Roundups

Top 7 Infrastructure as Code Tools in 2026

Seven infrastructure as code tools ranked on ecosystem reach, licence, state handling and real pricing - Terraform's licensor is now IBM, and OpenTofu has features Terraform does not.

Illustration of an architectural blueprint rising off the page into a half-built city of server halls

Who this is for: platform and DevOps engineers choosing an infrastructure as code tool in 2026. What changed: Terraform's licence now names IBM as licensor, OpenTofu has shipped features Terraform does not have, and Crossplane graduated from the CNCF in October 2025.

  • Terraform is still the default — roughly 7,349 providers and 24,614 modules in its registry — but it is BUSL-licensed, and drift detection is a paid feature.
  • OpenTofu is the licence escape hatch and is no longer just a copy: state encryption, native S3 locking and OCI registries are OpenTofu-only.
  • Ansible is not really IaC. It is procedural, keeps no state file, and Red Hat's own docs say idempotence is not guaranteed by the engine.
  • Only Pulumi, OpenTofu, Crossplane and the CDK are fully open source. Terraform is BUSL, CloudFormation is closed, Spacelift's core is proprietary.

Infrastructure as code means defining servers, networks and cloud services in version-controlled files rather than clicking through consoles. In 2026 the leading infrastructure as code tools are Terraform, its MPL-licensed fork OpenTofu, Pulumi, AWS CDK with CloudFormation, Ansible, Crossplane and Spacelift. Terraform still has the largest provider ecosystem by a wide margin; the interesting decisions now are about licensing, state handling and whether you want a control plane instead of a CLI.

Here are the seven ranked, with real licences, real pricing, and what each one gets wrong.

How we picked these

  1. Ecosystem reach. Provider and module counts, because a tool that cannot talk to your cloud is not a candidate. Where a project publishes no count, we say so.
  2. Licensing reality. The exact licence in the repository, not the marketing word "open." This is the single biggest differentiator in this category since 2023.
  3. State and drift handling. How the tool records reality, whether it can preview changes, and whether drift detection costs extra.
  4. Fit for a specific job. Multi-cloud CLI, cloud-native control plane, AWS-only, or orchestration on top of someone else's tool.

Ranked by adoption and ecosystem breadth first, then capability. Pricing and version numbers verified as of September 2026.

Quick comparison

Tool Best for Licence Published pricing
Terraform Default multi-cloud provisioning BUSL 1.1 (licensor IBM) Yes — usage-based
OpenTofu Avoiding BUSL restrictions MPL 2.0 Free, no SaaS
Pulumi Teams who want real programming languages Apache 2.0 Yes — $40–$2,000/mo
AWS CDK + CloudFormation AWS-only estates Apache 2.0 / proprietary Yes — largely free
Ansible Configuration management, not provisioning GPL v3 No list price
Crossplane Kubernetes-native control planes Apache 2.0 Free; Upbound from $1,000/mo
Spacelift Governing IaC you already run Proprietary core One figure only

1. Terraform

HashiCorp Terraform remains the reference implementation: declarative HCL, a write-plan-apply loop, a dependency graph, and by far the largest provider ecosystem in the category. Per the Terraform Registry API on 29 September 2026, it indexes 7,349 providers and 24,614 modules — HashiCorp does not publish a headline count itself.

The licence is the story. In August 2023 HashiCorp moved Terraform from MPL 2.0 to the Business Source License 1.1. The live LICENSE file now names International Business Machines Corporation as licensor, with the licensed work described as "Terraform Version 1.6.0 or later… (c) 2024 IBM Corp." The change date is four years from publication, after which each version becomes MPL 2.0. IBM's acquisition of HashiCorp closed on 27 February 2025 at roughly $7.2 billion in equity value according to IBM's SEC filings — not the $6.4 billion enterprise value quoted when the deal was announced in April 2024.

Current release is v1.16.4, shipped 23 September 2026. Recent additions include terraform stacks in 1.13, List Resources and provider-defined Actions in 1.14, and import inside modules in 1.16.

Best for: Almost any multi-cloud provisioning job where ecosystem coverage and hiring pool matter more than licence purity.

