Stackorder vs Spacelift
In short
- Both
- Plan on pull requests and order applies across dependent stacks.
- Spacelift
- A commercial platform, SaaS first, that runs each job in a container on its workers or yours, with an OPA policy engine, optional managed state and drift reconciliation.
- Stackorder
- Free and self-hosted; runs on your GitHub Actions runners and holds no cloud credentials; no policy engine, state or registry; GitHub and S3 only.
Spacelift is a commercial, closed-source platform for infrastructure as code. It is SaaS first, and its SaaS product is now called Spacelift Deploy; a self-hosted edition is sold on the Enterprise+ tier. Every job runs in a fresh Docker container on Spacelift's public workers or on private workers you run, and the platform adds a policy engine, optional managed state, drift reconciliation and stack dependencies that pass outputs downstream.
Where Spacelift runs each job in a fresh container on its workers or yours, Stackorder runs nothing itself: GitHub Actions runs every plan and apply on your runners, and a server you host, one container and Postgres, decides which stacks run and in what order. It has no policy engine and no managed state; state stays in your S3 bucket.
Stackorder and Spacelift side by side
Numbers link to the sources. A dash means we haven't verified it, not that it's missing.
| Feature | Stackorder | Spacelift |
|---|---|---|
| License | Apache-2.0, open source29 | Proprietary platform; open-source tooling such as spacectl and the Terraform provider under MIT4, 6 |
| Deployment | Self-hosted; setup mode creates the GitHub App from a manifest22, 26 | SaaS, now called Spacelift Deploy; self-hosted on AWS, Azure, GCP or on-premises Kubernetes only on the Enterprise+ tier1, 2, 3 |
| Pricing | Free and open source; you run the server29 | Free: 2 users, 1 public worker. Starter+: $20,000 a year, unlimited users. Business, Enterprise and Enterprise+ by quote2 |
| Maturity | v0.1.0, first released 2026-09-30; tested end to end against LocalStack, not yet against real AWS or a real GitHub organization by default27, 28 | —not verified |
| Where Terraform runs | Your GitHub Actions runners, GitHub-hosted or self-hosted; it manages no runners or agents18 | A fresh Docker container per job, on Spacelift's public workers or on private workers you run7 |
| State backend | Bring your own S3; never takes or releases the state lock18 | Optional Spacelift-managed state on S3, with history and rollback, chosen when a stack is created; or your own backend8 |
| Modules | No registry; lists each module's consumers, and for git modules the version each pins and how far behind it is18 | Private module registry on paid accounts, with tests per version; module trigger policies see each module's consumers10 |
| Self-hosted footprint | One container of about 30 MB and Postgres; actions that use no Docker18 | SaaS. Self-hosted: server and drain services on Kubernetes or ECS, PostgreSQL, object storage buckets, a queue and an optional MQTT broker5 |
| Cross-stack dependencies | A graph of stacks and modules from depends_, module sources and terraform_ reads, including cross-repository edges; applies in waves19, 20 | Stack dependencies form a DAG, across repositories, and pass outputs downstream as inputs9 |
| Cloud credentials | Not held by the server; the runner assumes your IAM role with its own GitHub OIDC token21 | Spacelift assumes your AWS role, or a private worker does and the credentials never reach Spacelift; Spacelift-signed OIDC as an alternative17 |
| Human sign-in | GitHub OAuth through the App, read:org scope only22 | SAML 2.0 single sign-on from the Enterprise tier2 |
| Git hosts | GitHub only, by design18 | GitHub (including GitHub Enterprise), GitLab, Azure DevOps, Bitbucket Cloud and Data Center, and raw Git1 |
| OpenTofu | Yes, with tool: tofu; tested end to end with OpenTofu 1.1225, 27 | Yes, first-class; all OpenTofu versions16 |
| Drift detection | Scheduled per stack with drift.; with open_, one GitHub issue per drifted stack, closed when the drift is gone; never applies to fix drift23 | Scheduled proposed runs with optional reconciliation; private workers only; Starter+ and above11 |
| Policy checks | Not a policy engine; run OPA, conftest, Checkov or Infracost in hooks, and stackorder check records a named check the apply gate honors24 | Built-in OPA/Rego policy engine with several policy types12 |
| Pull request workflow | A check per stack, one sticky comment, and stackorder plan, apply and unlock comments; applies before merge by default, or on merge19 | Proposed runs on pushes, reported as commit statuses; opt-in plan comments and /spacelift commands; deploying before merge is supported13, 14 |
Key differences
Hosted platform or a server you run
Spacelift is SaaS. Its self-hosted edition is listed only on the Enterprise+ tier, needs a license key from sales, and runs server and drain services on Kubernetes or ECS with PostgreSQL, several object storage buckets and a queue. Stackorder is open source and self-hosted: one container and a Postgres database.
