Skip to content

Rank #4 of 4 in Infrastructure as Code

Crossplane logo

Crossplane

Open Source

Cloud Native Computing Foundation

12.1k1.5k/yr +49

Access

Install

brewbrew install crossplane

Compare head-to-head

Alternatives to Crossplane

Showcase

Crossplane homepage screenshot
homepage · captured Sep 2026 · view live ↗
Crossplane docs screenshot
docs · captured Sep 2026 · view live ↗

Try itExperimental

See what an agent can do with Crossplane before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).

$crossplane version --clientrecorded session — replayed, not live
recorded 2026-09-04 · exit 0 · captured verbatim by our probe harness, secrets redacted

Verified integrations

No integration evidence found in our corpus for this product yet — that means none was found, never that it doesn’t integrate.

By theme — the product's score on each story themeBy theme

Agenticness — how well agents can access and operate the productAgenticnessevidence →

How well agents can access and operate the product

15.7/100

Automation depth — how much of the product can run unattendedAutomation depthevidence →

How much of the product can run unattended

24.0/100

Import migration — stories about import migration in this arenaImport migrationevidence →

Stories about import migration in this arena

0.0/100

Licensing governance — stories about licensing governance in this arenaLicensing governanceevidence →

Stories about licensing governance in this arena

0.0/100

Openness — open source, data portability, and self-hosting storiesOpennessevidence →

Open source, data portability, and self-hosting stories

50.0/100

Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan applyevidence →

The plan/apply loop — previewing infrastructure changes and applying them safely

7.8/100

Policy as code — stories about policy as code in this arenaPolicy as codeevidence →

Stories about policy as code in this arena

9.6/100

Privacy posture — data-handling and privacy storiesPrivacy postureevidence →

Data-handling and privacy stories

n/a

Providers modules — stories about providers modules in this arenaProviders modulesevidence →

Stories about providers modules in this arena

26.4/100

Secrets config — stories about secrets config in this arenaSecrets configevidence →

Stories about secrets config in this arena

7.2/100

State management — stories about state management in this arenaState managementevidence →

Stories about state management in this arena

34.3/100

Testing validation — stories about testing validation in this arenaTesting validationevidence →

Stories about testing validation in this arena

16.0/100

Story verdicts — every judged story with its evidenceStory verdicts

What’s free: 1 free · 0 paid · 0 enterprise · 19 not stated in evidence

?

Sorted by importance (agentic first) (high → low) · 54/54 stories · click a row’s chevron for the rationale and evidence

Drive the product through a documented public API G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3full7/10T

Connect an agent via an official MCP server G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3none0/10

Delegate tasks to a built-in AI assistant inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness3n/a0/10

Plug MCP servers into this product so it can use their tools G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3n/a0/10

Run the product headlessly / in CI for automation G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial6/10T

Use an official CLI G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial6/10T

Set up automations that run autonomously in the background G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial5/10C

Issue scoped/least-privilege API credentials for an agent G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial4/10C

Download a machine-readable API spec (OpenAPI or equivalent) G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Get AI-generated insights and suggestions from my data inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Operate the product with natural-language commands G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Build against official SDKs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2noneuntestednone yet

Explore an interactive API reference with runnable examples G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2noneuntestednone yet

Point an agent at llms.txt or agent-oriented docs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2noneuntestednone yet

Rely on versioned APIs with a documented deprecation policy G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2noneuntestednone yet

Subscribe to events via webhooks G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2noneuntestednone yet

Test against a sandbox environment without touching production data G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness1partial4/10T

Self-host the core product G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3fullfree9/10T

Detect drift between my declared configuration and the actual cloud resources C

Drift

platform-engineerState management — stories about state management in this arenaState management3full8/10X

Consume and publish reusable modules or components from a public registry C

Modules

developerProviders modules — stories about providers modules in this arenaProviders modules3partial6/10C

Define rules that trigger actions automatically on events G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth3partial6/10C

Manage resources across all major clouds and SaaS providers through a broad provider ecosystem C

Providers

developerProviders modules — stories about providers modules in this arenaProviders modules3partial6/10X

Export all of my data in open formats and leave G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3partial5/10C

Have an agent author an infrastructure change, run a plan headlessly, and present the diff for my approval C

Ai infra ops

ai-native userPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply3partial4/10T

Get machine-readable plan output (JSON) that an agent can parse to reason about a proposed change C

Agent plan parsing

ai-native userPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply3none0/10

Preview exactly what will change — creates, updates, and destroys — before applying C

