Stackorder vs Atlantis: an Atlantis alternative that runs on GitHub Actions

In short

Both
Free, Apache-2.0 and self-hosted; plan on pull requests and apply from a comment.
Atlantis
Runs Terraform on its own server, which holds your cloud credentials; works with six Git hosts and any state backend except local state.
Stackorder
Runs on your GitHub Actions runners with no cloud credentials on the server, and applies in waves from a graph of stacks and modules; GitHub and S3 only.

Atlantis and Stackorder are both free, open source under the Apache License 2.0, and self-hosted, and both bring Terraform and OpenTofu into the pull request. Atlantis is a CNCF Sandbox project. The main difference is where the work runs.

Atlantis is a Go server that receives webhooks from your Git host, runs plan and apply on its own host, and posts the output back to the pull request. Stackorder's server never runs Terraform: GitHub Actions runs every plan and apply on your runners, and the server decides which stacks run and in what order.

Last reviewed against Atlantis's own repository, documentation or pricing page.

Stackorder and Atlantis side by side

Numbers link to the sources. A dash means we haven't verified it, not that it's missing.

FeatureStackorderAtlantis
LicenseApache-2.0, open source27Apache-2.0, open source; a CNCF Sandbox project1, 2
DeploymentSelf-hosted; setup mode creates the GitHub App from a manifest20, 24Self-hosted only: Helm chart, Kubernetes manifests or Kustomize, OpenShift, an AWS Fargate module, GKE or GCE, or Docker3
PricingFree and open source; you run the server27Free; no paid tier or hosted offering1
Maturityv0.1.0, first released 2026-09-30; tested end to end against LocalStack, not yet against real AWS or a real GitHub organization by default25, 26A CNCF Sandbox project, actively released; v0.48.0 added slim images2, 15
Where Terraform runsYour GitHub Actions runners, GitHub-hosted or self-hosted; it manages no runners or agents16On the Atlantis server itself, not on CI runners3
State backendBring your own S3; never takes or releases the state lock16Bring your own; any backend except local state4
ModulesNo registry; lists each module's consumers, and for git modules the version each pins and how far behind it is16No registry; the opt-in --autoplan-modules plans the projects that use a changed local module7
Self-hosted footprintOne container of about 30 MB and Postgres; actions that use no Docker16One Go binary or container with no external database; a persistent disk for plans and BoltDB locks, or Redis for locks3
Cross-stack dependenciesA graph of stacks and modules from depends_on, module sources and terraform_remote_state reads, including cross-repository edges; applies in waves17, 18execution_order_group for a global plan or apply, and depends_on between projects in one atlantis.yaml6
Cloud credentialsNot held by the server; the runner assumes your IAM role with its own GitHub OIDC token19Held by the server, which runs Terraform: instance or workload roles, environment variables, credential files or Vault12
Human sign-inGitHub OAuth through the App, read:org scope only20—not verified
Git hostsGitHub only, by design16GitHub, GitLab, Gitea and Forgejo, Bitbucket Cloud and Server, Azure DevOps4
OpenTofuYes, with tool: tofu; tested end to end with OpenTofu 1.1223, 25Yes, with --default-tf-distribution=opentofu or terraform_distribution per project11
Drift detectionScheduled per stack with drift.schedule; with open_issue, one GitHub issue per drifted stack, closed when the drift is gone; never applies to fix drift21Alpha API endpoints since v0.45.0, off by default; no built-in scheduler, so an external job has to call them8
Policy checksNot a policy engine; run OPA, conftest, Checkov or Infracost in hooks, and stackorder check records a named check the apply gate honors22Built-in Conftest (OPA) checks with policy-owner approval; custom_policy_check for other tools9
Pull request workflowA check per stack, one sticky comment, and stackorder plan, apply and unlock comments; applies before merge by default, or on merge17atlantis plan and atlantis apply comments and autoplan on each commit; applies before merge by default; a lock per directory and workspace until the pull request merges or closes5, 10

Why look for an Atlantis alternative

  • The Atlantis server runs Terraform, so it holds your cloud credentials, and Atlantis's own security documentation names malicious pull request code as a way to exploit them.12, 13
  • Every plan and apply runs on that one server, not on CI runners.3
  • Drift detection is alpha API endpoints, off by default, with no built-in scheduler.8
  • Ordering covers the projects in one atlantis.yaml.6

Key differences

Where plan and apply run

Atlantis runs Terraform on its own long-lived server, so that server needs your cloud credentials, and its security documentation names malicious pull request code as a way to exploit them. Stackorder runs Terraform in GitHub Actions jobs that assume your AWS roles with their own OIDC token; its server has no cloud access at all. Both servers must be reachable from your Git host.

