Infrastructure as Code arenaInfrastructure as Code
Tools for declaring, previewing, and applying cloud infrastructure as code, judged on plan/apply workflows, state management, module and provider ecosystems, policy-as-code, testing, licensing openness, and how safely an agent can author and apply changes headlessly.
54 user stories · 216 judged cells · updated 2026-09-16 · Evidence as of 2026-09-15
Leaderboard — every product ranked by evidenceLeaderboard
| 1 | free-tier vs OpenTofu ↗ | 51/100 | 45/100 | 6/100 | 44/100 | 14/100 | ★ 25.7k▲ 2.6k/yrnpm 2.2M/wk | 32/40 verified | 73/100 integrity | ||
| 2 | 41/100 | 12/100 | 4/100 | 64/100 | 17/100 | ★ 30.2k▲ 9.8k/yr | 24/29 verified | 79/100 integrity | |||
| 3 | free-tier vs Pulumi ↗ | 43/100 | 12/100 | 5/100 | 46/100 | 14/100 | ★ 49.7k▲ 4k/yr | 16/30 verified · 2 disputed | 18/100 integrity | ||
| 4 | 22/100 | 10/100 | 3/100 | 50/100 | 24/100 | ★ 12.1k▲ 1.5k/yr | 12/21 verified · 1 disputed | 25/100 integrity |
Best by user type — persona-weighted winnersBest by user type
Per persona, the product with the highest persona-weighted coverage over just that persona's stories — not the same ranking as the overall PA Score leaderboard above.
Best for platform-engineer
Pulumi
60/100
Runner-up:
OpenTofu (51/100)
7 platform-engineer stories scored
Story matrix — every product × every judged storyStory matrix
Agenticness — how well agents can access and operate the productAgenticness
Agent access
| Story | Persona | ||||
|---|---|---|---|---|---|
| Agenticness — how well agents can access and operate the productPoint an agent at llms.txt or agent-oriented docs | ai-native | partialT 3/10 | fullT 8/10 | none 0/10 | none 0/10 |
| Agenticness — how well agents can access and operate the productRun the product headlessly / in CI for automation | ai-native | fullT 9/10 | fullT 9/10 | fullT 9/10 | partialT 6/10 |
| Agenticness — how well agents can access and operate the productPlug MCP servers into this product so it can use their tools | ai-native | n/a | none 0/10 | n/a | n/a |
| Agenticness — how well agents can access and operate the productConnect an agent via an official MCP server | ai-native | fullT 8/10 | fullT 9/10 | n/a | none 0/10 |
| Agenticness — how well agents can access and operate the productUse an official CLI | ai-native | fullT 8/10 | fullT 9/10 | fullT 9/10 | partialT 6/10 |
| Agenticness — how well agents can access and operate the productDrive the product through a documented public API | ai-native | partialT 6/10 | partialT 6/10 | partialT 5/10 | fullT 7/10 |
| Agenticness — how well agents can access and operate the productIssue scoped/least-privilege API credentials for an agent | ai-native | none 0/10 | none 0/10 | n/a | partialC 4/10 |
| Agenticness — how well agents can access and operate the productBuild against official SDKs | ai-native | partialC 4/10 | fullT 9/10 | none 0/10 | none 0/10 |
| Agenticness — how well agents can access and operate the productSubscribe to events via webhooks | ai-native | none 0/10 | none 0/10 | n/a | none 0/10 |
Agentic features
| Story | Persona | ||||
|---|---|---|---|---|---|
| Agenticness — how well agents can access and operate the productGet AI-generated insights and suggestions from my data inside the product | ai-native | none 0/10 | partialX 6/10 | n/a | none 0/10 |
| Agenticness — how well agents can access and operate the productSet up automations that run autonomously in the background | ai-native | partialC 5/10 | partialT 6/10 | partialT 4/10 | partialC 5/10 |
| Agenticness — how well agents can access and operate the productDelegate tasks to a built-in AI assistant inside the product | ai-native | none 0/10 | fullC 6/10 | n/a | n/a |
| Agenticness — how well agents can access and operate the productOperate the product with natural-language commands | ai-native | partialT 4/10 | partialT 7/10 | none 0/10 | none 0/10 |
Api quality
| Story | Persona | ||||
|---|---|---|---|---|---|
| Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples | ai-native | none 0/10 | none 0/10 | none 0/10 | none 0/10 |
| Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent) | ai-native | none 0/10 | none 0/10 | none 0/10 | none 0/10 |
| Agenticness — how well agents can access and operate the productTest against a sandbox environment without touching production data | ai-native | partialC 6/10 | partialT 7/10 | partialT 5/10 | partialT 4/10 |
| Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy | ai-native | none 0/10 | none 0/10 | none 0/10 | none 0/10 |
Automation depth — how much of the product can run unattendedAutomation depth
| Story | Persona | ||||
|---|---|---|---|---|---|
| Automation depth — how much of the product can run unattendedPerform bulk operations across many items at once | ai-native | partialT 6/10 | partialT 6/10 | partialC 6/10 | none 0/10 |
