{
 "researched": "2026-09",
 "criteria": [
  {
   "id": 1,
   "name": "CDK Terrain workflow",
   "short": "CDK Terrain",
   "category": "critical",
   "defaultWeight": 5,
   "maxWeight": 5,
   "description": "Synth before plan; plan only stacks a TS change affects"
  },
  {
   "id": 2,
   "name": "OpenTofu support",
   "short": "OpenTofu",
   "category": "critical",
   "defaultWeight": 5,
   "maxWeight": 5,
   "description": "First-class, version pinned per stack"
  },
  {
   "id": 3,
   "name": "Self-hosted runners (no K8s required)",
   "short": "Runners",
   "category": "critical",
   "defaultWeight": 5,
   "maxWeight": 5,
   "description": "EC2/Docker runners in your account; rootless image builds"
  },
  {
   "id": 4,
   "name": "RBAC & SSO",
   "short": "RBAC/SSO",
   "category": "critical",
   "defaultWeight": 5,
   "maxWeight": 5,
   "description": "SAML/OIDC SSO, team- and env-scoped roles"
  },
  {
   "id": 5,
   "name": "Linked-state orchestration",
   "short": "Orchestration",
   "category": "critical",
   "defaultWeight": 5,
   "maxWeight": 5,
   "description": "Deploy linked states as one unit: DAG, real unknowns across states, ordered applies, progress UI & gates"
  },
  {
   "id": 6,
   "name": "Drift detection",
   "short": "Drift",
   "category": "high",
   "defaultWeight": 4,
   "maxWeight": 5,
   "description": "Scheduled, per stack, with remediation"
  },
  {
   "id": 7,
   "name": "Cloud credentials (OIDC)",
   "short": "OIDC",
   "category": "high",
   "defaultWeight": 4,
   "maxWeight": 5,
   "description": "Short-lived AWS/cloud creds per stack, no static keys"
  },
  {
   "id": 8,
   "name": "Pricing suitability",
   "short": "Pricing",
   "category": "high",
   "defaultWeight": 4,
   "maxWeight": 5,
   "description": "Computed from the pricing calculator at your inputs"
  },
  {
   "id": 9,
   "name": "Repo scaffolding & codegen",
   "short": "Scaffolding",
   "category": "high",
   "defaultWeight": 4,
   "maxWeight": 5,
   "description": "Generate backend/provider/workspace boilerplate from one declarative source"
  },
  {
   "id": 10,
   "name": "State governance & RBAC",
   "short": "State",
   "category": "high",
   "defaultWeight": 4,
   "maxWeight": 5,
   "description": "Env-isolated state access, fine-grained RBAC, export, cross-state tracking"
  },
  {
   "id": 11,
   "name": "Migration from Atlantis",
   "short": "Migration",
   "category": "medium",
   "defaultWeight": 3,
   "maxWeight": 5,
   "description": "Documented path, atlantis.yaml import or PR-comment compat"
  },
  {
   "id": 12,
   "name": "Custom workflows, hooks & gates",
   "short": "Workflows",
   "category": "medium",
   "defaultWeight": 3,
   "maxWeight": 5,
   "description": "Arbitrary pre/post steps, custom images, blocking gates"
  },
  {
   "id": 13,
   "name": "Private module registry",
   "short": "Registry",
   "category": "medium",
   "defaultWeight": 3,
   "maxWeight": 5,
   "description": "Monorepo-friendly TF/OpenTofu registry"
  },
  {
   "id": 14,
   "name": "Cost estimation",
   "short": "Cost Est.",
   "category": "medium",
   "defaultWeight": 3,
   "maxWeight": 5,
   "description": "PR-level cost estimates"
  },
  {
   "id": 15,
   "name": "Policy as code",
   "short": "Policy",
   "category": "medium",
   "defaultWeight": 3,
   "maxWeight": 5,
   "description": "Portable OPA/Rego on plans > proprietary policy languages"
