Rank #3 of 4 in Infrastructure as Code
Install
brew tap hashicorp/tap && brew install hashicorp/tap/terraformShowcase


Try itExperimental
See what an agent can do with Terraform before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).
$terraform versionrecorded session — replayed, not liveVerified integrations
Connections to other tracked products — hover a chip for the verbatim evidence quote behind it.
By theme — the product's score on each story themeBy theme
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Import migration — stories about import migration in this arenaImport migrationevidence →
Stories about import migration in this arena
Licensing governance — stories about licensing governance in this arenaLicensing governanceevidence →
Stories about licensing governance in this arena
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan applyevidence →
The plan/apply loop — previewing infrastructure changes and applying them safely
Policy as code — stories about policy as code in this arenaPolicy as codeevidence →
Stories about policy as code in this arena
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Providers modules — stories about providers modules in this arenaProviders modulesevidence →
Stories about providers modules in this arena
Secrets config — stories about secrets config in this arenaSecrets configevidence →
Stories about secrets config in this arena
State management — stories about state management in this arenaState managementevidence →
Stories about state management in this arena
Testing validation — stories about testing validation in this arenaTesting validationevidence →
Stories about testing validation in this arena
Story verdicts — every judged story with its evidenceStory verdicts
Follow the green: where the map greys out is where Terraform stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
~6/10
unlocks → Webhooks · Scoped API keys · Machine-readable spec · Versioning policy
Subscribe to events via webhooks
—–
Build against official SDKs
~4/10
Issue scoped/least-privilege API credentials for an agent
—0/10
Connect an agent via an official MCP server
✓8/10
Download a machine-readable API spec (OpenAPI or equivalent)
—0/10
Rely on versioned APIs with a documented deprecation policy
—0/10
Test against a sandbox environment without touching production data
~6/10
Explore an interactive API reference with runnable examples
—0/10
Docs for agents
Point an agent at llms.txt or agent-oriented docs
~3/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
—–
Operate the product with natural-language commands
~4/10
Plug MCP servers into this product so it can use their tools
n/an/a
Get AI-generated insights and suggestions from my data inside the product
—0/10
Set up automations that run autonomously in the background
~5/10
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Import migration — stories about import migration in this arenaImport migration
Stories about import migration in this arena
Licensing governance — stories about licensing governance in this arenaLicensing governance
Stories about licensing governance in this arena
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply
The plan/apply loop — previewing infrastructure changes and applying them safely
Get machine-readable plan output (JSON) that an agent can parse to reason about a proposed change
✓9/10
Have an agent author an infrastructure change, run a plan headlessly, and present the diff for my approval
~6/10
Drive deployments programmatically from my own application code rather than only through the CLI
—0/10
Plan workflow
Policy as code — stories about policy as code in this arenaPolicy as code
Stories about policy as code in this arena
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Providers modules — stories about providers modules in this arenaProviders modules
Stories about providers modules in this arena
Generate infrastructure code from natural language using AI assistance built into the toolchain
~6/10
Define infrastructure in a general-purpose programming language with types, loops, and IDE support
—0/10
Consume and publish reusable modules or components from a public registry
✓9/10
Manage resources across all major clouds and SaaS providers through a broad provider ecosystem
✓9/10
Secrets config — stories about secrets config in this arenaSecrets config
Stories about secrets config in this arena
State management — stories about state management in this arenaState management
Stories about state management in this arena
Testing validation — stories about testing validation in this arenaTesting validation
Stories about testing validation in this arena
Sorted by importance (agentic first) (high → low) · 54/54 stories · click a row’s chevron for the rationale and evidence
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 8/10 | Tprobed | |
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | partial | 6/10 | Tprobed | |
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | 0/10 | ||
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | none | untested | none yet | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 9/10 | Tprobed | |
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed | |
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Cclaimed | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 4/10 | Cclaimed | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 4/10 | Tprobed | |
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 3/10 | Tprobed | |
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | partial | 6/10 | Cclaimed | |
Preview exactly what will change — creates, updates, and destroys — before applying C Plan workflow | platform-engineer | Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply | 3 | full | 10/10 | Xcommunity | |
Consume and publish reusable modules or components from a public registry C Modules | developer | Providers modules — stories about providers modules in this arenaProviders modules | 3 | full | 9/10 | Cclaimed | |
Get machine-readable plan output (JSON) that an agent can parse to reason about a proposed change C Agent plan parsing | ai-native user | Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply | 3 | full | 9/10 | Cclaimed | |
