infrastructure-as-code
Reusable GitHub Action that reviews Terraform PRs for security, cost, and style using a LangGraph multi-agent system, posting a single severity-ranked comment.
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.
KICS stands for Keeping Infrastructure as Code Secure, it is open source and is a must-have for any cloud native project.
Related contents:
Treat environments as configuration and eliminate code duplication, custom bash scripts, and complicated tooling with one tool to rule them all.
👽 Terraform Orchestration Tool for DevOps. Keep environment configuration DRY with hierarchical imports of configurations, inheritance, and WAY more. Native support for Terraform and Helmfile.
Boring-registry is a simple open source module and provider registry compatible with Terraform and OpenTofu.
With boring-registry, you can upload and distribute your own modules and providers, as an alternative to publishing them on HashiCorp’s public Terraform Registry.
Support for the Module Registry Protocol, Provider Registry Protocol, and Provider Network Mirror Protocol allows it to work natively with Terraform and OpenTofu.
Open-Source CDK for Terraform & OpenTofu. Define infrastructure resources using programming constructs and provision them using OpenTofu/Terraform.
CDK Terrain is a community-driven fork of CDKTF. Write infrastructure in TypeScript, Python, Java, and more. Works with both Terraform and OpenTofu. Made by developers, for developers.
Related contents:
Conftest is a utility to help you write tests against structured configuration data. For instance, you could write tests for your Kubernetes configurations, Tekton pipeline definitions, Terraform code, Serverless configs or any other structured data.
Conftest relies on the Rego language from Open Policy Agent for writing policies. If you're unsure what exactly a policy is, or unfamiliar with the Rego policy language, the Policy Language documentation provided by the Open Policy Agent documentation site is a great resource to read.
Related contents:
TerraTidy is a single-binary quality platform for Terraform and Terragrunt. It provides formatting, style checking, linting, and policy enforcement.
Customization of kubernetes YAML configurations.
kustomize lets you customize raw, template-free YAML files for multiple purposes, leaving the original YAML untouched and usable as is.
kustomize targets kubernetes; it understands and can patch kubernetes style API objects. It's like make, in that what it does is declared in a file, and it's like sed, in that it emits edited text.
Infrastructure as TypeScript
Deploy to Cloudflare, AWS, and more with pure TypeScript. Generate support for any API in minutes with AI.
Alchemy is an embeddable, TypeScript-native Infrastructure-as-Code (IaC) library for modeling Resources that are Created, Updated and Deleted automatically.
Review large Terraform diff to detect any issue. AI-Powered Terraform Plan Reviewer.
Verify your Terraform plan matches your code intent before apply.
tfrev uses Claude AI to review your terraform plan output against your code changes, catching mismatches, security risks, and unexpected side effects before they hit production. Works with any Terraform provider — AWS, Azure, GCP, Kubernetes, and more.
A curated and collaborative list of awesome OpenTofu resources and tools.
OpenTofu allows you to declaratively manage your infrastructure. It’s an open-source, community-driven alternative to Terraform.
A Watchdog for Your Infrastructure State. Continuous infrastructure drift detection with historical tracking and notifications.
Monitor infrastructure drift for Terraform, OpenTofu, and Terragrunt. Real-time drift detection with automated alerting.
AWS silently updates Managed IAM policies all the time. We catch every single change.
Every week, something breaks. Your job is to figure out what happened, why it happened, and how to fix it fast.
Fastest correct answer wins 100$
Terraform Visualization tool and Architecture Diagram Generator.
Terravision creates Professional Cloud Architecture Diagrams from your Terraform code automatically. Supports AWS, Google and Azure.
Visualise your Terraform code using official AWS/GCP/Azure design standards and icons to create solution architect grade architecture diagrams ready for audit, governance, team member and security reviews.
Open-source platform replacement for Terraform Enterprise.
Terrapod provides the collaboration, governance, state management, and UI layer that wraps around terraform or tofu as pluggable execution backends. It targets API compatibility with the HCP Terraform / TFE V2 API so that existing tooling -- the terraform CLI with cloud block, the go-tfe client, CI/CD integrations -- can point at a Terrapod instance with minimal reconfiguration.