| Automation depth — how much of the product can run unattendedDefine rules that trigger actions automatically on events | ai-native | none 0/10 | none 0/10 | none 0/10 | partialC 6/10 |
| Automation depth — how much of the product can run unattendedSchedule recurring jobs or workflows | ai-native | none 0/10 | none 0/10 | n/a | n/a |
| Automation depth — how much of the product can run unattendedVersion, review, and roll back my automations | ai-native | partialX 6/10 | partialT 6/10 | partialT 5/10 | partialX 6/10 |
Import migration — stories about import migration in this arenaImport migration
Import
| Story | Persona | ||||
|---|---|---|---|---|---|
| Import migration — stories about import migration in this arenaImport existing cloud resources under management and generate matching configuration code | platform-engineer | disputedD 4/10 | fullC 9/10 | partialX 6/10 | none 0/10 |
Migration
| Story | Persona | ||||
|---|---|---|---|---|---|
| Import migration — stories about import migration in this arenaMigrate an existing Terraform-format codebase and its state into this tool | platform-engineer | n/a | partialC 6/10 | fullT 7/10 | none 0/10 |
Licensing governance — stories about licensing governance in this arenaLicensing governance
Licensing
| Story | Persona | ||||
|---|---|---|---|---|---|
| Licensing governance — stories about licensing governance in this arenaRely on an open license and open governance so the tool cannot be relicensed out from under my company | devops-lead | disputedD 3/10 | none 0/10 | fullX 7/10 | none 0/10 |
Stability
| Story | Persona | ||||
|---|---|---|---|---|---|
| Licensing governance — stories about licensing governance in this arenaRely on documented compatibility promises and upgrade guides between releases | developer | none 0/10 | none 0/10 | partialX 5/10 | none 0/10 |
Openness — open source, data portability, and self-hosting storiesOpenness
| Story | Persona | ||||
|---|---|---|---|---|---|
| Openness — open source, data portability, and self-hosting storiesDo everything through the API that I can do in the UI | ai-native | partialT 5/10 | partialT 5/10 | n/a | fullC 7/10 |
| Openness — open source, data portability, and self-hosting storiesExport all of my data in open formats and leave | ai-native | partialX 6/10 | partialX 5/10 | partialT 6/10 | partialC 5/10 |
| Openness — open source, data portability, and self-hosting storiesRead the product's source under an open license | ai-native | partialX 4/10 | partialC 4/10 | fullX 8/10 | none 0/10 |
| Openness — open source, data portability, and self-hosting storiesSelf-host the core product | ai-native | fullX 8/10 | fullT 8/10 | fullT 8/10 | fullT 9/10 |
Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply
Agent plan parsing
| Story | Persona | ||||
|---|---|---|---|---|---|
| Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyGet machine-readable plan output (JSON) that an agent can parse to reason about a proposed change | ai-native | fullC 9/10 | fullT 9/10 | fullT 9/10 | none 0/10 |
Ai infra ops
| Story | Persona | ||||
|---|---|---|---|---|---|
| Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyHave an agent author an infrastructure change, run a plan headlessly, and present the diff for my approval | ai-native | partialC 6/10 | fullT 8/10 | fullT 8/10 | partialT 4/10 |
Automation api
| Story | Persona | ||||
|---|---|---|---|---|---|
| Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyDrive deployments programmatically from my own application code rather than only through the CLI | developer | none 0/10 | fullX 9/10 | none 0/10 | partialT 5/10 |
Plan workflow
| Story | Persona | ||||
|---|---|---|---|---|---|
| Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyTear down an entire environment cleanly with a destroy operation | developer | none 0/10 | fullT 9/10 | fullT 9/10 | none 0/10 |
| Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyRun plan and apply non-interactively in CI using saved plan artifacts and approval flags | devops-lead | fullC 9/10 | partialT 6/10 | fullT 9/10 | none 0/10 |
| Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPreview exactly what will change — creates, updates, and destroys — before applying | platform-engineer | fullX 10/10 | fullT 9/10 | fullT 9/10 | none 0/10 |
| Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyTarget or exclude specific resources in a plan or apply | platform-engineer | none 0/10 | none 0/10 | fullT 8/10 | none 0/10 |
Policy as code — stories about policy as code in this arenaPolicy as code
Ai infra ops
| Story | Persona | ||||
|---|---|---|---|---|---|