  },
  {
   "id": 16,
   "name": "AI: trusted PR review",
   "short": "AI Review",
   "category": "medium",
   "defaultWeight": 3,
   "maxWeight": 5,
   "description": "Native LLM review of PR intent + plan; instructions from the default branch; bring your own model"
  },
  {
   "id": 17,
   "name": "Collaboration integration",
   "short": "Collab",
   "category": "high",
   "defaultWeight": 4,
   "maxWeight": 5,
   "description": "Slack / MS Teams: interactive approvals > rich notifications > webhooks",
   "variants": [
    {
     "id": "slack",
     "label": "Slack"
    },
    {
     "id": "teams",
     "label": "MS Teams"
    }
   ],
   "defaultVariant": "teams"
  },
  {
   "id": 18,
   "name": "VCS integration",
   "short": "VCS",
   "category": "medium",
   "defaultWeight": 3,
   "maxWeight": 5,
   "description": "PR comments/checks, merge gating, PR-driven ops",
   "variants": [
    {
     "id": "github",
     "label": "GitHub"
    },
    {
     "id": "gitlab",
     "label": "GitLab"
    },
    {
     "id": "bitbucket",
     "label": "Bitbucket"
    },
    {
     "id": "azure_devops",
     "label": "Azure DevOps"
    }
   ],
   "defaultVariant": "github"
  },
  {
   "id": 19,
   "name": "Observability",
   "short": "Observability",
   "category": "medium",
   "defaultWeight": 3,
   "maxWeight": 5,
   "description": "Run events, metrics & audit to Datadog/OTel/webhooks"
  },
  {
   "id": 20,
   "name": "Visualizations / graphs",
   "short": "Viz",
   "category": "low",
   "defaultWeight": 2,
   "maxWeight": 5,
   "description": "Resource & dependency graphs, deployment views"
  },
  {
   "id": 21,
   "name": "AI: agentic ops & MCP",
   "short": "AI Agents",
   "category": "low",
   "defaultWeight": 2,
   "maxWeight": 5,
   "description": "MCP server, state context, agents that act on drift"
  },
  {
   "id": 22,
   "name": "Ephemeral environments",
   "short": "Ephemeral",
   "category": "nice",
   "defaultWeight": 1,
   "maxWeight": 5,
   "description": "Short-lived environments / TTL"
  },
  {
   "id": 23,
   "name": "Terraform provider",
   "short": "TF Provider",
   "category": "nice",
   "defaultWeight": 1,
   "maxWeight": 5,
   "description": "Manage the platform via Terraform"
  },
  {
   "id": 24,
   "name": "Multi-cloud support",
   "short": "Multi-cloud",
   "category": "nice",
   "defaultWeight": 1,
   "maxWeight": 5,
   "description": "Beyond AWS"
  }
 ],
 "gates": [
  {
   "id": "G1",
   "label": "No Kubernetes required"
  },
  {
   "id": "G2",
   "label": "Self-hosted runners in your cloud account"
  },
  {
   "id": "G3",
   "label": "Can run a CDK Terrain synth step before plan"
  },
  {
   "id": "G4",
   "label": "Actively maintained (recent releases, ≥3 active committers, core team still on it)"
  },
  {
   "id": "G5",
   "label": "OpenTofu support (advisory: scored under criterion 2, does not disqualify)"
  }
 ],
 "excluded": [
  {
   "name": "Terrakube",
   "url": "https://terrakube.io",
   "reason": "Requires Kubernetes (G1)"
  },
  {
   "name": "ops0",
   "url": "https://ops0.com",
   "reason": "Not a TACOS: cloud-security/governance SaaS with a thin Terraform run layer, no self-hosted runners"
  }
 ],
 "platforms": [
  {
   "id": "spacelift",
   "name": "Spacelift",
   "url": "https://spacelift.io",
   "icon": "Rocket",
   "color": "#4B6BFF",
   "scores": [
    2,
    3,
    2,
    2,
    2,
    3,
