Skip to content

Rank #3 of 4 in Infrastructure as Code

Terraform logo

Terraform

HashiCorp · commercial

49.7k4k/yr +40

Access

Install

brewbrew tap hashicorp/tap && brew install hashicorp/tap/terraform

Compare head-to-head

Alternatives to Terraform

Showcase

Terraform homepage screenshot
homepage · captured Sep 2026 · view live ↗
Terraform docs screenshot
docs · captured Sep 2026 · view live ↗

Try itExperimental

See what an agent can do with Terraform before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).

$terraform versionrecorded session — replayed, not live
recorded 2026-09-04 · exit 0 · captured verbatim by our probe harness, secrets redacted

Verified integrations

Connections to other tracked products — hover a chip for the verbatim evidence quote behind it.

By theme — the product's score on each story themeBy theme

Agenticness — how well agents can access and operate the productAgenticnessevidence →

How well agents can access and operate the product

26.9/100

Automation depth — how much of the product can run unattendedAutomation depthevidence →

How much of the product can run unattended

13.5/100

Import migration — stories about import migration in this arenaImport migrationevidence →

Stories about import migration in this arena

12.0/100

Licensing governance — stories about licensing governance in this arenaLicensing governanceevidence →

Stories about licensing governance in this arena

5.4/100

Openness — open source, data portability, and self-hosting storiesOpennessevidence →

Open source, data portability, and self-hosting stories

45.6/100

Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan applyevidence →

The plan/apply loop — previewing infrastructure changes and applying them safely

55.8/100

Policy as code — stories about policy as code in this arenaPolicy as codeevidence →

Stories about policy as code in this arena

34.8/100

Privacy posture — data-handling and privacy storiesPrivacy postureevidence →

Data-handling and privacy stories

0.0/100

Providers modules — stories about providers modules in this arenaProviders modulesevidence →

Stories about providers modules in this arena

61.2/100

Secrets config — stories about secrets config in this arenaSecrets configevidence →

Stories about secrets config in this arena

12.0/100

State management — stories about state management in this arenaState managementevidence →

Stories about state management in this arena

38.0/100

Testing validation — stories about testing validation in this arenaTesting validationevidence →

Stories about testing validation in this arena

53.3/100

Story verdicts — every judged story with its evidenceStory verdicts

?

Sorted by importance (agentic first) (high → low) · 54/54 stories · click a row’s chevron for the rationale and evidence

Connect an agent via an official MCP server G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3full8/10T

Drive the product through a documented public API G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3partial6/10T

Plug MCP servers into this product so it can use their tools G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3n/a0/10

Delegate tasks to a built-in AI assistant inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness3noneuntestednone yet

Run the product headlessly / in CI for automation G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full9/10T

Use an official CLI G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full8/10T

Set up automations that run autonomously in the background G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial5/10C

Build against official SDKs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial4/10C

Operate the product with natural-language commands G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial4/10T

Point an agent at llms.txt or agent-oriented docs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial3/10T

Download a machine-readable API spec (OpenAPI or equivalent) G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Explore an interactive API reference with runnable examples G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Get AI-generated insights and suggestions from my data inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Issue scoped/least-privilege API credentials for an agent G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Rely on versioned APIs with a documented deprecation policy G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Subscribe to events via webhooks G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2noneuntestednone yet

Test against a sandbox environment without touching production data G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness1partial6/10C

Preview exactly what will change — creates, updates, and destroys — before applying C

Plan workflow

platform-engineerPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply3full10/10X

Consume and publish reusable modules or components from a public registry C

Modules

developerProviders modules — stories about providers modules in this arenaProviders modules3full9/10C

Get machine-readable plan output (JSON) that an agent can parse to reason about a proposed change C

Agent plan parsing

ai-native userPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply3full9/10C

Manage resources across all major clouds and SaaS providers through a broad provider ecosystem C

Providers

developerProviders modules — stories about providers modules in this arenaProviders modules3full9/10X