Manage resources across all major clouds and SaaS providers through a broad provider ecosystem C Providers | developer | Providers modules — stories about providers modules in this arenaProviders modules | 3 | full | 9/10 | Xcommunity | |
Run plan and apply non-interactively in CI using saved plan artifacts and approval flags C Plan workflow | devops-lead | Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply | 3 | full | 9/10 | Cclaimed | |
Detect drift between my declared configuration and the actual cloud resources C Drift | platform-engineer | State management — stories about state management in this arenaState management | 3 | full | 8/10 | Xcommunity | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | full | 8/10 | Xcommunity | |
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | partial | 6/10 | Xcommunity | |
Have an agent author an infrastructure change, run a plan headlessly, and present the diff for my approval C Ai infra ops | ai-native user | Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply | 3 | partial | 6/10 | Cclaimed | |
Enforce policy-as-code checks that block non-compliant infrastructure changes before apply C Policy | devops-lead | Policy as code — stories about policy as code in this arenaPolicy as code | 3 | partial | 5/10 | Cclaimed | |
Import existing cloud resources under management and generate matching configuration code G Import | platform-engineer | Import migration — stories about import migration in this arenaImport migration | 3 | disputed | 4/10 | Dcontradicted | |
Rely on an open license and open governance so the tool cannot be relicensed out from under my company G Licensing | devops-lead | Licensing governance — stories about licensing governance in this arenaLicensing governance | 3 | disputed | 3/10 | Dcontradicted | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | none | 0/10 | ||
Pass secrets and sensitive configuration into deployments without exposing them in code or logs C Secrets | developer | Secrets config — stories about secrets config in this arenaSecrets config | 3 | none | 0/10 | ||
Store state in a remote backend with locking so concurrent runs cannot corrupt it C State backends | platform-engineer | State management — stories about state management in this arenaState management | 3 | none | 0/10 | ||
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | n/a | untested | none yet | |
Write automated tests for my infrastructure code and run them without touching production C Testing | developer | Testing validation — stories about testing validation in this arenaTesting validation | 2 | full | 8/10 | Cclaimed | |
Let an agent plan and apply with least-privilege credentials and review gates so it cannot make unapproved changes C Ai infra ops | ai-native user | Policy as code — stories about policy as code in this arenaPolicy as code | 2 | partial | 7/10 | Cclaimed | |
Safely inspect and modify state — moving, removing, or renaming resources — when refactoring C State backends | platform-engineer | State management — stories about state management in this arenaState management | 2 | full | 7/10 | Cclaimed | |
Generate infrastructure code from natural language using AI assistance built into the toolchain C Ai authoring | ai-native user | Providers modules — stories about providers modules in this arenaProviders modules | 2 | partial | 6/10 | Tprobed | |
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | partial | 6/10 | Tprobed | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 5/10 | Tprobed | |
Manage per-environment configuration (dev, staging, prod) as separate stacks or workspaces C Config stacks | developer | Secrets config — stories about secrets config in this arenaSecrets config | 2 | partial | 5/10 | Cclaimed | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 4/10 | Xcommunity | |
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | 0/10 | ||
Define infrastructure in a general-purpose programming language with types, loops, and IDE support C Languages | developer | Providers modules — stories about providers modules in this arenaProviders modules | 2 | none | 0/10 | ||
Drive deployments programmatically from my own application code rather than only through the CLI G Automation api | developer | Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply | 2 | none | 0/10 | ||
Encrypt state at rest so credentials and sensitive values are not readable in plaintext state files C State backends | devops-lead | State management — stories about state management in this arenaState management | 2 | none | 0/10 | ||
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Migrate an existing Terraform-format codebase and its state into this tool C Migration | platform-engineer | Import migration — stories about import migration in this arenaImport migration | 2 | n/a | untested | none yet | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Rely on documented compatibility promises and upgrade guides between releases C Stability | developer | Licensing governance — stories about licensing governance in this arenaLicensing governance | 2 | none | untested | none yet | |
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | none | untested | none yet | |
Tear down an entire environment cleanly with a destroy operation C Plan workflow | developer | Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply | 2 | none | untested | none yet | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | partial | 6/10 | Xcommunity | |
Target or exclude specific resources in a plan or apply C Plan workflow | platform-engineer | Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply | 1 | none | untested | none yet | |
Validate and auto-format my configuration before planning C Testing | developer | Testing validation — stories about testing validation in this arenaTesting validation | 1 | none | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 37 stories with headroom
What would move Terraform’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Agenticness — how well agents can access and operate the productDelegate tasks to a built-in AI assistant inside the product
nonemoves Built-in AIimpact 45
Evidence shows an MCP server that lets external AI models query Terraform docs/modules/policies, but this is Terraform acting as a server for outside agents, not a built-in assistant inside the product that a user can delegate tasks to.
