Stackorder vs OpenTaco (formerly Digger)
In short
- Both
- Run Terraform plans and applies in your GitHub Actions, keep cloud credentials in your CI, and use no Docker in their actions.
- OpenTaco
- Open core; also hosts state, offers Remote Runs in beta and remediates drift, as a hosted app or a self-hosted platform of several services.
- Stackorder
- Apache-2.0 throughout; one container and Postgres; a graph of stacks and modules that orders applies in waves; S3 state only.
Digger is now OpenTaco, renamed in November 2025; the company is still Digger, and the digger CLI, digger.yml and the GitHub Action keep their names. Like Stackorder, it runs Terraform and OpenTofu plans and applies in your own CI, GitHub Actions by default, with an orchestrator that dispatches the jobs and keeps pull request locks. Its scope has grown from pull request automation to state management, Remote Runs in beta, and drift detection and remediation.
Stackorder stays narrow on purpose: one container and Postgres, no state hosting and no runners, with a dependency graph of stacks, modules and repositories as the server's core data structure.
Stackorder and OpenTaco side by side
Numbers link to the sources. A dash means we haven't verified it, not that it's missing.
| Feature | Stackorder | OpenTaco |
|---|---|---|
| License | Apache-2.0, open source36 | Open core: MIT at the root, and a proprietary Digger Enterprise license for the ee/ directory4 |
| Deployment | Self-hosted; setup mode creates the GitHub App from a manifest29, 33 | Hosted app at otaco.app, or self-hosted with Docker Compose, Railway or Helm charts6 |
| Pricing | Free and open source; you run the server36 | No public pricing page; Enterprise features by per-seat subscription, through contact or a demo2 |
| Maturity | v0.1.0, first released 2026-09-30; tested end to end against LocalStack, not yet against real AWS or a real GitHub organization by default34, 35 | Actively released: v0.6.151 on 2026-09-13, after roughly monthly releases through 20263 |
| Where Terraform runs | Your GitHub Actions runners, GitHub-hosted or self-hosted; it manages no runners or agents25 | Your CI, GitHub Actions by default, for pull request automation and drift; Remote Runs (beta) in E2B sandbox VMs8, 9 |
| State backend | Bring your own S3; never takes or releases the state lock25 | Your existing backend; or OpenTaco's HCP Terraform-compatible state service on S3-compatible storage12 |
| Modules | No registry; lists each module's consumers, and for git modules the version each pins and how far behind it is25 | No registry; include_ globs trigger projects when a module path changes17 |
| Self-hosted footprint | One container of about 30 MB and Postgres; actions that use no Docker25 | UI, orchestrator, drift, drift trigger, state, token and sidecar services; three Postgres databases, S3-compatible storage and WorkOS6, 7 |
| Cross-stack dependencies | A graph of stacks and modules from depends_, module sources and terraform_ reads, including cross-repository edges; applies in waves26, 27 | depends_ between projects and numeric layers in digger.; Terragrunt dependency parsing14, 15, 16 |
| Cloud credentials | Not held by the server; the runner assumes your IAM role with its own GitHub OIDC token28 | Not held for pull request automation: credentials stay in your CI, with OIDC recommended; not documented for Remote Runs9, 22 |
| Human sign-in | GitHub OAuth through the App, read:org scope only29 | WorkOS, required when self-hosting7 |
| Git hosts | GitHub only, by design25 | GitHub is the documented path; GitLab pipelines need an Enterprise license key23, 24 |
| OpenTofu | Yes, with tool: tofu; tested end to end with OpenTofu 1.1232, 34 | Yes, per project with opentofu: true; Terragrunt and Pulumi too21 |
| Drift detection | Scheduled per stack with drift.; with open_, one GitHub issue per drifted stack, closed when the drift is gone; never applies to fix drift30 | A drift service on a cron schedule, or a backendless Actions workflow, reporting to Slack or GitHub Issues18 |
| Policy checks | Not a policy engine; run OPA, conftest, Checkov or Infracost in hooks, and stackorder check records a named check the apply gate honors31 | OPA through Conftest, run as a workflow step against the plan19 |
| Pull request workflow | A check per stack, one sticky comment, and stackorder plan, apply and unlock comments; applies before merge by default, or on merge26 | digger plan, apply, lock and unlock comments; applies before merge by default, on merge if configured; pull request locks13, 20 |
Key differences
The same execution model
Both run plans and applies in your GitHub Actions, and neither action uses Docker: OpenTaco's is a composite action that downloads a prebuilt CLI or builds it with Go. OpenTaco can also run with no backend at all, from the action alone, with documented limits such as no queuing of clashing applies. Stackorder always has its server, and when that server is down, plans still run but applies are refused.