Git hosts and state backends

Atlantis works with GitHub, GitLab, Gitea and Forgejo, Bitbucket Cloud and Server, and Azure DevOps, and with any state backend except local state. Stackorder is GitHub only, by design, and supports the S3 backend only.

Dependencies between stacks

Atlantis orders projects in one atlantis.yaml: execution_order_group orders a global plan or apply, and depends_on holds a project's apply until its dependencies have applied. Stackorder builds a graph from depends_on, module sources and terraform_remote_state reads, plans downstream stacks when something they depend on changes, and applies in waves. Cross-repository edges appear in its graph and can trigger plan-only runs downstream, but each run applies one repository.

Drift detection

Atlantis added alpha drift detection and remediation endpoints in v0.45.0. They are off by default, keep results in memory, and have no scheduler, so a cron job or CI job must call them. Stackorder runs drift checks on a cron schedule you set in stackorder.yaml and, with open_issue, keeps one GitHub issue per drifted stack. It never applies to fix drift; that stays a pull request.

Policy

Atlantis runs Conftest policy checks against the plan, and a failure blocks the apply until a policy owner approves. Stackorder is not a policy engine: you run OPA, conftest, Checkov or Infracost in a hook, and stackorder check records the verdict as a named check that the apply gate honors.

Locking

Atlantis locks each directory and workspace when it plans, until the pull request merges or closes. Stackorder takes stack-level locks in Postgres, all or nothing, before the first wave of an apply, and releases them on merge or when the run completes. Neither replaces Terraform's own state lock.

Where Atlantis is strong

  • Free and open source under Apache-2.0, and governed as a CNCF Sandbox project.1, 2
  • Six Git hosts: GitHub, GitLab, Gitea and its forks such as Forgejo, Bitbucket Cloud, Bitbucket Server and Azure DevOps.4
  • Any Terraform state backend except local state.4
  • Built-in Conftest policy checks that hold an apply until a policy owner approves.9
  • One binary or container with no external database; Redis is an option for locks.3
  • OpenTofu as a first-class distribution, with versions detected from .tofu files since v0.46.0.11
  • Metrics for StatsD or Prometheus, and a web UI that shows and releases locks.14
  • Actively released: v0.48.0 added slim images without bundled binaries.15

When to choose which

Choose Stackorder when

  • Your code is on GitHub and you want Terraform or OpenTofu to run on your own GitHub Actions runners, under AWS roles the runner assumes with its own GitHub OIDC token.
  • You have many stacks that depend on each other or on shared modules, and you want a change planned everywhere it lands and applied in dependency waves.
  • You want a small open-source server you host yourself, which holds no cloud credentials and no state, and whose outage pauses applies but not pull request plans.

Choose Atlantis when

  • Your repositories live on GitLab, Gitea, Bitbucket or Azure DevOps, or your state is in a backend other than S3.
  • You want Conftest policy checks built into the tool, with approval by policy owners.
  • You want one server to run Terraform with no CI runners involved, and you are comfortable securing a long-lived server that holds cloud credentials.
  • You want a tool governed by the CNCF.
  • You want a tool with more production use: Stackorder's first release, v0.1.0, came out on .

Try Stackorder on your own repositories

Free and open source under the Apache License 2.0. The getting started guide takes one repository from nothing to a first stackorder apply; the local demo runs on one machine with no GitHub App and no AWS account.

Frequently asked questions

Is Stackorder an alternative to Atlantis?

Yes, for teams on GitHub that keep state in S3. Both are free, Apache-2.0 and self-hosted, and both plan on pull requests and apply from a comment. Stackorder differs in running Terraform on GitHub Actions instead of on its own server, and in ordering applies from a dependency graph that includes modules and terraform_remote_state reads.

Does the Stackorder server need cloud credentials like the Atlantis server does?

No. The Atlantis server runs Terraform, so it needs provider credentials from instance roles, environment variables, credential files or Vault. The Stackorder server has no cloud access: each GitHub Actions job assumes your IAM role with its own GitHub OIDC token.

Do both support OpenTofu?

Yes. Atlantis supports OpenTofu with --default-tf-distribution=opentofu on the server or terraform_distribution per project. Stackorder supports it with tool: tofu, set at the root or per stack, and its end-to-end tests run OpenTofu 1.12.

Does Atlantis support GitLab and Bitbucket? Does Stackorder?

Atlantis supports GitHub, GitLab, Gitea and Forgejo, Bitbucket Cloud, Bitbucket Server and Azure DevOps. Stackorder supports GitHub only, by design.

Which one has scheduled drift detection?

Stackorder runs drift checks on a cron schedule and can keep one GitHub issue per drifted stack. Atlantis has alpha drift detection and remediation endpoints, added in v0.45.0, with no built-in scheduler: an external cron or CI job calls them.

More comparisons