10
partialC
5/10
partialC
3/10

Secrets

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
Secrets config — stories about secrets config in this arenaPass secrets and sensitive configuration into deployments without exposing them in code or logsdeveloper
none
0/10
partialT
5/10
partialX
5/10
none
0/10

State management — stories about state management in this arenaState management

Drift

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
State management — stories about state management in this arenaDetect drift between my declared configuration and the actual cloud resourcesplatform-engineer
fullX
8/10
partialT
6/10
fullT
8/10
fullX
8/10

State backends

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
State management — stories about state management in this arenaStore state in a remote backend with locking so concurrent runs cannot corrupt itplatform-engineer
none
0/10
fullX
8/10
none
0/10
n/a
State management — stories about state management in this arenaEncrypt state at rest so credentials and sensitive values are not readable in plaintext state filesdevops-lead
none
0/10
fullT
7/10
fullX
9/10
none
0/10
State management — stories about state management in this arenaSafely inspect and modify state — moving, removing, or renaming resources — when refactoringplatform-engineer
fullC
7/10
partialC
5/10
partialC
3/10
none
0/10

Testing validation — stories about testing validation in this arenaTesting validation

Testing

StoryPersona
Terraform logoTerraform
Pulumi logoPulumi
OpenTofu logoOpenTofu
Crossplane logoCrossplane
Testing validation — stories about testing validation in this arenaWrite automated tests for my infrastructure code and run them without touching productiondeveloper
fullC
8/10
fullT
8/10
partialC
6/10
disputedD
5/10
Testing validation — stories about testing validation in this arenaValidate and auto-format my configuration before planningdeveloper
none
0/10
none
0/10
none
0/10
partialT
3/10
Verdict✓ fullclear evidence~ partialwith caveats! disputedevidence conflicts— noneno evidence foundn/aquestion doesn't apply to this kind of product
ProofT probedtested by usX communityusers back itC claimedvendor claim onlyD contradictedevidence disagrees⚿ auth-gatedprobe hit a live sign-in wall — verified reachable, untestable keylessly
quality 0–10 · PA Score /100 · A–D = evidence confidence · full guide

Adjacent arenas — categories often shopped togetherAdjacent arenas

Shopping this category often means shopping these too.