Catch cloud waste before it ships. Shift-left cloud hygiene engine for AWS and Azure. Catch waste in CI - read-only, deterministic, zero telemetry.
Like tfsec for Terraform or trivy for containers — CleanCloud finds orphaned resources in AWS and Azure and enforces hygiene gates in your CI/CD pipeline before waste reaches production.
Related contents:
How to design, build, and operate AI agents for infrastructure teams — safely. 13 chapters covering architecture, sandboxing, credentials, change control, observability, and more.
AI agents can write IaC, fix compliance findings, detect drift, review PRs, and respond to incidents — all autonomously. But autonomy without guardrails is a liability. Agents that can terraform apply can also terraform destroy. Agents that read configs can leak secrets. Agents that loop can burn budgets.
This guide covers every architectural decision you need to make when building infrastructure agents — with real patterns, code snippets, multiple alternatives, and the risk framework to evaluate your choices.
Threat Designer is a GenerativeAI application designed to automate and streamline the threat modeling process for secure system design.
Threat Designer is an AI-driven agent that automates and streamlines the threat modeling process for secure system design. Harnessing the power of large language models (LLMs), it analyzes system architectures, identifies potential security threats, and generates detailed threat models—empowering developers and security professionals to incorporate security from the earliest stages of development.
Custom Claude Code skills for infrastructure as code development.
Related contents:
The open source platform that helps teams manage their infrastructure as code at scale using Terraform or OpenTofu. No vendor lock-in, No licensing headache, Self Hosted anywhere.
Terrakube is an open source collaboration platform for running remote infrastructure as code operations using Terraform or OpenTofu that aims to be a complete replacement for close source tools like Terraform Enterprise, Scalr or Env0.
Transform Terraform Plans Into Readable Reports
Stop drowning in verbose plan output. Generate structured Markdown reports that render perfectly in PR comments.
Related contents:
Vagrant is the command line utility for managing the lifecycle of virtual machines. Isolate dependencies and their configuration within a single disposable and consistent environment.
Related contents:
Fast Python Infrastructure Automation & Configuration Management Tool.
🔧 pyinfra turns Python code into shell commands and runs them on your servers. Execute ad-hoc commands and write declarative operations. Target SSH servers, local machine and Docker containers. Fast and scales from one server to thousands.
Related contents:
Automated tests for your infrastructure code.
Terratest is a Go library that provides patterns and helper functions for testing infrastructure, with 1st-class support for Terraform, Packer, Docker, Kubernetes, AWS, GCP, and more.
Related contents:
a lightweight, security focused, BDD test framework against terraform.
terraform-compliance is a lightweight, security and compliance focused test framework against terraform to enable negative testing capability for your infrastructure-as-code.
Turn Your IaC into a Lightning-Fast Platform. Rapidly accelerate Terraform, OpenTofu, and Terragrunt projects with faster pipelines, reduced blast radius, drift and vulnerability detection, full visibility and observability in minutes.
Open-source Infrastructure as Code (IaC) orchestration platform: GitOps workflows, orchestration, code generation, observability, drift detection, asset management, policies, Slack notifications, and more. Integrates with Terraform, OpenTofu, Terragrunt, Kubernetes, GitHub Actions, GitLab CI/CD, BitBucket Pipelines, and any other CI/CD platform.
Terramate CLI is an open-source orchestration and code generation engine that allows Infrastructure as Code (IaC) such as Terraform, OpenTofu, Terragrunt and Kubernetes to scale.
Related contents:
Terraspace Is A Terraform Framework that optimizes for infrastructure-as-code happiness.
It provides an organized structure, conventions over configurations, keeps your code DRY, and adds convenient tooling. TERRASPACE makes working with Terraform easier and more fun.