Where Terraform runs
Spacelift runs every job in a fresh Docker container on its public workers or on private workers you deploy, which reach Spacelift over MQTT or HTTP long-polling. It does not run jobs on GitHub Actions; its only action installs the spacectl CLI. Stackorder runs every plan and apply on your GitHub Actions runners, with actions that use no Docker.
Dependencies
Spacelift's stack dependencies form a DAG that rejects cycles, queues a dependent stack's tracked run after its upstream finishes, passes outputs downstream as inputs, and can link stacks in different repositories. Stackorder infers edges from module sources and terraform_remote_state reads as well as depends_on, plans downstream stacks in the pull request, and applies in waves; its cross-repository edges trigger plan-only runs rather than ordering one run.
Credentials
With Spacelift's AWS integration, either Spacelift assumes your role or, on private workers, the worker does, and then the credentials never reach Spacelift. The Stackorder server never assumes a role: each GitHub Actions job does, with its own GitHub OIDC token.
Policy, state and drift
Spacelift has a built-in OPA/Rego policy engine, optional managed state with history and rollback, and drift detection that can reconcile with a tracked run. Stackorder is not a policy engine, stores no state, and never applies to fix drift; it records the verdicts of the tools you run in hooks, and keeps one GitHub issue per drifted stack when open_issue is on.
Git hosts and pricing
Spacelift works with GitHub, GitLab, Azure DevOps, Bitbucket and raw Git. On 2026-09-30 its free plan covered 2 users and 1 public worker, and Starter+ cost $20,000 a year. Stackorder is GitHub only, by design, and free under Apache-2.0.
Where Spacelift is strong
- A managed service with a free plan: 2 users and 1 public worker, with no credit card and no time limit.2
- Stack dependencies that form a DAG, pass outputs downstream as inputs, and link stacks in different repositories.9
- A built-in OPA/Rego policy engine with several policy types.12
- Drift detection on a schedule, with optional reconciliation.11
- Optional managed state with history, rollback and state import.8
- A private module registry with test cases per version, and module consumers visible to trigger policies.10
- GitHub, GitLab, Azure DevOps, Bitbucket Cloud and Data Center, and raw Git.1
- Private workers can assume your AWS role themselves, so the credentials never reach Spacelift.17
- OpenTofu as a first-class tool, with every OpenTofu version supported.16
When to choose which
Choose Stackorder when
- Your code is on GitHub and you want Terraform or OpenTofu to run on your own GitHub Actions runners, under AWS roles the runner assumes with its own GitHub OIDC token.
- You have many stacks that depend on each other or on shared modules, and you want a change planned everywhere it lands and applied in dependency waves.
- You want a small open-source server you host yourself, which holds no cloud credentials and no state, and whose outage pauses applies but not pull request plans.
Choose Spacelift when
- You want a managed platform with a built-in OPA policy engine, optional managed state, drift reconciliation and dependencies that pass outputs between stacks, and you can budget for a commercial contract.
- Your code is on GitLab, Azure DevOps or Bitbucket, or on more than one Git host.
- You want vendor-run workers, or private workers managed from the same platform, rather than GitHub Actions runners.
- You need an on-premises or air-gapped installation, which Spacelift lists on its Enterprise+ tier.
- You want a tool with more production use: Stackorder's first release, v0.1.0, came out on .
Try Stackorder on your own repositories
Free and open source under the Apache License 2.0. The getting started guide takes one repository from nothing to a first stackorder apply; the local demo runs on one machine with no GitHub App and no AWS account.
Frequently asked questions
Is Stackorder an alternative to Spacelift?
Is Spacelift now called Spacelift Deploy?
Does Spacelift run Terraform on GitHub Actions?
Can Spacelift be self-hosted?
How do their prices compare?
More comparisons
- All tools in one feature matrix
- Stackorder vs Atlantis
- Stackorder vs HCP Terraform (formerly Terraform Cloud)
- Stackorder vs Stategraph (formerly Terrateam)
- Stackorder vs env zero (formerly env0)
- Stackorder vs Scalr
- Stackorder vs Terrakube
- Stackorder vs OpenTaco (formerly Digger)
- What Stackorder is and how it works