Automation depth — how much of the product can run unattendedDefine rules that trigger actions automatically on events
nonemoves PA Scoreimpact 30
The evidence shows Terraform's policy enforcement (Sentinel/OPA) validates plans against rules and its plan/apply workflow can be scripted, but there is no evidence of a built-in mechanism to define rules that automatically trigger actions in response to arbitrary events (e.g., event-driven automation, webhooks-to-action rules).
State management — stories about state management in this arenaStore state in a remote backend with locking so concurrent runs cannot corrupt it
nonemoves PA Scoreimpact 30
Missing: any docs/tests referencing S3/Consul/Terraform Cloud remote backends, state locking mechanism, or a hands-on probe demonstrating locking prevents concurrent corruption.
Secrets config — stories about secrets config in this arenaPass secrets and sensitive configuration into deployments without exposing them in code or logs
nonemoves PA Scoreimpact 30
The evidence pack contains no documentation of Terraform's sensitive-variable marking, environment-variable injection, or secret-manager integrations that would let a developer pass secrets without exposing them in code or logs.
Agenticness — how well agents can access and operate the productGet AI-generated insights and suggestions from my data inside the product
nonemoves Built-in AIimpact 30
Evidence only shows an MCP server that lets external AI models query Terraform docs/modules/policies for building configurations — this is agentic tool access, not Terraform itself generating insights or suggestions from a user's own infrastructure data.
Agenticness — how well agents can access and operate the productIssue scoped/least-privilege API credentials for an agent
nonemoves agent-readyimpact 30
No evidence that Terraform (or its MCP server) supports issuing scoped/least-privilege API credentials for an agent; credential/auth scoping is typically delegated to cloud provider IAM, and nothing in the docs describes Terraform generating or managing agent-specific least-privilege credentials.
Agenticness — how well agents can access and operate the productSubscribe to events via webhooks
nonemoves agent-readyimpact 30
No evidence of webhook subscription capability for events in Terraform's core product; while Terraform Cloud has run notifications/webhooks in some contexts, nothing in this evidence pack documents a webhook subscription mechanism for AI-native event consumption.
Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples
nonemoves API qualityimpact 30
The evidence pack shows standard static documentation pages and CLI references, but no interactive API reference or runnable code examples; probes explicitly confirm absence of machine-readable docs formats (llms.txt, docs.md, OpenAPI spec all 404).
Showing the top 8 of 37 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map5 surfaces · 30 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
Terraform docs29 stories
- Point an agent at llms.txt or agent-oriented docs
- Run the product headlessly / in CI for automation
- Connect an agent via an official MCP server
- Use an official CLI
- Drive the product through a documented public API
- Build against official SDKs
- Set up automations that run autonomously in the background
- Operate the product with natural-language commands
- Test against a sandbox environment without touching production data
- Perform bulk operations across many items at once
- Version, review, and roll back my automations
- Import existing cloud resources under management and generate matching configuration code
- Rely on an open license and open governance so the tool cannot be relicensed out from under my company
- Do everything through the API that I can do in the UI
- Export all of my data in open formats and leave
- Self-host the core product
- Get machine-readable plan output (JSON) that an agent can parse to reason about a proposed change
- Have an agent author an infrastructure change, run a plan headlessly, and present the diff for my approval
- Run plan and apply non-interactively in CI using saved plan artifacts and approval flags
- Preview exactly what will change — creates, updates, and destroys — before applying
- Let an agent plan and apply with least-privilege credentials and review gates so it cannot make unapproved changes
- Enforce policy-as-code checks that block non-compliant infrastructure changes before apply
- Generate infrastructure code from natural language using AI assistance built into the toolchain
- Consume and publish reusable modules or components from a public registry
- Manage resources across all major clouds and SaaS providers through a broad provider ecosystem
- Manage per-environment configuration (dev, staging, prod) as separate stacks or workspaces
- Detect drift between my declared configuration and the actual cloud resources
- Safely inspect and modify state — moving, removing, or renaming resources — when refactoring
- Write automated tests for my infrastructure code and run them without touching production
Hacker News9 stories
- Version, review, and roll back my automations
- Import existing cloud resources under management and generate matching configuration code
- Rely on an open license and open governance so the tool cannot be relicensed out from under my company
- Export all of my data in open formats and leave
- Read the product's source under an open license
- Self-host the core product
- Preview exactly what will change — creates, updates, and destroys — before applying
- Manage resources across all major clouds and SaaS providers through a broad provider ecosystem
- Detect drift between my declared configuration and the actual cloud resources
llms.txt3 stories
GitHub README3 stories
Probe proofs — replayable recordings from the probe harnessProbe proofs
Replayable recordings from our probe harness — see the Prove-It protocol to submit one.