Pros

  • The largest provider and module ecosystem of any tool here, by roughly an order of magnitude over its nearest rivals.
  • Deepest talent pool and the most third-party tooling, tutorials and CI integrations.
  • Free for up to 500 managed resources on HCP Terraform, which covers a lot of small teams.
  • Usage-based rates are published on IBM's pricing table: $0.00013 per resource-hour on Essentials, $0.00064 on Standard, $0.00135 on Premium.

Cons

  • Secrets land in state in plaintext, and HashiCorp says so. Its docs state that if you add secret values to configuration, "Terraform stores those secrets in its state and plan files," and local state is "a plaintext file, which includes any secret values."
  • Locking is not universal. The state documentation says plainly that "not all backends support locking," and force-unlock warns it "could cause multiple writers."
  • Drift detection is a paid feature. Health assessments are Standard and Premium only — and they pause when the last run errored, so drift monitoring goes dark exactly when a workspace is broken.
  • Audit logging is Premium-only, and the API rate limit is 30 requests per minute on every tier including Premium.
  • BUSL restrictions are real: the use grant bars offering Terraform on a hosted or embedded basis to compete with the paid product, and explicitly counts paid support arrangements as competing. Violations "automatically terminate your rights… for the current and all other versions."
  • HashiCorp's own documentation contradicts IBM's pricing table, telling buyers to contact sales for tiers IBM publishes rates for.
Terraform write, plan and apply workflow diagram
Image: HashiCorp

2. OpenTofu

OpenTofu is the fork of Terraform 1.5.x created after the BUSL relicensing, announced on 25 August 2023, hosted by the Linux Foundation from September 2023, and generally available as 1.6 on 10 January 2024. It was also accepted into the CNCF at Sandbox level on 23 April 2025. The licence is MPL 2.0, verified in the repository, which retains HashiCorp's original copyright line as a fork artefact.

The important development is that OpenTofu stopped being a drop-in copy. Client-side state encryption and provider-defined functions arrived in 1.7, early variable evaluation in 1.8, provider for_each and -exclude in 1.9, OCI registry support and native S3 state locking without DynamoDB in 1.10, and ephemeral resources in 1.11. Its homepage has a section titled "Features Unique to OpenTofu." Current stable release is v1.12.6, 19 August 2026.

Best for: Teams that need Terraform's model without BUSL constraints — vendors building on it, regulated buyers whose legal team objects, or anyone who wants encrypted state for free.

Pros

  • MPL 2.0 throughout, with no use restrictions and no four-year change-date clocks to track.
  • State encryption is built in and free — the single most useful feature Terraform does not have.
  • Native S3 state locking removes the DynamoDB table that Terraform users have maintained for years.
  • Backed by the Linux Foundation with 163 supporting companies, and existing HCL skills transfer directly.

Cons

  • CNCF Sandbox is the lowest maturity tier, defined as "experimental projects not yet widely tested in production" — an awkward label 17 months after acceptance.
  • No managed control plane and no first-party commercial support. The project's /pricing, /enterprise and /cloud URLs all return 404; orchestration is explicitly outsourced to third parties.
  • Compatibility stops at Terraform 1.5.x, and divergence is deliberate. The .tofu file extension exists because, in the project's words, "Terraform doesn't support these new language features" — so code using OpenTofu-only features is not portable back.
  • Terraform Stacks has no equivalent, and the project's own provider-count figures disagree with each other: the homepage says 3,900+ providers while its search site says 4,000+.
  • Provider signing-key coverage is incomplete, acknowledged by the project as containing GPG keys "only for a small number of providers."
  • Smaller community: 30,319 GitHub stars against Terraform's 49,786, and only about 13% of Terraform's fork count.
OpenTofu Registry user interface showing provider listings
Image: OpenTofu

3. Pulumi

Pulumi takes the same declarative execution model and lets you write the configuration in a real programming language: TypeScript, JavaScript, Python, .NET, Go and Java, plus YAML and HCL for people who want them. The program is evaluated to build a desired-state resource graph, which the engine diffs against recorded state — so loops, conditionals, functions and unit tests all work the way they do in application code.

