Skip to content

tacos.guru

llms.txtlists every page for an agent

tacos.guru holds Terraform automation platforms to one list of criteria. This page answers that list for terragucci, with each answer proven by a passing smoke claim on the validation page.

tacos.guru has not scored terragucci, and this page claims no score from it.

Two blocks carry no claim. The dashed one, RBAC and SSO, stays with your forge, which already decides who signs in and who may approve a merge (Access and identity). Pricing, outlined, has nothing to prove: terragucci is Apache-2.0 and runs in your CI. Hover or tap a block for its criterion.

Each block is as wide as its criterion's default weight. 71 of 80 weight points rest on a passing smoke claim. tacos.guru scores each criterion 0 to 3 times its weight, 240 in all, and has not scored terragucci.
  • proven by a claim (71)
  • the forge's, by design (5)
  • Apache-2.0, nothing hosted (4)

tacos.guru is an independent evaluator of TACOs (Terraform automation and collaboration software). It scores each platform from the vendor’s public documentation. Its data, evaluation.json, is the September 2026 dataset, and its page lets you change each weight and the pricing inputs and re-ranks the platforms as you do.

Part Meaning
Criteria 24 features, each with a short description of what it asks
Category Critical, High, Medium, Low or Nice-to-have; it sets the default weight from 5 down to 1
Weight the default from the category; you set each from 0 to 5
Score 0 None, 1 Limited, 2 Good, 3 Excellent, with a rationale per platform
Variants chat is scored for Slack and Teams, version control for GitHub, GitLab, Bitbucket and Azure DevOps; you pick which counts
Pricing a calculator of team size, resources, runs and states; a monthly cost up to $750 scores 3, up to $2,500 scores 2, up to $7,500 scores 1, quote-only 1, higher 0
Gates five pass or fail checks; a platform that fails one is marked disqualified and sorts below every platform that passes

A platform’s result is its weighted share of a perfect score:

score = sum(score × weight) / sum(3 × weight) × 100%

A 3 below is what tacos.guru’s description of the criterion asks for. The terragucci column links the page that shows it and names the claims that prove it on the validation page.