Related contents:
Infrastructure-as-Code Platform Built for the Future.
formae is a 100% code-based, agentic IaC (Infrastructure-as-Code) tool built from scratch for the modern age. We believe that code is the only medium every engineer on every level understands and wants. So formae implements infrastructure entirely as code - in and out, and in any granularity. formae doesn't require its user to maintain any secondary artifacts such as state files, and keeps the infrastructure code automatically in sync with the reality.
Stop EC2 instances and RDS/Aurora databases overnight by tagging them with cron schedules, to cut AWS costs. Trigger CloudFormation stack updates and AWS Backup, too.
SSE (Spitzkop Systems Engineering) Landing Zone as a Service - Command Line Interface. A powerful CLI tool for managing AWS Account Factory (AFT) through GitOps Infrastructure as Code principles.
2048 game with DevOps practices.
A fully containerized and cloud-native implementation of the classic 2048 game with complete CI/CD pipeline, Kubernetes deployment, and Infrastructure as Code.
Artificial Intelligence Infrastructure-as-Code Generator.
aiac is a library and command line tool to generate IaC (Infrastructure as Code) templates, configurations, utilities, queries and more via LLM providers such as OpenAI, Amazon Bedrock and Ollama.
The CLI allows you to ask a model to generate templates for different scenarios (e.g. "get terraform for AWS EC2"). It composes an appropriate request to the selected provider, and stores the resulting code to a file, and/or prints it to standard output.
Terraform Pull Request Automation. Running Terraform Workflows with Ease.
A self-hosted golang application that listens for Terraform pull request events via webhooks.
Related contents:
- Collaborating with Terraform: How Teams Can Work Together Without Breaking Things @ SYJ's Learning Diary's Medium.
- A more mature take on stateless Terraform @ Ricard Bejarano.
- A one-line Kubernetes fix that saved 600 hours a year @ Cloudflare.
- How to Use Atlantis with GitHub Actions for Terraform @ spacelift.
Toolchain for your architecture diagrams. Architecture-as-a-code with live diagrams.
LikeC4 is a powerful set of tools and a Domain-Specific Language (DSL) designed to describe your architecture as a single, cohesive model, which is then compiled into multiple diagrams. Visualize, collaborate, and evolve the software architecture with always actual and live diagrams from your code.
Terraform Private Registry for modules and providers manageable from a REST API.
Terralist is a private Terraform registry for providers and modules that follows the published HashiCorp protocols. It provides:
-
A secure way to distribute your confidential modules and providers;
-
A management interface to visualize artifacts (including modules documentation);
Terrascan is a static code analyzer for Infrastructure as Code.
Detect compliance and security violations across Infrastructure as Code (IaC) to mitigate risk before provisioning cloud native infrastructure.
Terraform version manager. Install a specific version of Terraform.
Related contents:
Terraform is an infrastructure as code tool that lets you build, change, and version infrastructure safely and efficiently. This includes low-level components like compute instances, storage, and networking; and high-level components like DNS entries and SaaS features.
Related contents:
- 17 Key Considerations Before Designing Terraform Modules @ My Devops Journal.
- Terraform Search: Deep-Dive @ mattias.engineer.
- Terraform Actions: Deep-Dive @ mattias.engineer.
- Why Ephemeral Resources in Terraform Matter: How MyCoCo Eliminated Secrets from State Files @ Dhruv Chaudhary's dev.to.
- Automating Azure SFTP deployment with Terraform @ Techielass - A blog by Sarah Lean.
- Terraform state locking explained (and why it hurts at scale) @ Stategraph.
- How to write and rightsize Terraform modules @ HashiCorp's The Stack.
- Implementing Test-Driven Development with Terraform @ Version 1's Medium.
- Implementing Terraform Drift Detection in Your Workflow @ Devin Rosario's dev.to.
- Writing a Terraform Action @ DanielMSchmidt.de.
- Querying Terraform state with AWS Athena @ Aidan Steele's blog (usually about AWS).
- Terraform Workbook - Your Guide to Infra as Code (IaC) @ Hackerstack.
- Collaborating with Terraform: How Teams Can Work Together Without Breaking Things @ SYJ's Learning Diary's Medium.