Its most pragmatic feature is the Terraform provider bridge: bridged providers wrap a Terraform or OpenTofu provider as a dependency, and "Any Terraform Provider" lets you consume anything in the OpenTofu registry with no Pulumi package at all. pulumi convert imports from Terraform, Bicep, ARM and Kubernetes. In August 2026 Pulumi Cloud became generally available as a Terraform state backend. The licence is Apache 2.0 — a meaningful contrast with BUSL. Current release is v3.265.0, 25 September 2026; there is no Pulumi 4.

Best for: Teams with strong software engineering practice who want testable infrastructure code and are tired of HCL's limits.

Pros

  • Apache 2.0, unmodified, with no use restrictions.
  • Real languages mean real abstractions, real testing and IDE support — not a templating language pretending to be one.
  • Not per-seat. All paid tiers include unlimited users: Essentials $40/month, Pro $400, Enterprise $2,000, on a credit model where one credit is one dollar.
  • The Terraform bridge means provider coverage is effectively the Terraform ecosystem's, not a smaller one.
  • DIY state backends do support locking — "a basic file-based locking system is enabled by default for all DIY backends" — which is widely misreported.

Cons

  • Physical resource IDs are always stored in plaintext in state and cannot be encrypted. Pulumi documents this directly, and notes additionalSecretOutputs has no effect on id — so a random.RandomString whose result is also its ID lands unencrypted even when marked secret.
  • Secrets get decrypted inside apply callbacks, and Pulumi says it "cannot guarantee that the apply callback itself will not expose the secret value."
  • SAML/SSO and automated audit-log export both require the $400/month Pro tier. Self-hosting requires Enterprise at $2,000/month plus mandatory Platinum support.
  • Support is priced separately on top of the platform — from $625/month for Standard up to $50,000/year for Gold.
  • Credit pricing is hard to forecast: unused monthly credits expire, partial resource-hours bill as full hours, stacks and component resources are themselves billable, and discovered resources bill even when Pulumi does not manage them.
  • Smaller community than Terraform — 25,740 stars against 49,786 — with more open issues despite being the smaller project.
Pulumi Cloud unified resource search interface
Image: Pulumi

4. AWS CDK and CloudFormation

These are one stack, not two competitors. AWS CDK is an imperative authoring layer in TypeScript, JavaScript, Python, Java, C# or Go that synthesizes CloudFormation templates; CloudFormation is the deployment and state engine. AWS's own example: a roughly 20-line Fargate app produces a template of more than 500 lines and over 50 resources.

The big architectural advantage is stated plainly in AWS's docs — "CloudFormation manages state for you." No state file, no backend to configure, no locking to operate, and change sets let you inspect a diff before executing. CDK constructs come in three levels: L1 auto-generated wrappers that "offer no abstraction," L2 curated resources with sensible defaults, and L3 patterns. CDK is Apache 2.0; CloudFormation is a proprietary managed service with no engine repository.

Current versions are aws-cdk-lib 2.271.0 and CLI 2.1143.0 — two different version lines since AWS decoupled them in February 2025. CDK v1 ended support on 1 June 2023.

Best for: Teams entirely on AWS who would rather not operate state files at all.

Pros

  • Server-managed state eliminates an entire class of operational problems: no state file to lose, corrupt, lock or leak.
  • Effectively free. All AWS::* and Alexa::* resources cost nothing; only third-party resource types and Hooks are charged, at $0.0009 per handler operation after 1,000 free per month.
  • CDK is Apache 2.0 with six officially supported languages and genuine reusable constructs.
  • 2025 brought real operational improvements: stack refactoring, drift-aware change sets, a CloudFormation language server and an IaC MCP server.

Cons

  • AWS-only, and AWS says so under headings literally titled "Disadvantages." Its guidance states "CloudFormation does not support multi-cloud deployments" and "the AWS CDK can be used to deploy IaC only in the AWS Cloud."
  • Drift detection fails silently. Unsupported resource types return NOT_CHECKED, so a stack can read as in sync while unmonitored resources have drifted — and the unsupported set includes AWS::S3::BucketPolicy, AWS::EC2::SecurityGroupIngress and Egress, AWS::SecretsManager::ResourcePolicy and nested stacks themselves.
  • Hard quotas that bite CDK users hardest: 500 resources per template and a 51,200-byte template body in a request, precisely because CDK generates far more resource text per authored line. The prescribed workaround is nested stacks.
  • Stacks get stuck — AWS uses that word. A documented UPDATE_ROLLBACK_FAILED case involves rolling back to a database deleted outside CloudFormation.
  • CDK's abstraction leaks by design. AWS recommends you "learn and understand key AWS CloudFormation concepts," and L2/L3 gaps push you down to L1 constructs that offer no abstraction at all. Node.js is a hard dependency even for Python, Java and Go users.
  • No self-hosted option and no portable state export, so the managed-state benefit and the lock-in are the same fact viewed from two sides.
AWS CDK application and stack synthesis process diagram
Image: Amazon Web Services

