tacos.guru
tacos.guru holds Terraform automation platforms to one list of criteria. This page answers that list for terragucci, with each answer proven by a passing smoke claim on the validation page.
tacos.guru has not scored terragucci, and this page claims no score from it.
Two blocks carry no claim. The dashed one, RBAC and SSO, stays with your forge, which already decides who signs in and who may approve a merge (Access and identity). Pricing, outlined, has nothing to prove: terragucci is Apache-2.0 and runs in your CI. Hover or tap a block for its criterion.
CDK Terrain synth in CI, plans of the synthesized stacks
proven by a claim
OpenTofu and Terraform, each root on its own pinned version
proven by a claim
every job runs in your CI's runners, in an image you can extend
proven by a claim
left to your forge: its sign-in, SSO and permissions decide who can merge and approve
the forge's, by design
waves in dependency order, downstream roots planned on real unknowns
proven by a claim
scheduled drift checks that open an issue, a pull request or a tip
proven by a claim
short-lived cloud credentials through OIDC, a role per environment
proven by a claim
Apache-2.0 and self-hosted: no plan, seat or run to pay for
Apache-2.0, nothing hosted
backend, provider and version files generated from one source
proven by a claim
state roles per environment, gated export, versions and moves between roots
proven by a claim
terragucci import atlantis converts atlantis.yaml and digger.yml
proven by a claim
custom steps before and after each stage, and custom job images
proven by a claim
a private module registry served from your bucket
proven by a claim
cost per plan in the note, in policy input, and as an approval threshold
proven by a claim
OPA or conftest over every plan, from a policy source you choose
proven by a claim
an AI review of the pull request's intent against its plan
proven by a claim
approve and decline from Slack or Teams, with the approver's identity checked
proven by a claim
plan and apply from pull request comments on GitHub, GitLab and Forgejo
proven by a claim
traces, metrics, webhooks and an audit trail of every run
proven by a claim
dependency graph, blast radius and run timeline on the estate page
proven by a claim
a read-only MCP server over the estate, and an agent that drafts drift fixes
proven by a claim
an environment per pull request, destroyed after its TTL
proven by a claim
a Terraform provider for the control repo's projects and defaults
proven by a claim
AWS, Google Cloud and Azure: OIDC roles and report buckets on each
proven by a claim
- proven by a claim (71)
- the forge's, by design (5)
- Apache-2.0, nothing hosted (4)
Evaluation
Section titled “Evaluation”tacos.guru is an independent evaluator of TACOs (Terraform automation and collaboration software). It scores each platform from the vendor’s public documentation. Its data, evaluation.json, is the September 2026 dataset, and its page lets you change each weight and the pricing inputs and re-ranks the platforms as you do.
| Part | Meaning |
|---|---|
| Criteria | 24 features, each with a short description of what it asks |
| Category | Critical, High, Medium, Low or Nice-to-have; it sets the default weight from 5 down to 1 |
| Weight | the default from the category; you set each from 0 to 5 |
| Score | 0 None, 1 Limited, 2 Good, 3 Excellent, with a rationale per platform |
| Variants | chat is scored for Slack and Teams, version control for GitHub, GitLab, Bitbucket and Azure DevOps; you pick which counts |
| Pricing | a calculator of team size, resources, runs and states; a monthly cost up to $750 scores 3, up to $2,500 scores 2, up to $7,500 scores 1, quote-only 1, higher 0 |
| Gates | five pass or fail checks; a platform that fails one is marked disqualified and sorts below every platform that passes |
A platform’s result is its weighted share of a perfect score:
score = sum(score × weight) / sum(3 × weight) × 100%Criteria
Section titled “Criteria”A 3 below is what tacos.guru’s description of the criterion asks for. The terragucci column links the page that shows it and names the claims that prove it on the validation page.