- Manage Azure Firewall Rules,NSG rules, using Terraform resource blocks and csv files @ Azure Infrastructure Blog.
- Terraform vs OpenTofu: Which IaC tool fits your platform strategy? @ Platform Engineering.
- Securing AWS IAM with Terraform: From Shared Root to Structured Access @ Rayane Kadi's Medium.
- 20 Terraform Best Practices I Wish I Had Learned Earlier @ AWS in Plain English's Medium.
- How We Scaled Code Repository Management at DNSimple @ DNSimple.
- Terraform Parallelism: How It Works, Tuning & Best Practices @ spacelift.
- A secure automation platform: Terraform Enterprise, Ansible Automation Platform, & Vault Enterprise @ HashiCorp's YouTube.
- How AirFrance-KLM built a secure automation platform at global scale with Terraform, Vault, and Ansible @ HashiCorp's The Stack.
- How We Scaled Code Repository Management at DNSimple @ DNSSimple Blog.
- Automating Route 53 DNS Updates with Terraform When ALBs Are Reprovisioned @ Young Gyu Kim's Medium.
- How do we use Terraform at Preply @ Preply Engineering Blog.
- Terraform Enterprise 1.2 upgrades workflows, visibility, and brownfield migration @ HashiCorp's The Stack.
- GitOps architecture, patterns and anti-patterns @ Platform Engineering.
- Terraform, Feature Flags and Configurability @ Ninad's Blog.
- Advanced Terraform performance optimization @ Ricard Bejarano.
- A more mature take on stateless Terraform @ Ricard Bejarano.
- Speeding up Terraform caching with OverlayFS @ Ricard Bejarano.
- SREcon23 Americas - Scaling Terraform at ThousandEyes @ USENIX's YouTube.
- Inside Terraform: A series about the internals of Terraform @ DanielMSchmidt.de.
- Terraform Drift Detection Powered by GitHub Actions @ rosecurity@dev.
- Terraform Audit Guide: Monitoring, Logging & Compliance @ Spacelift.
- Terraform is dead @ graham gilbert.
- Terraform State Isolation—How I Kept Dev, Staging, and Production From Destroying Each Other @ DevOps.dev.
Terraform without the state file bottleneck.
Stategraph replaces the flat state file with a database-backed graph. Independent changes can run in parallel, and the state becomes queryable and auditable. No code changes.
Related contents:
IaC for Docker Compose
A thin layer on top of Docker Compose for declarative configurations.
Manage volumes, network, secrets, and even configuration files in a fully declarative way.
infrastructure made simple with Python.WS for Python devs - made simple.
Build AWS apps in high-level Python with smart defaults. Keep full control when you need it. No YAML, JSON or HSL. No clicking through consoles. No configuration hell.
Stelvio is a Python framework that simplifies AWS cloud infrastructure management and deployment. It lets you define your cloud infrastructure using pure Python, with smart defaults that handle complex configuration automatically.
This document is an attempt to systematically describe best practices using Terraform and provide recommendations for the most frequent problems Terraform users experience.
Generate Terraform moved blocks automatically for painless refactoring. Generate moved blocks and state move commands automatically for Terraform, OpenTofu, and Terragrunt. tfautomv is designed for refactoring scenarios where you want to restructure your Terraform code without changing the actual infrastructure. Understanding this distinction is crucial for successful usage.
tfautomv (a.k.a Terraform auto-move) is a refactoring helper. With it, making structural changes to your Terraform codebase becomes much easier.
When you move a resource in your code, Terraform loses track of the resource's state. The next time you run Terraform, it will plan to delete the resource it has memory of and create the "new" resource it found in your refactored code.
tfautomv inspects the output of terraform plan, detects such creation/deletion pairs and writes a moved block so that Terraform now knows no deletion or creation is required.
Deploy and Manage Kubernetes at scale.
k0rdent has been developed to provide a way to manage distributed infrastructure at massive scale leveraging kubernetes.
