Stackorder vs HCP Terraform: a Terraform Cloud alternative for GitHub and S3
In short
- Both
- Plan on pull requests and apply dependent work in order.
- HCP Terraform
- A SaaS that runs Terraform on HashiCorp's VMs or your agents, hosts state and a private registry, has policy built in and drift detection on Standard and Premium; priced per managed resource.
- Stackorder
- Free and self-hosted; runs on your GitHub Actions runners, stores no state and holds no cloud credentials; GitHub and S3 only.
HCP Terraform, called Terraform Cloud until April 2024, is HashiCorp's commercial platform for running Terraform; HashiCorp has been an IBM company since February 2025. It runs Terraform on HashiCorp-hosted VMs or on self-hosted agents, is the state backend, and has a private module registry, policy as code and drift detection built in. Terraform Enterprise is the self-hosted distribution of the same application.
Stackorder takes a narrower approach. It is open source and self-hosted, stores neither state nor modules, and runs nothing itself: GitHub Actions runs every plan and apply on your runners, and a small server decides which stacks run and in what order.
Stackorder and HCP Terraform side by side
Numbers link to the sources. A dash means we haven't verified it, not that it's missing.
| Feature | Stackorder | HCP Terraform |
|---|---|---|
| License | Apache-2.0, open source32 | Proprietary, commercial; the Terraform CLI itself is under BSL 1.1 since version 1.6.01, 3 |
| Deployment | Self-hosted; setup mode creates the GitHub App from a manifest25, 29 | SaaS, with a separate HCP Europe region; Terraform Enterprise is the self-hosted distribution4, 6 |
| Pricing | Free and open source; you run the server32 | Per managed resource, billed hourly: Free up to 500 resources; Essentials from $0.10, Standard from $0.47 and Premium from $0.99 per resource a month; Terraform Enterprise custom1, 2, 6 |
| Maturity | v0.1.0, first released 2026-09-30; tested end to end against LocalStack, not yet against real AWS or a real GitHub organization by default30, 31 | —not verified |
| Where Terraform runs | Your GitHub Actions runners, GitHub-hosted or self-hosted; it manages no runners or agents21 | Disposable VMs in HashiCorp's cloud by default, or self-hosted agents that need only outbound access; a workspace can also run locally6, 7 |
| State backend | Bring your own S3; never takes or releases the state lock21 | Built in: HCP Terraform is the state backend6 |
| Modules | No registry; lists each module's consumers, and for git modules the version each pins and how far behind it is21 | Built-in private registry versioned by Git tags; the Explorer shows module usage across workspaces11 |
| Self-hosted footprint | One container of about 30 MB and Postgres; actions that use no Docker21 | SaaS. Terraform Enterprise runs as containers with PostgreSQL, S3-compatible storage and Vault, plus Redis for active-active19, 20 |
| Cross-stack dependencies | A graph of stacks and modules from depends_, module sources and terraform_ reads, including cross-repository edges; applies in waves22, 23 | Run triggers between workspaces, up to 20 sources each; Stacks, with linked Stacks, on RUM plans8, 9 |
| Cloud credentials | Not held by the server; the runner assumes your IAM role with its own GitHub OIDC token24 | Held by the service: static credentials as variables, or short-lived OIDC credentials it receives for each run17, 18 |
| Human sign-in | GitHub OAuth through the App, read:org scope only25 | —not verified |
| Git hosts | GitHub only, by design21 | GitHub, GitLab, Bitbucket and Azure DevOps, hosted and self-managed; an API-driven workflow for others15 |
| OpenTofu | Yes, with tool: tofu; tested end to end with OpenTofu 1.1228, 30 | Not documented; it runs the Terraform CLI16 |
| Drift detection | Scheduled per stack with drift.; with open_, one GitHub issue per drifted stack, closed when the drift is gone; never applies to fix drift26 | Health assessments on Standard and Premium, for workspaces in remote or agent execution12 |
| Policy checks | Not a policy engine; run OPA, conftest, Checkov or Infracost in hooks, and stackorder check records a named check the apply gate honors27 | Built in: Sentinel, OPA, and HCL-based Terraform policy in beta13 |
| Pull request workflow | A check per stack, one sticky comment, and stackorder plan, apply and unlock comments; applies before merge by default, or on merge22 | Speculative plans posted as pull request checks; merges trigger plans; manual or automatic apply per workspace6 |
Why look for a Terraform Cloud alternative
- Pricing is per managed resource, billed hourly, above a free tier of 500 resources.1, 2
- The Terraform CLI it runs has been under BSL 1.1 since version 1.6.0.3
- OpenTofu support is not documented; it runs the Terraform CLI.16
- Runs execute on HashiCorp's VMs or your agents, and the service holds your cloud credentials or receives short-lived ones for each run.6, 17, 18
Key differences
Hosted service or a server you run
HCP Terraform is SaaS. Its self-hosted distribution, Terraform Enterprise, runs as containers on Docker, Kubernetes, OpenShift, Nomad or Podman, with PostgreSQL, S3-compatible object storage and Vault, plus Redis for active-active mode. Stackorder is one container and a Postgres database that you run.