$terraform versionreproduced$ terraform version Terraform v1.16.0 on darwin_arm64 Your version of Terraform is out of date! The latest version is 1.16.1. You can update by downloading from https://developer.hashicorp.com/terraform/install
$terraform plan -helpreproduced$ terraform plan -help
Usage: terraform [global options] plan [options]
Generates a speculative execution plan, showing what actions Terraform
would take to apply the current configuration. This command will not
actually perform the planned actions.
You can optionally save the plan to a file, which you can then pass to
the "apply" command to perform exactly the actions described in the plan.
Plan Customization Options:
The following options customize how Terraform will produce its plan. You
can also use these options when you run "terraform apply" without passing
it a saved plan, in order to plan and apply in a single command.
-destroy Select the "destroy" planning mode, which creates a plan
to destroy all objects currently managed by this
Terraform configuration instead of the usual behavior.
-refresh-only Select the "refresh only" planning mode, which checks
whether remote objects still match the outcome of the
most recent Terraform apply but does not propose any
actions to undo any changes made outside of Terraform.
-refresh=false Skip checking for external changes to remote objects
while creating the plan. This can potentially make
planning faster, but at the expense of possibly planning
against a stale record of the remote system state.
-replace=resource Force replacement of a particular resource instance using
its resource address. If the plan would've normally
produced an update or no-op action for this instance,
Terraform will plan to replace it instead. You can use
this option multiple times to replace more than one object.
-target=resource Limit the planning operation to only the given module,
resource, or resource instance and all of its
dependencies. You can use this option multiple times to
include more than one object. This is for exceptional
use only.
-var 'foo=bar' Set a value for one of the input variables in the root
module of the configuration. Use this option more than
once to set more than one variable.
-var-file=filename Load variable values from the given file, in addition
to the default files terraform.tfvars and *.auto.tfvars.
Use this option more than once to include more than one
variables file.
Other Options:
-compact-warnings If Terraform produces any warnings that are not
accompanied by errors, shows them in a more compact
form that includes only the summary messages.
-detailed-exitcode Return detailed exit codes when the command exits.
This will change the meaning of exit codes to:
0 - Succeeded, diff is empty (no changes)
1 - Errored
2 - Succeeded, there is a diff
-generate-config-out=path (Experimental) If import blocks are present in
configuration, instructs Terraform to generate HCL
for any imported resources not already present. The
configuration is written to a new file at PATH,
which must not already exist. Terraform may still
attempt to write configuration if the plan errors.
-input=true Ask for input for variables if not directly set.
-lock=false Don't hold a state lock during the operation. This
is dangerous if others might concurrently run
commands against the same workspace.
-lock-timeout=0s Duration to retry a state lock.
-no-color If specified, output won't contain any color.
-out=path Write a plan file to the given path. This can be
used as input to the "apply" command.
-parallelism=n Limit the number of concurrent operations. Defaults
to 10.
-state=statefile A legacy option used for the local backend only.
See the local backend's documentation for more
information.
Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence
4 of 11 testable claims verified · 1 contradicted → integrity 18/100
20 distinct capability claims found in Terraform’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.