Run plan and apply non-interactively in CI using saved plan artifacts and approval flags C

Plan workflow

devops-leadPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply3full9/10C

Detect drift between my declared configuration and the actual cloud resources C

Drift

platform-engineerState management — stories about state management in this arenaState management3full8/10X

Self-host the core product G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3full8/10X

Export all of my data in open formats and leave G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3partial6/10X

Have an agent author an infrastructure change, run a plan headlessly, and present the diff for my approval C

Ai infra ops

ai-native userPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply3partial6/10C

Enforce policy-as-code checks that block non-compliant infrastructure changes before apply C

Policy

devops-leadPolicy as code — stories about policy as code in this arenaPolicy as code3partial5/10C

Import existing cloud resources under management and generate matching configuration code G

Import

platform-engineerImport migration — stories about import migration in this arenaImport migration3disputed4/10D

Rely on an open license and open governance so the tool cannot be relicensed out from under my company G

Licensing

devops-leadLicensing governance — stories about licensing governance in this arenaLicensing governance3disputed3/10D

Define rules that trigger actions automatically on events G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth3none0/10

Pass secrets and sensitive configuration into deployments without exposing them in code or logs C

Secrets

developerSecrets config — stories about secrets config in this arenaSecrets config3none0/10

Store state in a remote backend with locking so concurrent runs cannot corrupt it C

State backends

platform-engineerState management — stories about state management in this arenaState management3none0/10

Prevent my data from being used to train AI models G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture3n/auntestednone yet

Write automated tests for my infrastructure code and run them without touching production C

Testing

developerTesting validation — stories about testing validation in this arenaTesting validation2full8/10C

Let an agent plan and apply with least-privilege credentials and review gates so it cannot make unapproved changes C

Ai infra ops

ai-native userPolicy as code — stories about policy as code in this arenaPolicy as code2partial7/10C

Safely inspect and modify state — moving, removing, or renaming resources — when refactoring C

State backends

platform-engineerState management — stories about state management in this arenaState management2full7/10C

Generate infrastructure code from natural language using AI assistance built into the toolchain C

Ai authoring

ai-native userProviders modules — stories about providers modules in this arenaProviders modules2partial6/10T

Perform bulk operations across many items at once G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2partial6/10T

Do everything through the API that I can do in the UI G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2partial5/10T

Manage per-environment configuration (dev, staging, prod) as separate stacks or workspaces C

Config stacks

developerSecrets config — stories about secrets config in this arenaSecrets config2partial5/10C

Read the product's source under an open license G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2partial4/10X

Choose where my data is stored (region/residency) G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2none0/10

Define infrastructure in a general-purpose programming language with types, loops, and IDE support C

Languages

developerProviders modules — stories about providers modules in this arenaProviders modules2none0/10

Drive deployments programmatically from my own application code rather than only through the CLI G

Automation api

developerPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply2none0/10

Encrypt state at rest so credentials and sensitive values are not readable in plaintext state files C

State backends

devops-leadState management — stories about state management in this arenaState management2none0/10

Control data retention and deletion G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

Migrate an existing Terraform-format codebase and its state into this tool C

Migration

platform-engineerImport migration — stories about import migration in this arenaImport migration2n/auntestednone yet

Opt out of telemetry and usage tracking G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

Rely on documented compatibility promises and upgrade guides between releases C

Stability

developerLicensing governance — stories about licensing governance in this arenaLicensing governance2noneuntestednone yet

Schedule recurring jobs or workflows G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2noneuntestednone yet

Tear down an entire environment cleanly with a destroy operation C

Plan workflow

developerPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply2noneuntestednone yet

Version, review, and roll back my automations G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth1partial6/10X

Target or exclude specific resources in a plan or apply C

Plan workflow

platform-engineerPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply1noneuntestednone yet

Validate and auto-format my configuration before planning C

Testing

developerTesting validation — stories about testing validation in this arenaTesting validation1noneuntestednone yet

Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 37 stories with headroom

What would move Terraform’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.