State and modules
HCP Terraform is the state backend, has a private module registry versioned by Git tags, and its Explorer shows module, provider and Terraform versions across workspaces. Stackorder stores neither state nor modules: state stays in your S3 bucket and modules stay in git. It records module consumers and, for git modules, how far behind each one pins.
Where Terraform runs and who holds credentials
HCP Terraform runs on disposable VMs in HashiCorp's cloud or on self-hosted agents. It holds static credentials as variables, or, with dynamic provider credentials, receives short-lived credentials for each run and places them in the run environment. Stackorder runs on your GitHub Actions runners, which assume your AWS roles with their own OIDC token; its server has no cloud access.
GitHub Actions
HCP Terraform does not need GitHub Actions. HashiCorp publishes optional actions that drive runs through its API, and those runs still execute in HCP Terraform or on its agents. With Stackorder, GitHub Actions is where every plan and apply runs.
Dependencies
HCP Terraform connects workspaces with run triggers: a successful apply in a source workspace queues a run downstream, which applies automatically only if you enable it. Terraform Stacks, generally available since September 2025 on RUM plans, deploy components across many deployments, and linked Stacks trigger downstream Stacks when outputs change. Stackorder builds a graph of stacks and modules, including inferred terraform_remote_state edges, and applies the affected stacks in waves.
OpenTofu and pricing
HashiCorp's documentation describes HCP Terraform running the Terraform CLI and documents no OpenTofu support; Stackorder runs either. HCP Terraform is priced per managed resource, with a free tier up to 500 resources. Stackorder is free and open source under Apache-2.0.
Where HCP Terraform is strong
- A managed service: HashiCorp runs the platform, the state backend and the run infrastructure.6
- State, a private module registry, and an Explorer of module, provider and Terraform versions, all built in.6, 11
- Policy as code built in, with Sentinel, OPA and the HCL-based Terraform policy in beta.13
- Drift detection and continuous validation through health assessments on Standard and Premium.12
- GitHub, GitLab, Bitbucket and Azure DevOps, hosted and self-managed, plus an API-driven workflow.15
- Dynamic provider credentials through OIDC for AWS, GCP, Azure, Kubernetes, Vault, HCP and Tencent Cloud.18
- Terraform Stacks, which deploy the same components across many deployments, with linked Stacks between them.9, 10
- A self-hosted edition, Terraform Enterprise, on Docker, Kubernetes, OpenShift, Nomad or Podman.19
- A free tier of up to 500 managed resources with unlimited users.2
When to choose which
Choose Stackorder when
- Your code is on GitHub and you want Terraform or OpenTofu to run on your own GitHub Actions runners, under AWS roles the runner assumes with its own GitHub OIDC token.
- You have many stacks that depend on each other or on shared modules, and you want a change planned everywhere it lands and applied in dependency waves.
- You want a small open-source server you host yourself, which holds no cloud credentials and no state, and whose outage pauses applies but not pull request plans.
Choose HCP Terraform when
- You are standardized on HashiCorp Terraform and want one vendor-managed platform with hosted state, a private registry, built-in policy and drift detection.
- Your code is on GitLab, Bitbucket or Azure DevOps. Stackorder is GitHub only, by design.
- You want HashiCorp-hosted run infrastructure, or agents in your network, rather than GitHub Actions runners.
- You want a self-hosted edition from the same vendor: Terraform Enterprise.
- You want a tool with more production use: Stackorder's first release, v0.1.0, came out on .
Try Stackorder on your own repositories
Free and open source under the Apache License 2.0. The getting started guide takes one repository from nothing to a first stackorder apply; the local demo runs on one machine with no GitHub App and no AWS account.
Frequently asked questions
Is Terraform Cloud now HCP Terraform?
Is Stackorder a Terraform Cloud alternative?
Does HCP Terraform support OpenTofu?
tool at the root or per stack.