Plan workflow

platform-engineerPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply3none0/10

Run plan and apply non-interactively in CI using saved plan artifacts and approval flags C

Plan workflow

devops-leadPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply3none0/10

Enforce policy-as-code checks that block non-compliant infrastructure changes before apply C

Policy

devops-leadPolicy as code — stories about policy as code in this arenaPolicy as code3noneuntestednone yet

Import existing cloud resources under management and generate matching configuration code G

Import

platform-engineerImport migration — stories about import migration in this arenaImport migration3noneuntestednone yet

Pass secrets and sensitive configuration into deployments without exposing them in code or logs C

Secrets

developerSecrets config — stories about secrets config in this arenaSecrets config3noneuntestednone yet

Prevent my data from being used to train AI models G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture3n/auntestednone yet

Rely on an open license and open governance so the tool cannot be relicensed out from under my company G

Licensing

devops-leadLicensing governance — stories about licensing governance in this arenaLicensing governance3noneuntestednone yet

Store state in a remote backend with locking so concurrent runs cannot corrupt it C

State backends

platform-engineerState management — stories about state management in this arenaState management3n/auntestednone yet

Do everything through the API that I can do in the UI G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2full7/10C

Drive deployments programmatically from my own application code rather than only through the CLI G

Automation api

developerPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply2partial5/10T

Write automated tests for my infrastructure code and run them without touching production C

Testing

developerTesting validation — stories about testing validation in this arenaTesting validation2disputed5/10D

Define infrastructure in a general-purpose programming language with types, loops, and IDE support C

Languages

developerProviders modules — stories about providers modules in this arenaProviders modules2partial4/10C

Let an agent plan and apply with least-privilege credentials and review gates so it cannot make unapproved changes C

Ai infra ops

ai-native userPolicy as code — stories about policy as code in this arenaPolicy as code2partial4/10X

Manage per-environment configuration (dev, staging, prod) as separate stacks or workspaces C

Config stacks

developerSecrets config — stories about secrets config in this arenaSecrets config2partial3/10C

Safely inspect and modify state — moving, removing, or renaming resources — when refactoring C

State backends

platform-engineerState management — stories about state management in this arenaState management2none0/10

Tear down an entire environment cleanly with a destroy operation C

Plan workflow

developerPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply2none0/10

Choose where my data is stored (region/residency) G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2n/auntestednone yet

Control data retention and deletion G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2n/auntestednone yet

Encrypt state at rest so credentials and sensitive values are not readable in plaintext state files C

State backends

devops-leadState management — stories about state management in this arenaState management2noneuntestednone yet

Generate infrastructure code from natural language using AI assistance built into the toolchain C

Ai authoring

ai-native userProviders modules — stories about providers modules in this arenaProviders modules2noneuntestednone yet

Migrate an existing Terraform-format codebase and its state into this tool C

Migration

platform-engineerImport migration — stories about import migration in this arenaImport migration2noneuntestednone yet

Opt out of telemetry and usage tracking G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2n/auntestednone yet

Perform bulk operations across many items at once G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2noneuntestednone yet

Read the product's source under an open license G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2noneuntestednone yet

Rely on documented compatibility promises and upgrade guides between releases C

Stability

developerLicensing governance — stories about licensing governance in this arenaLicensing governance2noneuntestednone yet

Schedule recurring jobs or workflows G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2n/auntestednone yet

Version, review, and roll back my automations G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth1partial6/10X

Validate and auto-format my configuration before planning C

Testing

developerTesting validation — stories about testing validation in this arenaTesting validation1partial3/10T

Target or exclude specific resources in a plan or apply C

Plan workflow

platform-engineerPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply1none0/10

Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 41 stories with headroom

What would move Crossplane’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.

  1. Agenticness — how well agents can access and operate the productConnect an agent via an official MCP server

    nonemoves agent-readyimpact 45

    Crossplane is a Kubernetes control-plane framework, not an AI agent, so publishing an official MCP server is a plausible ecosystem capability, but no evidence in the pack mentions an MCP server, MCP integration, or agent connectivity of any kind—only marketing language about 'AI systems' acting on APIs, which is not an MCP server claim.

  2. Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyRun plan and apply non-interactively in CI using saved plan artifacts and approval flags

    nonemoves PA Scoreimpact 30

    Crossplane operates as a continuously-reconciling Kubernetes control plane rather than a plan/apply tool with saved plan artifacts and approval gates; the evidence pack contains no documentation of a CI-oriented plan/apply/approve workflow.