Related contents:
Production-Grade Container Scheduling and Management.
Kubernetes, also known as K8s, is an open source system for automating deployment, scaling, and management of containerized applications.
Related contents:
- How Kubernetes Works Internally? @ System Design Codex.
- Minimum vital pour survivre sur un sujet Kubernetes @ Téotime Pacreau :fr:.
- Formation Kubernetes : Admin & Développeurs @ DevSecOps :fr:.
- How To Run Kubernetes Commands in Go: Steps and Best Practices @ The New Stack.
- Kubernetes Is Powerful, But Not Secure (at least not by default) @ Tigera.
- Docker to Kubernetes: The 30-Day Migration Path Every Developer Should Know @ Teamcamp's dev.to.
- Beyond the surface - Exploring attacker persistence strategies in Kubernetes @ Raesene's Ramblings.
- The Myths (and Costs) of Running Node.js on Kubernetes @ Platformatic.
- k8s-1m: fully functional Kubernetes cluster with 1 million active nodes.
- Investigating and fixing "StopPodSandbox from runtime service failed" Kubelet errors @ Marcus Noble.
- Managing Kubernetes Workloads Using the App of Apps Pattern in ArgoCD-2 @ CNCF.
- How to use AI to make Kubernetes monitoring smarter @ Danlio's Medium.
- Why Kube-State-Metrics Matters for Kubernetes Observability @ weeklycloud's Medium.
- 64GB RAM Kubernetes Cluster for €39/month — Part 1: Proxmox & LVM & NAT @ TrackIT Blog.
- A Practical Guide to Running NVIDIA GPUs on Kubernetes @ jimangel.io.
- Preventing Kubernetes from Pulling the Pause Image from the Internet @ Kyle Cascade.
- Ten Common Kubernetes Misconfigurations That Cause Outages (And What You Can Do About It) @ Cloud Native Now.
- Wrangling Kubernetes contexts @ natkr's ramblings.
- In-place Pod resizing in Kubernetes: How it works and how to use it @ Palark's Blog.
- Kubernetes Metrics: Types, Tools, & Monitoring Guide @ spacelift.
- How to Troubleshoot Common Kubernetes Errors (2025 Guide) @ Spacelift.
- Kubernetes Optimization using In-Place Pod Resizing and Zone-Aware Routing @ halodoc.
- What's Wrong with Kubernetes Today @ DevZero.
- How I think about Kubernetes @ Georgi Arnaudov.
- A Brief Deep-Dive into Attacking and Defending Kubernetes @ Heilan Cyber.
- Le premier intérêt de Kubernetes n'est pas le scaling @ mcorbien.fr :fr:.
- Kubernetes Rolling Updates for Reliable Deployments @ spacelift.
- Kubernetes 1.35 features that change Day 2 operations @ The New Stack.
- How to Setup Kubectl Aliases with Kuberc (Native Method) @ Devopscube.
- Scaling Nodes From Zero - The Bottleneck @ Labyrinth Labs.
- Learn Kubernetes – Full Handbook for Developers, Startups, and Businesses @ freeCodeCamp.
- Managing Kubernetes Secrets with Mozilla SOPS and AGE @ Cyril Baah's Medium.
- Registry mirror authentication with Kubernetes secrets @ CNCF.
- When Kubernetes Is the Wrong Default @ DevOps Daily.
- Why Kubernetes Reliability Is Now a Machine-Speed Problem @ Cloud Native Now.
- The Invisible Rewrite: Modernizing the Kubernetes Image Promoter @ Kubernetes Blog.
- When Kubernetes restarts your pod — And when it doesn’t @ CNCF.
- Why is your Kubernetes cluster adding nodes when the dashboards look fine? @ The New Stack.
- Kubernetes : la solution face aux promesses non tenues du cloud ? @ AXOPEN's ausha :fr:.
- Kubernetes Still Feels Weird? What i wish i knew sooner @ AWS in Plain English's Medium.
- Kubernetes Strategic Merge Patch @ ITNEXT.