  1. Agenticness — how well agents can access and operate the productDelegate tasks to a built-in AI assistant inside the product

    nonemoves Built-in AIimpact 45

    Evidence shows an MCP server that lets external AI models query Terraform docs/modules/policies, but this is Terraform acting as a server for outside agents, not a built-in assistant inside the product that a user can delegate tasks to.

  2. Automation depth — how much of the product can run unattendedDefine rules that trigger actions automatically on events

    nonemoves PA Scoreimpact 30

    The evidence shows Terraform's policy enforcement (Sentinel/OPA) validates plans against rules and its plan/apply workflow can be scripted, but there is no evidence of a built-in mechanism to define rules that automatically trigger actions in response to arbitrary events (e.g., event-driven automation, webhooks-to-action rules).

  3. State management — stories about state management in this arenaStore state in a remote backend with locking so concurrent runs cannot corrupt it

    nonemoves PA Scoreimpact 30

    Missing: any docs/tests referencing S3/Consul/Terraform Cloud remote backends, state locking mechanism, or a hands-on probe demonstrating locking prevents concurrent corruption.

  4. Secrets config — stories about secrets config in this arenaPass secrets and sensitive configuration into deployments without exposing them in code or logs

    nonemoves PA Scoreimpact 30

    The evidence pack contains no documentation of Terraform's sensitive-variable marking, environment-variable injection, or secret-manager integrations that would let a developer pass secrets without exposing them in code or logs.

  5. Agenticness — how well agents can access and operate the productGet AI-generated insights and suggestions from my data inside the product

    nonemoves Built-in AIimpact 30

    Evidence only shows an MCP server that lets external AI models query Terraform docs/modules/policies for building configurations — this is agentic tool access, not Terraform itself generating insights or suggestions from a user's own infrastructure data.

  6. Agenticness — how well agents can access and operate the productIssue scoped/least-privilege API credentials for an agent

    nonemoves agent-readyimpact 30

    No evidence that Terraform (or its MCP server) supports issuing scoped/least-privilege API credentials for an agent; credential/auth scoping is typically delegated to cloud provider IAM, and nothing in the docs describes Terraform generating or managing agent-specific least-privilege credentials.

  7. Agenticness — how well agents can access and operate the productSubscribe to events via webhooks

    nonemoves agent-readyimpact 30

    No evidence of webhook subscription capability for events in Terraform's core product; while Terraform Cloud has run notifications/webhooks in some contexts, nothing in this evidence pack documents a webhook subscription mechanism for AI-native event consumption.

  8. Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples

    nonemoves API qualityimpact 30

    The evidence pack shows standard static documentation pages and CLI references, but no interactive API reference or runnable code examples; probes explicitly confirm absence of machine-readable docs formats (llms.txt, docs.md, OpenAPI spec all 404).

Showing the top 8 of 37 — every none/partial verdict in the story verdicts table is headroom.

Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.

Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map5 surfaces · 30 covered stories

Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.

Terraform docs29 stories

Probe proofs — replayable recordings from the probe harnessProbe proofs

Replayable recordings from our probe harness — see the Prove-It protocol to submit one.

$terraform versionreproduced
$ terraform version
Terraform v1.16.0
on darwin_arm64

Your version of Terraform is out of date! The latest version
is 1.16.1. You can update by downloading from https://developer.hashicorp.com/terraform/install
proves: Use an official CLIrecorded 2026-09-04
$terraform plan -helpreproduced
$ terraform plan -help
Usage: terraform [global options] plan [options]

  Generates a speculative execution plan, showing what actions Terraform
  would take to apply the current configuration. This command will not
  actually perform the planned actions.

  You can optionally save the plan to a file, which you can then pass to
  the "apply" command to perform exactly the actions described in the plan.