    3,
    2,
    2,
    2,
    2,
    3,
    2,
    2,
    3,
    1,
    1,
    3,
    2,
    3,
    2,
    1,
    3,
    3
   ],
   "rationales": [
    "Documented CDKTF via custom runner image + before_init synth hooks. Change triggers are path/glob or Rego push-policy based; no turbo-style affected detection.",
    "OpenTofu and Terraform both first-class, selectable and version-pinned per stack and per module; dedicated OpenTofu runner image.",
    "Docker workers on EC2 (official ASG module, HTTP long-poll). Custom images OK but runs are unprivileged containers; in-run container builds undocumented.",
    "Space-scoped RBAC with IdP group bindings and login policies. OIDC SSO on paid plans; SAML SSO and audit trail are Enterprise-only.",
    "Stack dependency DAG with output references, cycle rejection and ordered tracked runs. PR (proposed) runs ignore dependencies; no unknown-value planning.",
    "Scheduled per-stack drift detection on private workers, with notifications and optional auto-reconcile; granular drift RBAC added 2026.",
    "AWS integration assumes IAM roles per stack (read/write roles, external ID), optionally from the worker; OIDC tokens also available. No static keys.",
    "Starter+ ≈ $1,667/mo at the default calculator inputs",
    "No repo codegen for backend/provider boilerplate. Stacks can be declared via TF provider; Blueprints/Templates are UI self-service (Business+).",
    "Managed state with state import and external state access; space-level access, not resource-level; local dev plan/apply against managed state is limited.",
    "Atlantis-specific guides and PR comment commands, but the migration kit only automates Terraform Cloud exports.",
    "Before/after hooks for init, plan, apply, destroy; custom runner images; plan/approval policies can gate applies (e.g. a cosign verify hook).",
    "Private module registry with monorepo project roots, OpenTofu, tests and space sharing, but gated to Business tier and above.",
    "Infracost integration surfaces cost estimates in runs and PR feedback; no native pricing engine.",
    "Native OPA/Rego policies on plan, push, approval, trigger, login and notification events; policy library and sampling.",
    "AI run summaries and error explanation via Infra Assistant with BYOM (incl. Bedrock). No LLM PR-intent review or trusted-branch instructions found.",
    "Slack is interactive (confirm/discard runs). MS Teams and other chat are notification-policy webhooks only, no actions from chat.",
    "GitHub App with commit checks, PR plan comments, PR comment commands and push policies; GitLab similar; Bitbucket/Azure DevOps supported, thinner.",
    "Datadog run metrics via notification-policy webhook module; generic webhooks; audit trail webhook (Enterprise). No native OTel export.",
    "Resources view across stacks, stack dependency graph and run timelines built in.",
    "Remote MCP server exposes full GraphQL API and Intent tools with read/write scopes; Infra Assistant build mode. No agentic drift-fix PRs.",
    "No first-class ephemeral/TTL environments; scheduled stack deletion and example preview-env tooling only.",
    "Official spacelift-io/spacelift Terraform provider, actively released, covers stacks, policies, contexts, integrations, workers.",
    "Terraform, OpenTofu, Terragrunt, Pulumi, CloudFormation, Ansible, Kubernetes across AWS, Azure and GCP."