- Kubernetes forensics 1/3 : what the container ? @ Synacktiv :fr:.
- Fleet-Scale Kubernetes: An Operating Model for Homogeneous Clusters with Decoupled Capacity @ lucy.sh.
- From Kubernetes Dev Setup to Production: What Actually Changes @ Georg Schwarz.
- How to Encrypt Kubernetes Traffic with cert-manager, Let's Encrypt, and Internal TLS @ freeCodeCamp.
- Comment migrer ses applications de VMs vers Kubernetes ? Bonnes pratiques et outils indispensables ! @ AXOPEN's ausha :fr:.
- Les données dans Kubernetes : comment bien les gérer et les protéger ? @ AXOPEN's YouTube :fr:.
- Where Did My Pod Go? A Deep Dive into K8s Scheduling @ DevOps.dev's Medium.
- Kubernetes in the Age of AI @ O'Reilly Radar.
- What job interviews taught me about Kubernetes @ ~~p.
- Running AI Agents Safely Inside Kubernetes @ KodeKloud.
- How to Become Ridiculously Good at Kubernetes @ F8010's Medium.
- The feedback loops behind Kubernetes @ Planetscale.
- Multi-Cluster Kubernetes Explained @ Cilium.
- Why I haven’t run my databases on Kubernetes @ Percona.
- Operating Kubernetes at scale: a few stories from running Amazon EKS @ The New Stack.
Docker image for terraform provisioning that supports provider plugin caching and declarative binary installation via mise.
Related contents:
Bicep is a language for declaratively deploying Azure resources. You can use Bicep instead of JSON for developing your Azure Resource Manager templates (ARM templates).
Related contents:
Introducing the IaC Package Manager for Kubernetes.
yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer.
The philosophy behind yoke is that Kubernetes packages should be described via code. Programming environments have control flow, test frameworks, static typing, documentation, error management, and versioning. They are ideal for building contracts and enforcing them.
Related contents:
ExternalDNS synchronizes exposed Kubernetes Services and Ingresses with DNS providers.
Configure external DNS servers (AWS Route53, Google CloudDNS and others) for Kubernetes Ingresses and Services.
Related contents:
Open Source, Multi Cloud, Analytics, IaC, more. Provision. Query. Secure.
Query, provision and operate Cloud and SaaS resources and APIs using an extensible SQL based framework. Deploy, manage and query cloud resources and interact with APIs using SQL.
Related content:
Kube Resource Orchestrator. Powerful Abstractions for Kubernetes.
Kube Resource Orchestrator (kro) helps you to define complex multi-resource constructs as reusable components in your applications and systems. It does this by providing a Kubernetes-native, vendor agnostic way to define groupings of Kubernetes resources.
Related contents:
[Node, Python, Java] Repository of sample Custom Rules for AWS Config. AWS Community repository of custom Config rules. Contributions welcome. Instructions for leveraging these rules are below.
Very fast server provisioning for your data centre.
Self-service, remote installation of Windows, CentOS, ESXi and Ubuntu on real servers turns your data centre into a bare metal cloud.
Related content:
OpenVox is the modern open source implementation of the world's most capable configuration management platform -- trusted by everyone from the smallest hobbyist to operators of some of the largest commercial infrastructures in the business.
Related contents:
Dans cette université nous vous proposons de découvrir Pulumi en mettant en lumière ses points forts comme la programmation multi-langages, la possibilité de mieux tester son code, d'avoir une couche d'abstraction multi-cloud plus efficace et même la capacité de réaliser de véritables applications web modernes de déploiement ...
Related contents:
Reloader can watch changes in ConfigMap and Secret and do rolling upgrades on Pods with their associated DeploymentConfigs, Deployments, Daemonsets Statefulsets and Rollouts.
A Kubernetes controller to watch changes in ConfigMap and Secrets and do rolling upgrades on Pods with their associated Deployment, StatefulSet, DaemonSet and DeploymentConfig.
Plan and apply Terraform/OpenTofu via PR automation, using best practices for secure and scalable IaC workflows.