4
Verified
6
Unverified
1
Contradicted
18
Undersold
Verified (7)
“Generate an execution plan that previews resource creates, updates, and destroys before applying”
Preview exactly what will change — creates, updates, and destroys — before applyingfullproof ↗
“Provide an MCP server giving AI models real-time access to provider docs, modules, and policies”
“Automate infrastructure provisioning across any cloud provider”
Manage resources across all major clouds and SaaS providers through a broad provider ecosystemfullproof ↗
“Apply command executes a plan, auto-generating one if needed and prompting for approval before performing operations”
Preview exactly what will change — creates, updates, and destroys — before applyingfullproof ↗
“Show command renders human-readable output from a saved state or plan file”
Preview exactly what will change — creates, updates, and destroys — before applyingfullproof ↗
“State file maps real-world resources to configuration, tracks metadata, and improves performance for large infra”
Detect drift between my declared configuration and the actual cloud resourcesfullproof ↗
“Write custom providers/plugins to extend supported resources”
Manage resources across all major clouds and SaaS providers through a broad provider ecosystemfullproof ↗
Unverified (10)
“Skip interactive approval and auto-approve a plan when applying”
Run plan and apply non-interactively in CI using saved plan artifacts and approval flagsfullproof ↗
“Output a JSON representation of the plan, configuration, and state via terraform show -json”
Get machine-readable plan output (JSON) that an agent can parse to reason about a proposed changefullproof ↗
“Use the terraform state CLI command to inspect and modify state”
Safely inspect and modify state — moving, removing, or renaming resources — when refactoringfullproof ↗
“Run tests that validate module changes against short-lived resources without risking real infrastructure”
Write automated tests for my infrastructure code and run them without touching productionfullproof ↗
“Emit a stream of JSON UI messages for long-running commands like plan, apply, refresh, and test”
Get machine-readable plan output (JSON) that an agent can parse to reason about a proposed changefullproof ↗
“Define policy-as-code rules that validate plans against security and compliance requirements”
Enforce policy-as-code checks that block non-compliant infrastructure changes before applypartialproof ↗
“Publish and consume providers, modules, and policies via a public registry”
Consume and publish reusable modules or components from a public registryfullproof ↗
“Create reusable infrastructure configurations packaged as modules”
Consume and publish reusable modules or components from a public registryfullproof ↗
“Mock provider-returned data during terraform test runs”
Write automated tests for my infrastructure code and run them without touching productionfullproof ↗
“Save a generated plan to a file that can later be applied exactly as previewed”
Run plan and apply non-interactively in CI using saved plan artifacts and approval flagsfullproof ↗
Contradicted (1)
“Import existing cloud resources into Terraform state from the CLI”
Import existing cloud resources under management and generate matching configuration codedisputedproof ↗
Undersold (18)
Point an agent at llms.txt or agent-oriented docspartialproof ↗
Run the product headlessly / in CI for automationfullproof ↗
Drive the product through a documented public APIpartialproof ↗
Set up automations that run autonomously in the backgroundpartialproof ↗
Operate the product with natural-language commandspartialproof ↗
Test against a sandbox environment without touching production datapartialproof ↗
Perform bulk operations across many items at oncepartialproof ↗
Do everything through the API that I can do in the UIpartialproof ↗
Export all of my data in open formats and leavepartialproof ↗
Read the product's source under an open licensepartialproof ↗
Have an agent author an infrastructure change, run a plan headlessly, and present the diff for my approvalpartialproof ↗
Let an agent plan and apply with least-privilege credentials and review gates so it cannot make unapproved changespartialproof ↗
Generate infrastructure code from natural language using AI assistance built into the toolchainpartialproof ↗
Manage per-environment configuration (dev, staging, prod) as separate stacks or workspacespartialproof ↗
Claims outside our story set (2)
Real capability claims found in Terraform’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.
“Define cloud and on-prem infrastructure in human-readable config files that can be versioned, reused, and shared”
source ↗“Build a dependency graph of resources and parallelize creation/modification of non-dependent resources”
source ↗
Business model
Terraform CLI is free under the source-available BSL 1.1; HCP Terraform has a free tier, then usage-based pricing per resource under management, plus custom Enterprise licensing.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Try Experimental
Run it in the microterminal →Recorded agent sessions — and a live MCP handshake where the vendor ships one.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