| # | Criterion | Weight | A 3 | terragucci |
|---|---|---|---|---|
| 1 | CDK Terrain workflow | 5 | synth before plan; plan only the stacks a TypeScript change reaches | synth runs before check and plan, and a pull request plans only the stacks it changes. cdktn-synth, cdktn-affected |
| 2 | OpenTofu support | 5 | OpenTofu first-class, its version pinned per stack | OpenTofu is the default binary. A root’s .opentofu-version, .terraform-version or exact required_version picks its version, installed in the job and checked against the release’s SHA256SUMS (guide). root-pins, pinned-install |
| 3 | Self-hosted runners (no K8s required) | 5 | runners in your account; your own images | every stage is a job in your CI, on its runners, hosted or your own, picked by label per stage with runner, in the published image or one you build on it (architecture, image). boot, image, runner-label |
| 4 | RBAC & SSO | 5 | SAML or OIDC sign-in; roles by team and environment | no accounts and no login: sign-in is your forge’s and roles are forge permissions plus cloud IAM. See Access and identity |
| 5 | Linked-state orchestration | 5 | linked states deployed as one unit: a DAG, real unknowns across states, ordered applies, progress and gates | waves order the applies, each behind its gate; a root plans on its upstream’s planned outputs, unknown where unknown, and plans again once the upstream applies; the run view shows each wave’s state (linked roots). linked-plan, linked-states, waves |
| 6 | Drift detection | 4 | scheduled, per stack, with remediation | a scheduled run per root opens and closes the drift issue, and turns drift on a literal into a pull request (guide). drift, drift-close, respond-drift |
| 7 | Cloud credentials (OIDC) | 4 | short-lived cloud credentials per stack, no static keys | each job trades the forge’s OIDC token for a plan or apply role, per root glob with oidc.roles, on AWS, GCP and Azure (credentials). forgejo-oidc, report-oidc, oidc-clouds |
| 8 | Pricing suitability | 4 | a low monthly cost at the calculator’s inputs | Apache-2.0, with no license fee and nothing hosted; you pay for your CI minutes and your bucket |
| 9 | Repo scaffolding & codegen | 4 | backend, provider and workspace boilerplate from one declarative source | terragucci generate writes each root’s backend, provider and version files from repo, glob and root settings, and tf-check refuses a hand edit (guide). generate |
| 10 | State governance & RBAC | 4 | state access isolated per environment, fine-grained roles, export, cross-state tracking | a role per environment scoped to its state keys (guide), an approved and audited export, cross-state edges, state versions and migrations. state-roles, state-export, state-edges, state-versions, migrate-split |
| 11 | Migration from Atlantis | 3 | a documented path, atlantis.yaml import or comment compatibility |
terragucci import atlantis and import digger write terragucci.yml, and atlantis plan and atlantis apply comments work behind a setting (guide). Teams on a hosted platform have guides too: HCP Terraform, Scalr or OTF, Spacelift or env zero. import-atlantis, comment-atlantis |
| 12 | Custom workflows, hooks & gates | 3 | any step before or after each stage, custom images, blocking gates | steps run before and after init, plan, apply and drift; a failing step stops the wave or holds it at the gate; image runs a root’s jobs in your own image. steps-before-plan, steps-stop, steps-gate, image |
| 13 | Private module registry | 3 | a monorepo-friendly Terraform and OpenTofu registry | each release is written as the module registry protocol to your bucket, with namespaces by tag prefix and tofu test before release (guide). module-registry, publish |
| 14 | Cost estimation | 3 | cost estimates on each pull request | Infracost figures in the plan note, in the policy input, and as a threshold that holds a wave at its gate (guide). cost-estimate, cost-gate, cost-policy |
| 15 | Policy as code | 3 | portable OPA and Rego on plans | conftest or OPA over each plan, HCP Terraform policy sets and policies.hcl, from the repo or a shared source at a pinned ref (reference). policy-opa, policy-hcl, policy-source |
| 16 | AI: trusted PR review | 3 | a model reviews a change’s intent against its plan, from default-branch instructions, on your own model | review.agent runs your model on the description, diff and plan with instructions from the default branch and no forge token; the note approves nothing (guide). review-agent, review-policy |
| 17 | Collaboration integration | 4 | interactive approvals in Slack and Teams | terragucci relay, in your cloud, records a Slack click or a Teams reply as the approver’s own approval; drift notices carry a re-plan button (guide). chat-approve, chat-approve-teams, chat-replan |
| 18 | VCS integration | 3 | plan comments and checks, merge gating, operations from comments | a plan note and status on each pull request, comment commands for plan and apply, on GitHub, GitLab and Forgejo (guide). Bitbucket and Azure DevOps get no pipeline. comment-plan, comment-apply, fork-no-plan |
| 19 | Observability | 3 | run events, metrics and audit to Datadog, OTel or webhooks | OpenTelemetry traces and metrics to any OTLP endpoint (guide), signed webhooks (event) and an audit trail. traces, metrics, notify-webhook, audit |
| 20 | Visualizations / graphs | 2 | resource and dependency graphs, deployment views | the estate page draws roots by wave with cross-project edges; the run view shows blast radius and a timeline (guide). estate-graph |
| 21 | AI: agentic ops & MCP | 2 | an MCP server, state context, agents that act on drift | terragucci mcp serves the estate read-only, and the drift agent opens a pull request that plans like any other. mcp-last-apply, drift-agent |
| 22 | Ephemeral environments | 1 | short-lived environments with a TTL | a copy of the named roots per pull request, destroyed through a planned destroy on close or when its TTL passes (guide). ephemeral-pr, ephemeral-ttl |
| 23 | Terraform provider | 1 | manage the platform through Terraform | the terragucci provider owns a control repo’s projects and defaults, and plans show each change (guide). You build it from the repository; its publication to the OpenTofu and Terraform registries is pending (#659). provider-project |
| 24 | Multi-cloud support | 1 | clouds beyond AWS | OIDC to AWS, GCP and Azure, and reports in S3, GCS or Azure Blob Storage (guide). oidc-clouds, blob-gcs, blob-azure |
| Gate | Checks | terragucci |
|---|---|---|
| G1 | no Kubernetes required | jobs in your CI; nothing to install in a cluster |
| G2 | self-hosted runners in your cloud account | your CI’s runners, wherever you run them |
| G3 | a CDK Terrain synth step before plan | the synth key (guide). cdktn-synth |
| G4 | actively maintained: recent releases, at least three active committers, the core team still on it | a judgement of the maintainers, not a feature, so this page makes no claim for it. The releases and commits are public |
| G5 | OpenTofu support (advisory) | the default binary. root-pins |
- Access and identity: the forge and cloud permissions that stand in for accounts and roles.
- Standards: the open standards terragucci reads and writes.
- Validation: every claim named here, with its result.
These docs count page views and clicks with PostHog. They set no cookies, store nothing in your browser, and send nothing when your browser asks not to be tracked.