| Policy as code — stories about policy as code in this arenaLet an agent plan and apply with least-privilege credentials and review gates so it cannot make unapproved changes | ai-native | partialC 7/10 | partialT 5/10 | partialT 4/10 | partialX 4/10 |
Policy
| Story | Persona | ||||
|---|---|---|---|---|---|
| Policy as code — stories about policy as code in this arenaEnforce policy-as-code checks that block non-compliant infrastructure changes before apply | devops-lead | partialC 5/10 | fullC 8/10 | none 0/10 | none 0/10 |
Privacy posture — data-handling and privacy storiesPrivacy posture
| Story | Persona | ||||
|---|---|---|---|---|---|
| Privacy posture — data-handling and privacy storiesChoose where my data is stored (region/residency) | ai-native | none 0/10 | partialC 5/10 | none 0/10 | n/a |
| Privacy posture — data-handling and privacy storiesPrevent my data from being used to train AI models | ai-native | n/a | n/a | n/a | n/a |
| Privacy posture — data-handling and privacy storiesControl data retention and deletion | ai-native | none 0/10 | partialC 3/10 | n/a | n/a |
| Privacy posture — data-handling and privacy storiesOpt out of telemetry and usage tracking | ai-native | none 0/10 | none 0/10 | none 0/10 | n/a |
Providers modules — stories about providers modules in this arenaProviders modules
Ai authoring
| Story | Persona | ||||
|---|---|---|---|---|---|
| Providers modules — stories about providers modules in this arenaGenerate infrastructure code from natural language using AI assistance built into the toolchain | ai-native | partialT 6/10 | fullT 8/10 | n/a | none 0/10 |
Languages
| Story | Persona | ||||
|---|---|---|---|---|---|
| Providers modules — stories about providers modules in this arenaDefine infrastructure in a general-purpose programming language with types, loops, and IDE support | developer | none 0/10 | fullX 9/10 | none 0/10 | partialC 4/10 |
Modules
| Story | Persona | ||||
|---|---|---|---|---|---|
| Providers modules — stories about providers modules in this arenaConsume and publish reusable modules or components from a public registry | developer | fullC 9/10 | partialT 6/10 | partialC 6/10 | partialC 6/10 |
Providers
| Story | Persona | ||||
|---|---|---|---|---|---|
| Providers modules — stories about providers modules in this arenaManage resources across all major clouds and SaaS providers through a broad provider ecosystem | developer | fullX 9/10 | fullT 9/10 | fullX 9/10 | partialX 6/10 |
Secrets config — stories about secrets config in this arenaSecrets config
Config stacks
| Story | Persona | ||||
|---|---|---|---|---|---|
| Secrets config — stories about secrets config in this arenaManage per-environment configuration (dev, staging, prod) as separate stacks or workspaces | developer | partialC 5/10 | fullT 7/10 | partialC 5/10 | partialC 3/10 |
Secrets
| Story | Persona | ||||
|---|---|---|---|---|---|
| Secrets config — stories about secrets config in this arenaPass secrets and sensitive configuration into deployments without exposing them in code or logs | developer | none 0/10 | partialT 5/10 | partialX 5/10 | none 0/10 |
State management — stories about state management in this arenaState management
Drift
| Story | Persona | ||||
|---|---|---|---|---|---|
| State management — stories about state management in this arenaDetect drift between my declared configuration and the actual cloud resources | platform-engineer | fullX 8/10 | partialT 6/10 | fullT 8/10 | fullX 8/10 |
State backends
| Story | Persona | ||||
|---|---|---|---|---|---|
| State management — stories about state management in this arenaStore state in a remote backend with locking so concurrent runs cannot corrupt it | platform-engineer | none 0/10 | fullX 8/10 | none 0/10 | n/a |
| State management — stories about state management in this arenaEncrypt state at rest so credentials and sensitive values are not readable in plaintext state files | devops-lead | none 0/10 | fullT 7/10 | fullX 9/10 | none 0/10 |
| State management — stories about state management in this arenaSafely inspect and modify state — moving, removing, or renaming resources — when refactoring | platform-engineer | fullC 7/10 | partialC 5/10 | partialC 3/10 | none 0/10 |
Testing validation — stories about testing validation in this arenaTesting validation
Testing
| Story | Persona | ||||
|---|---|---|---|---|---|
| Testing validation — stories about testing validation in this arenaWrite automated tests for my infrastructure code and run them without touching production | developer | fullC 8/10 | fullT 8/10 | partialC 6/10 | disputedD 5/10 |
| Testing validation — stories about testing validation in this arenaValidate and auto-format my configuration before planning | developer | none 0/10 | none 0/10 | none 0/10 | partialT 3/10 |
Adjacent arenas — categories often shopped togetherAdjacent arenas
Shopping this category often means shopping these too.