Scope
OpenTaco has grown from pull request automation into state management, Remote Runs in E2B sandbox VMs (beta) and drift remediation. Stackorder is deliberately not a state backend or a runner: state stays in your S3 bucket and every job runs on your GitHub Actions runners.
Footprint
OpenTaco's current self-hosted platform runs UI, orchestrator, drift, drift trigger, state, token and sidecar services, with three Postgres databases, S3-compatible storage and WorkOS for sign-in, plus E2B for Remote Runs. Stackorder runs one container and Postgres.
Dependencies and modules
OpenTaco orders the projects changed in a pull request with depends_on and numeric layers, can derive layers from Terragrunt dependency blocks, and triggers projects on module changes through include_patterns globs. Its documentation describes no module version tracking and no cross-repository edges. Stackorder parses module sources and terraform_remote_state reads into its graph, tracks the versions of git modules, and draws cross-repository edges.
License
OpenTaco is open core: the repository root is MIT, while the ee/ directory is under a proprietary license that needs a subscription in production, and GitLab pipelines, Buildkite and FIPS builds need an Enterprise license key. Stackorder is Apache-2.0 throughout.
Drift and policy
OpenTaco's drift service runs plans on a cron schedule and notifies Slack or GitHub Issues, with remediation through an issue-driven apply or the normal pull request flow. Its documented policy path is Conftest as a workflow step. Stackorder keeps one GitHub issue per drifted stack when open_issue is on, never applies to fix drift, and records the verdicts of your policy tools as named checks the apply gate honors.
Where OpenTaco is strong
- Pull request plans and applies run in your own CI, so cloud credentials stay there.22
- Its GitHub Action uses no Docker: a composite action that downloads a prebuilt CLI or builds it with Go.10
- A backendless mode that runs from the GitHub Action alone, with locks in DynamoDB, a GCP bucket or Azure Storage Tables.11
- An HCP Terraform-compatible state service with RBAC, version history and rollback.12
- Terragrunt dependency parsing, plus OpenTofu and Pulumi per project.16, 21
- Scheduled drift detection with Slack and GitHub Issues notifications.18
- A hosted app, as well as self-hosting with Docker Compose, Railway or Helm charts.6
- Actively released: v0.6.151 came out on 2026-09-13, after roughly monthly releases through 2026.3
When to choose which
Choose Stackorder when
- Your code is on GitHub and you want Terraform or OpenTofu to run on your own GitHub Actions runners, under AWS roles the runner assumes with its own GitHub OIDC token.
- You have many stacks that depend on each other or on shared modules, and you want a change planned everywhere it lands and applied in dependency waves.
- You want a small open-source server you host yourself, which holds no cloud credentials and no state, and whose outage pauses applies but not pull request plans.
Choose OpenTaco when
- You want Atlantis-style pull request plans and applies in your own GitHub Actions, and are happy to start on a hosted app or with no backend at all.
- You work in a Terragrunt monorepo and want its dependency blocks to drive the order of runs.
- You want one project to host state, run remote runs and detect drift, in a form you can self-host.
- You want a tool with more production use: Stackorder's first release, v0.1.0, came out on .
Try Stackorder on your own repositories
Free and open source under the Apache License 2.0. The getting started guide takes one repository from nothing to a first stackorder apply; the local demo runs on one machine with no GitHub App and no AWS account.
Frequently asked questions
Is Digger now OpenTaco?
diggerhq/digger, and the digger CLI, digger.yml and the diggerhq/digger@vLatest action keep their names.Is Stackorder an alternative to OpenTaco (Digger)?
How is Stackorder different from OpenTaco?
Is OpenTaco open source?
ee/ directory is under a proprietary Digger Enterprise license that needs a subscription in production. Stackorder is open source under the Apache License 2.0.