  3. Import migration — stories about import migration in this arenaImport existing cloud resources under management and generate matching configuration code

    nonemoves PA Scoreimpact 30

    Missing: an import/adopt command or workflow, generated MR/Composition code from existing infra, any docs or community reports of migrating pre-existing resources into Crossplane management.

  4. Licensing governance — stories about licensing governance in this arenaRely on an open license and open governance so the tool cannot be relicensed out from under my company

    nonemoves PA Scoreimpact 30

    Missing: license identification, governance/foundation structure, any statement on relicensing protection.

  5. Policy as code — stories about policy as code in this arenaEnforce policy-as-code checks that block non-compliant infrastructure changes before apply

    nonemoves PA Scoreimpact 30

    The evidence pack describes Crossplane's control-plane architecture, RBAC, packages, and CLI tooling, but contains no mention of a policy-as-code engine (e.g., OPA/Gatekeeper/Kyverno integration, admission webhooks, or built-in policy checks) that blocks non-compliant infrastructure changes before apply.

  6. Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPreview exactly what will change — creates, updates, and destroys — before applying

    nonemoves PA Scoreimpact 30

    Missing: any documented `crossplane plan`/diff command showing pending creates/updates/deletes, first-party guidance on previewing resource changes before applying, and independent confirmation of such a preview workflow.

  7. Secrets config — stories about secrets config in this arenaPass secrets and sensitive configuration into deployments without exposing them in code or logs

    nonemoves PA Scoreimpact 30

    Missing: any documentation or community evidence of secret injection, secure credential storage, or protection from log exposure.

  8. Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyGet machine-readable plan output (JSON) that an agent can parse to reason about a proposed change

    nonemoves PA Scoreimpact 30

    Crossplane's model is continuous reconciliation (drift correction) rather than a discrete plan/apply workflow, and the probe evidence explicitly states no local plan/preview loop exists — every operation requires a live cluster.

Showing the top 8 of 41 — every none/partial verdict in the story verdicts table is headroom.

Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.

Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map4 surfaces · 21 covered stories

Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.

Probe proofs — replayable recordings from the probe harnessProbe proofs

Replayable recordings from our probe harness — see the Prove-It protocol to submit one.

$crossplane version --clientreproduced
$ crossplane version --client
Client Version: v2.5.0
proves: Use an official CLIrecorded 2026-09-04

Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence

4 of 8 testable claims verified · 1 contradictedintegrity 25/100

27 distinct capability claims found in Crossplane’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.

4

Verified

3

Unverified

1

Contradicted

13

Undersold

Verified (7)
Unverified (5)
Contradicted (1)
Undersold (13)
Claims outside our story set (14)

Real capability claims found in Crossplane’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.

  • Lets you configure infrastructure behavior via composable function pipelines instead of writing custom controllers

    source ↗
  • Installs via a Helm chart

    source ↗
  • Supports enabling real-time compositions via a feature flag

    source ↗
  • Can automatically protect Providers from deletion while they have active managed resources

    source ↗
  • Provides tooling for troubleshooting Compositions, Composite Resources, and Managed Resources

    source ↗
  • Image Configs give centralized control over package image configuration

    source ↗
  • Composite Resource Definitions let you define schemas for composite resources (custom APIs)

    source ↗
  • Extends Kubernetes' RBAC and reliability features to orchestrate more than just containers

    source ↗
  • New features are introduced behind alpha feature flags, off by default

    source ↗
  • Lets you design custom APIs and abstractions for how users interact with your control plane

    source ↗
  • Installing Crossplane enables installation of Provider, Function, and Configuration package resources

    source ↗
  • Real-time compositions can be enabled via the --enable-realtime-compositions flag

    source ↗
  • Pre-release versions can be installed from the master Helm channel

    source ↗
  • Functions extend Crossplane with new ways to configure composition logic

    source ↗
Suggest a story for these →

Business model

open-source

Apache-2.0 CNCF project with no direct monetization; vendors such as Upbound sell commercial distributions, control planes, and support built on Crossplane.

pricing ↗

Score trend

How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.

PA Score22 (Sep 4 '26)23 (Sep 4 '26)
Agent-ready21 (Sep 4 '26)22 (Sep 4 '26)

Try Experimental

Run it in the microterminal →

Recorded agent sessions — and a live MCP handshake where the vendor ships one.

Flag

⚑ Flag a verdict

Think a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.

Badge

Embed this product's score badge →

Hotlinked SVG — always shows the live current score.

For agents

Data