5. Ansible

Ansible is on this list because practitioners use it for infrastructure, but it deserves a precise description. It is procedural, not declarative: Red Hat's documentation says "a playbook runs in order from top to bottom" and tasks within a play do the same. It is agentless — "there are no servers, daemons, or databases required" — and it keeps no state file at all, which means no prior state to diff against, no plan equivalent, and no notion of resources Ansible owns.

Idempotence is an aspiration, not an engine guarantee. Red Hat's own wording: most modules check whether the desired state has been achieved, "however, not all playbooks and not all modules behave this way." The Galaxy API reports 4,557 published collections and 37,800 roles. The licence is GPL v3. Current versions are Ansible Automation Platform 2.7, generally available on 10 June 2026, and ansible-core 2.21.4 from 8 September 2026. Note that ansible.com now redirects to Red Hat's site.

Best for: Configuration management, OS-level provisioning and orchestrating other tools — not as your primary cloud provisioner.

Pros

  • Agentless over SSH, with modules copied over and removed after execution — nothing persistent to install or patch on managed hosts.
  • No state file to lose, corrupt or leak secrets into, which sidesteps the biggest operational hazard in this whole category.
  • GPL v3, with a large collection ecosystem covering cloud, network and OS-level tasks.
  • YAML playbooks are approachable for operators who are not software engineers.

Cons

  • No plan or preview worth relying on. Red Hat states "check mode is just a simulation," that it does not account for unexpected command failures or cascade effects, and that you should "not substitute it for a good staging environment."
  • Idempotence is the module author's responsibility, not the engine's — Red Hat's developer guidance urges authors to "strive for" it and, failing that, to "document the behavior."
  • Default parallelism is five forks, and the pipelining optimisation that helps most "conflicts with privilege escalation" and is off by default. Red Hat's own FAQ advises against managing a fleet from your laptop.
  • Vault has documented limits: it "ONLY protects data at rest," always decrypts entire files, and you "cannot rekey encrypted variables."
  • Windows cannot be a control node — an API limitation Red Hat states directly, and WSL is unsupported for that role.
  • No published list price. Red Hat names only Standard and Premium tiers with no figures; the only hard number is AWS Marketplace at $19,250 per 100-node pack for 12 months. RBAC, the controller UI, Event-Driven Ansible, audit trails and certified collections are all platform-gated.
  • Red Hat itself positions it as complementary, noting Ansible "can even act as an orchestrator of other popular provisioning tools like HashiCorp Terraform."
Red Hat Ansible Automation Platform automation dashboard
Image: Red Hat

6. Crossplane

Crossplane inverts the model. Instead of running a CLI that converges infrastructure and exits, it installs into a Kubernetes cluster and runs controllers that reconcile continuously — "if your software ever drifts from your desired state, the control plane automatically corrects the drift." Cloud resources become Kubernetes custom resources; platform teams compose them into higher-level APIs their developers consume.

It graduated from the CNCF on 28 October 2025, announced the following week, having been accepted in June 2020 and reaching incubation in 2021. Crossplane v2.0 shipped on 14 August 2025, making composite and managed resources namespaced, allowing composition of any Kubernetes resource, and adding Operations for scheduled and event-driven work. Claims were removed. Current release is v2.4.2, 22 September 2026. Licence is Apache 2.0.

One thing worth knowing: the official AWS, Azure and GCP providers are generated from Terraform providers by Crossplane's own Upjet tool, whose README says it powers them "along with 50+ community providers" and provides "Terraform state management" in its runtime.

Best for: Platform teams already running Kubernetes who want to publish self-service infrastructure APIs with continuous reconciliation.