# Criterion Weight A 3 terragucci
1 CDK Terrain workflow 5 synth before plan; plan only the stacks a TypeScript change reaches synth runs before check and plan, and a pull request plans only the stacks it changes. cdktn-synth, cdktn-affected
2 OpenTofu support 5 OpenTofu first-class, its version pinned per stack OpenTofu is the default binary. A root’s .opentofu-version, .terraform-version or exact required_version picks its version, installed in the job and checked against the release’s SHA256SUMS (guide). root-pins, pinned-install
3 Self-hosted runners (no K8s required) 5 runners in your account; your own images every stage is a job in your CI, on its runners, hosted or your own, picked by label per stage with runner, in the published image or one you build on it (architecture, image). boot, image, runner-label
4 RBAC & SSO 5 SAML or OIDC sign-in; roles by team and environment no accounts and no login: sign-in is your forge’s and roles are forge permissions plus cloud IAM. See Access and identity
5 Linked-state orchestration 5 linked states deployed as one unit: a DAG, real unknowns across states, ordered applies, progress and gates waves order the applies, each behind its gate; a root plans on its upstream’s planned outputs, unknown where unknown, and plans again once the upstream applies; the run view shows each wave’s state (linked roots). linked-plan, linked-states, waves
6 Drift detection 4 scheduled, per stack, with remediation a scheduled run per root opens and closes the drift issue, and turns drift on a literal into a pull request (guide). drift, drift-close, respond-drift
7 Cloud credentials (OIDC) 4 short-lived cloud credentials per stack, no static keys each job trades the forge’s OIDC token for a plan or apply role, per root glob with oidc.roles, on AWS, GCP and Azure (credentials). forgejo-oidc, report-oidc, oidc-clouds
8 Pricing suitability 4 a low monthly cost at the calculator’s inputs Apache-2.0, with no license fee and nothing hosted; you pay for your CI minutes and your bucket
9 Repo scaffolding & codegen 4 backend, provider and workspace boilerplate from one declarative source terragucci generate writes each root’s backend, provider and version files from repo, glob and root settings, and tf-check refuses a hand edit (guide). generate
10 State governance & RBAC 4 state access isolated per environment, fine-grained roles, export, cross-state tracking a role per environment scoped to its state keys (guide), an approved and audited export, cross-state edges, state versions and migrations. state-roles, state-export, state-edges, state-versions, migrate-split
11 Migration from Atlantis 3 a documented path, atlantis.yaml import or comment compatibility terragucci import atlantis and import digger write terragucci.yml, and atlantis plan and atlantis apply comments work behind a setting (guide). Teams on a hosted platform have guides too: HCP Terraform, Scalr or OTF, Spacelift or env zero. import-atlantis, comment-atlantis
12 Custom workflows, hooks & gates 3 any step before or after each stage, custom images, blocking gates steps run before and after init, plan, apply and drift; a failing step stops the wave or holds it at the gate; image runs a root’s jobs in your own image. steps-before-plan, steps-stop, steps-gate, image
13 Private module registry 3 a monorepo-friendly Terraform and OpenTofu registry each release is written as the module registry protocol to your bucket, with namespaces by tag prefix and tofu test before release (guide). module-registry, publish
14 Cost estimation 3 cost estimates on each pull request Infracost figures in the plan note, in the policy input, and as a threshold that holds a wave at its gate (guide). cost-estimate, cost-gate, cost-policy
15 Policy as code 3 portable OPA and Rego on plans conftest or OPA over each plan, HCP Terraform policy sets and policies.hcl, from the repo or a shared source at a pinned ref (reference). policy-opa, policy-hcl, policy-source
16 AI: trusted PR review 3 a model reviews a change’s intent against its plan, from default-branch instructions, on your own model review.agent runs your model on the description, diff and plan with instructions from the default branch and no forge token; the note approves nothing (guide). review-agent, review-policy
17 Collaboration integration 4 interactive approvals in Slack and Teams terragucci relay, in your cloud, records a Slack click or a Teams reply as the approver’s own approval; drift notices carry a re-plan button (guide). chat-approve, chat-approve-teams, chat-replan
18 VCS integration 3 plan comments and checks, merge gating, operations from comments a plan note and status on each pull request, comment commands for plan and apply, on GitHub, GitLab and Forgejo (guide). Bitbucket and Azure DevOps get no pipeline. comment-plan, comment-apply, fork-no-plan
19 Observability 3 run events, metrics and audit to Datadog, OTel or webhooks OpenTelemetry traces and metrics to any OTLP endpoint (guide), signed webhooks (event) and an audit trail. traces, metrics, notify-webhook, audit
20 Visualizations / graphs 2 resource and dependency graphs, deployment views the estate page draws roots by wave with cross-project edges; the run view shows blast radius and a timeline (guide). estate-graph
21 AI: agentic ops & MCP 2 an MCP server, state context, agents that act on drift terragucci mcp serves the estate read-only, and the drift agent opens a pull request that plans like any other. mcp-last-apply, drift-agent
22 Ephemeral environments 1 short-lived environments with a TTL a copy of the named roots per pull request, destroyed through a planned destroy on close or when its TTL passes (guide). ephemeral-pr, ephemeral-ttl
23 Terraform provider 1 manage the platform through Terraform the terragucci provider owns a control repo’s projects and defaults, and plans show each change (guide). You build it from the repository; its publication to the OpenTofu and Terraform registries is pending (#659). provider-project
24 Multi-cloud support 1 clouds beyond AWS OIDC to AWS, GCP and Azure, and reports in S3, GCS or Azure Blob Storage (guide). oidc-clouds, blob-gcs, blob-azure
Gate Checks terragucci
G1 no Kubernetes required jobs in your CI; nothing to install in a cluster
G2 self-hosted runners in your cloud account your CI’s runners, wherever you run them
G3 a CDK Terrain synth step before plan the synth key (guide). cdktn-synth
G4 actively maintained: recent releases, at least three active committers, the core team still on it a judgement of the maintainers, not a feature, so this page makes no claim for it. The releases and commits are public
G5 OpenTofu support (advisory) the default binary. root-pins
  • Access and identity: the forge and cloud permissions that stand in for accounts and roles.
  • Standards: the open standards terragucci reads and writes.
  • Validation: every claim named here, with its result.

terragucci

These docs count page views and clicks with PostHog. They set no cookies, store nothing in your browser, and send nothing when your browser asks not to be tracked.