Plan Customization Options:

  The following options customize how Terraform will produce its plan. You
  can also use these options when you run "terraform apply" without passing
  it a saved plan, in order to plan and apply in a single command.

  -destroy            Select the "destroy" planning mode, which creates a plan
                      to destroy all objects currently managed by this
                      Terraform configuration instead of the usual behavior.

  -refresh-only       Select the "refresh only" planning mode, which checks
                      whether remote objects still match the outcome of the
                      most recent Terraform apply but does not propose any
                      actions to undo any changes made outside of Terraform.

  -refresh=false      Skip checking for external changes to remote objects
                      while creating the plan. This can potentially make
                      planning faster, but at the expense of possibly planning
                      against a stale record of the remote system state.

  -replace=resource   Force replacement of a particular resource instance using
                      its resource address. If the plan would've normally
                      produced an update or no-op action for this instance,
                      Terraform will plan to replace it instead. You can use
                      this option multiple times to replace more than one object.

  -target=resource    Limit the planning operation to only the given module,
                      resource, or resource instance and all of its
                      dependencies. You can use this option multiple times to
                      include more than one object. This is for exceptional
                      use only.

  -var 'foo=bar'      Set a value for one of the input variables in the root
                      module of the configuration. Use this option more than
                      once to set more than one variable.

  -var-file=filename  Load variable values from the given file, in addition
                      to the default files terraform.tfvars and *.auto.tfvars.
                      Use this option more than once to include more than one
                      variables file.

Other Options:

  -compact-warnings          If Terraform produces any warnings that are not
                             accompanied by errors, shows them in a more compact
                             form that includes only the summary messages.

  -detailed-exitcode         Return detailed exit codes when the command exits.
                             This will change the meaning of exit codes to:
                             0 - Succeeded, diff is empty (no changes)
                             1 - Errored
                             2 - Succeeded, there is a diff

  -generate-config-out=path  (Experimental) If import blocks are present in
                             configuration, instructs Terraform to generate HCL
                             for any imported resources not already present. The
                             configuration is written to a new file at PATH,
                             which must not already exist. Terraform may still
                             attempt to write configuration if the plan errors.

  -input=true                Ask for input for variables if not directly set.

  -lock=false                Don't hold a state lock during the operation. This
                             is dangerous if others might concurrently run
                             commands against the same workspace.

  -lock-timeout=0s           Duration to retry a state lock.

  -no-color                  If specified, output won't contain any color.

  -out=path                  Write a plan file to the given path. This can be
                             used as input to the "apply" command.

  -parallelism=n             Limit the number of concurrent operations. Defaults
                             to 10.

  -state=statefile           A legacy option used for the local backend only.
                             See the local backend's documentation for more
                             information.

Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence

4 of 11 testable claims verified · 1 contradictedintegrity 18/100

20 distinct capability claims found in Terraform’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.

4

Verified

6

Unverified

1

Contradicted

18

Undersold

Verified (7)
Unverified (10)
Contradicted (1)
Undersold (18)
Claims outside our story set (2)

Real capability claims found in Terraform’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.

  • Define cloud and on-prem infrastructure in human-readable config files that can be versioned, reused, and shared

    source ↗
  • Build a dependency graph of resources and parallelize creation/modification of non-dependent resources

    source ↗
Suggest a story for these →

Business model

free-tierusage-basedenterprise-custom

Terraform CLI is free under the source-available BSL 1.1; HCP Terraform has a free tier, then usage-based pricing per resource under management, plus custom Enterprise licensing.

pricing ↗

Score trend

How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.

PA Score33 (Sep 4 '26)27 (Sep 16 '26)
Agent-ready52 (Sep 4 '26)43 (Sep 16 '26)

Try Experimental

Run it in the microterminal →

Recorded agent sessions — and a live MCP handshake where the vendor ships one.

Flag

⚑ Flag a verdict

Think a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.

Badge

Embed this product's score badge →

Hotlinked SVG — always shows the live current score.

For agents

Data