Pros

  • Continuous drift correction is built in and free — no scheduled plan runs, no paid health assessments.
  • Apache 2.0 and CNCF-graduated, with vendor-neutral governance and third-party security audits as a condition of graduation.
  • Composing custom APIs for developers is genuinely better than handing them modules, if you have the platform team to build them.
  • Composition functions can be written in YAML, KCL, Python or Go rather than one bespoke language.

Cons

  • Kubernetes is a hard prerequisite. You must run, secure, upgrade and pay for a cluster before managing your first resource — against a single binary for Terraform or OpenTofu.
  • There is no plan equivalent. No plan, diff or --dry-run command exists. crossplane composition render runs compositions locally against mocked inputs whose schema "isn't validated" — useful, but it does not diff desired state against live cloud state.
  • v2's headline feature is still incomplete. The docs state namespaced managed resources are "fully available in Crossplane v2" for AWS, with maintainers "actively working to update managed resources for other systems including Azure, GCP, Terraform, Helm, GitHub" — thirteen months after v2.0.
  • Cluster-scoped managed resources are now a legacy feature that "Crossplane will deprecate and remove… at a future date," with no date published.
  • Connection secrets are plain Kubernetes Secrets, including usernames and passwords.
  • Nine-month support windows with no response-time SLA, plus 17-plus feature flags on the install page and several subsystems still alpha.
  • CNCF's own metrics show decline. LFX Insights currently rates project health "Fair (62)" with contributors down 7% and contributing organisations down 15% year over year — unusual for a project that graduated less than a year ago.
  • Heavy Upbound concentration: Upbound created the project, employs founding maintainers, runs the dominant registry and authors the Upjet-generated official providers. Its commercial tier starts at $1,000/month.
Crossplane Upjet build-time and runtime architecture diagram showing Terraform provider derivation
Image: Crossplane

7. Spacelift

Spacelift is not an IaC language and does not pretend to be. It describes itself as "an infrastructure-as-code orchestration platform that automates plans, applies, policy checks, and drift detection while keeping full auditability," and its Series C post put it bluntly: "our goal isn't to reinvent Terraform or Ansible — it's to help teams manage them reliably at scale." It supports nine tools, including OpenTofu, Terraform, Pulumi, CloudFormation, Ansible, AWS CDK and Terragrunt.

Policy runs on Open Policy Agent and Rego, so governance rules are portable even though the platform is not. It offers an optional managed state backend on S3 with one-off credentials per run. The company was founded in 2020, states $82.3 million raised over four rounds — most recently a $51 million Series C led by Five Elms Capital in July 2025 — and reports 948 customers and 107 employees. In February 2026 it made OpenTofu the default tool for new Terragrunt stacks, a notable signal. The core product has been renamed Spacelift Deploy.

Best for: Organisations with many teams running IaC who need policy enforcement, RBAC and drift detection across all of it.

Pros

  • Tool-agnostic across nine IaC tools, so you are not forced to standardise on one to get governance.
  • Policy as code on OPA/Rego — an open, portable standard rather than a proprietary rules language.
  • Managed state, drift detection, approval workflows and audit trails without building them yourself in CI.
  • Self-hosted, FedRAMP-authorised and air-gapped deployment options exist for regulated buyers.

Cons

  • The orchestration engine is proprietary. Across roughly 100 public repositories, none is the backend — you can read the CLI and Terraform provider (MIT) but cannot fork or self-build the platform.
  • Exactly one price is published: $20,000 per year for Starter+. Business, Enterprise, Enterprise+ and Spacelift Intelligence are all quote-only, so you cannot model cost past a single private worker.
  • SSO/SAML, SCIM, MFA and audit trail are Enterprise-only — baseline security controls behind the top tiers. Self-hosting requires Enterprise+, the highest tier, with no public price.
  • Drift detection has a hidden prerequisite: it works only on private workers, so free-tier users cannot use the feature Spacelift markets most heavily.
  • Annual lock-in is strict. Its terms state that after 14 days a plan cannot be cancelled, and "if the software has been activated, the plan can not be canceled."
  • An extra vendor in the deploy path. Runs auto-terminate after 30 days, queued runs are cancelled after two to seven days, and worker limits are contractual with usage notifications at 80% and 100%.
  • Breaking changes at a real clip, including the sunset of AWS IoT Core worker communication at the end of 2026, plus naming churn: three policy types deprecated and the core product renamed.
  • Small scale for something in production deploys — 107 employees against a critical-path dependency.
Spacelift console showing a list of infrastructure as code stacks
Image: Spacelift

How to choose

If you are starting fresh and multi-cloud: Terraform, unless your legal team objects to BUSL. The ecosystem advantage is large enough that the licence is the only real argument against it.

If BUSL is a blocker, or you want encrypted state without paying: OpenTofu. Accept that you have no managed control plane and no vendor to call, and that adopting its unique features makes your code non-portable back to Terraform.

If your team writes good software and hates HCL: Pulumi. Price the Pro tier, not the Essentials tier, because SSO lives there — and read the state documentation on physical IDs before you store anything sensitive.

If you are all-in on AWS: CDK and CloudFormation, and stop shopping. Managed state is worth more than most teams realise. Just know that drift detection has silent gaps on exactly the policy resources you would most want watched.

If you need to configure machines rather than create them: Ansible, alongside a real provisioner. Using it as your only IaC tool means giving up state and previews.

If you run Kubernetes and want to publish platform APIs: Crossplane — with a platform team that can absorb a cluster dependency and the absence of a plan command.

If your problem is governance across tools you already use: Spacelift, or one of its competitors. Budget for Enterprise if you need SSO, and confirm the private-worker requirement for drift detection.

One cross-cutting warning: every tool here except Ansible and CloudFormation writes secrets into state, and several document it explicitly. Treat state storage as a security boundary and encrypt it — OpenTofu does this natively, everyone else expects you to solve it at the backend.

Related reading: our top 7 CI/CD tools covers where IaC runs get executed, internal developer platforms covers the self-service layer above it, and observability and APM tools covers how you find out the deploy broke something.

Frequently Asked Questions

What is infrastructure as code?

Infrastructure as code is the practice of defining servers, networks, databases and other cloud resources in machine-readable configuration files kept in version control, then applying those files to create and update real infrastructure. It replaces manual console work with reviewable, repeatable, auditable changes.

What are infrastructure as code tools?

The main infrastructure as code tools are Terraform and its fork OpenTofu, Pulumi, AWS CloudFormation with the AWS CDK, Crossplane, and Ansible for configuration management. Orchestration platforms such as Spacelift sit above them, adding policy enforcement, drift detection and access control across whichever tools you already run.

Is Terraform infrastructure as code?

Yes — Terraform is the most widely used infrastructure as code tool. You declare resources in HCL, Terraform builds a dependency graph, shows a plan of what will change, then applies it. It records what it created in a state file and uses that to work out future changes. Versions 1.6 and later are BUSL-licensed.

Is Ansible infrastructure as code?

Partly. Ansible can provision cloud resources, but it is procedural rather than declarative and keeps no state file, so it has no true plan step and no record of what it owns. It is better understood as configuration management. Most teams pair it with Terraform, OpenTofu or CloudFormation.

Is Kubernetes infrastructure as code?

Kubernetes manifests are declarative configuration, so managing them in Git is an infrastructure-as-code practice. Kubernetes itself does not provision cloud infrastructure outside the cluster, though Crossplane extends its control plane to do exactly that, turning cloud resources into Kubernetes custom resources reconciled by controllers.


Editor's note — sources: the Terraform LICENSE file, state and sensitive-data docs and HCP workspace health documentation, plus IBM's SEC filings for the acquisition figures; OpenTofu's 1.8 release post, FAQ and MPL 2.0 licence, and the Linux Foundation announcement; Pulumi's pricing and secrets documentation; AWS's CDK developer guide, CloudFormation pricing page and IaC tool-selection guidance; Red Hat's playbook documentation and Ansible Automation Platform pricing page; the CNCF Crossplane project page, Crossplane docs and the Upjet README; Spacelift's pricing page, docs and changelog. Provider, module and star counts were read from each project's public API on 29 September 2026. All pricing and feature claims verified as of September 2026.

Get Edgewisely in your inbox

Business stories that matter, free. Enter your email — no password, no account to set up.
jamie@example.com
Subscribe