   ],
   "variants": {
    "17": {
     "slack": 3,
     "teams": 1
    },
    "18": {
     "github": 3,
     "gitlab": 3,
     "bitbucket": 2,
     "azure_devops": 2
    }
   },
   "gates": {
    "G1": {
     "pass": true,
     "evidence": "Private workers run as Docker-based workers on EC2 VMs (official EC2 ASG module); Kubernetes workers are optional. SaaS control plane.",
     "url": "https://docs.spacelift.io/concepts/worker-pools/docker-based-workers"
    },
    "G2": {
     "pass": true,
     "evidence": "Private worker pools in customer AWS account (EC2 ASG module, Docker launcher); credentials can be generated on the worker via instance role. Requires Starter+ or above.",
     "url": "https://docs.spacelift.io/concepts/worker-pools"
    },
    "G3": {
     "pass": true,
     "evidence": "Documented CDKTF pattern: custom runner image with Node + before_init hooks running synth; arbitrary shell commands allowed in hooks.",
     "url": "https://docs.spacelift.io/vendors/terraform/cdktf"
    },
    "G4": {
     "pass": true,
     "evidence": "Weekly runner releases (runner-opentofu v1.0.0 2026-09-21), TF provider v1.55.0 2026-09-10, EC2 worker module v9.0.0 2026-09-22, active changelog.",
     "url": "https://docs.spacelift.io/product/changelog"
    },
    "G5": {
     "pass": true,
     "evidence": "OpenTofu is a first-class workflow tool per stack and module, with dedicated runner image.",
     "url": "https://github.com/spacelift-io/runner-opentofu/releases"
    }
   },
   "disqualified": false,
   "tagline": "Mature, policy-rich TACOS with EC2 workers; key features gated behind $20k+/yr tiers"
  },
  {
   "id": "env0",
   "name": "env zero",
   "url": "https://www.envzero.com",
   "icon": "Leaf",
   "color": "#00B389",
   "scores": [
    2,
    3,
    2,
    3,
    2,
    3,
    3,
    0,
    2,
    2,
    2,
    3,
    3,
    3,
    3,
    1,
    2,
    3,
    3,
    2,
    3,
    3,
    3,
    3
   ],
   "rationales": [
    "Custom flows can run pnpm/turbo synth before plan. Affected detection is only per-env glob triggers, with no native cdktn or turbo --affected support.",
    "OpenTofu is first-class and version-pinned per template; Terraform capped at MPL 1.5.x (BSL versions unsupported).",
    "Standalone Docker agent on EC2/ECS, no K8s, custom image. One deploy per container, no autoscaler, rootless builds unverified.",
    "SAML/OIDC SSO, SCIM, and custom roles scoped to org, project or environment, plus team sync and an audit log (audit on the top tier).",
    "Workflows: YAML DAG (needs), output passing, per-node approvals, live graph. PR plans run per sub-env on deployed outputs, no unknown-value plan.",
    "Per-environment cron drift detection with notifications, AI cause analysis, and auto-remediation that either redeploys or opens a PR.",
    "Native OIDC for AWS, Azure, GCP and Vault (v2 per-provider audience). Project-scoped creds; agents can use their instance or task role.",
    "Cloud Pilot ≈ $11,426/mo at the default calculator inputs",
    "env0-discovery.yml declares envs (triggers, PR plan, drift, remote backend) and auto-injects the backend. No provider/version codegen.",
    "Managed remote backend: per-role Read/Write State, state download, S3 self-hosted option, remote plan. Access is per workspace, not per resource.",
    "Atlantis-style PR comment commands (env0 plan/apply --all/--path), bulk import of existing TF dirs, and a migration blog/video. No atlantis.yaml import.",
    "Hooks before and after every init/plan/apply step. Non-zero exit fails the run and ENV0_REQUIRES_APPROVAL forces a gate, so cosign verify fits.",
    "Private module and provider registry backed by VCS tags, with monorepo tag-prefix support and module CI testing.",
    "Built-in Infracost cost estimation on plans, feeding OPA policy input and PR summaries. Documented under the Cloud Pilot cost-management tier.",
    "OPA/Rego approval policies on plan and cost input from a separate policy repo; Conftest in custom flows. Not enforced on PR plans.",
    "AI plan/apply summaries and error insights use the vendor's model. There is no documented BYO model and no PR-intent review from trusted instructions.",
    "Slack and MS Teams (via Teams Workflows webhook) get formatted event notifications, including drift. No interactive approvals in chat.",
    "PR plan comments and checks, PR-comment plan/apply gated on branch protection, commenter RBAC. GitHub, GitLab, Bitbucket, Azure DevOps.",
    "Native forwarding of deployment and audit logs to Datadog and 10 other sinks, signed CloudEvents webhooks, and an audit log API.",
    "Workflow DAG graph with live status, dashboards, Cloud Compass IaC-coverage views and Cloud Analyst charts. No resource dependency graph.",
    "Open-source MCP server (deploy/approve/logs/Compass), agent-ready CLI with skill install, Cloud Analyst chat, and drift remediation PRs.",
    "TTL policies, schedules, and automatic environment creation and teardown per pull request.",
    "Official env0/env0 Terraform/OpenTofu provider, actively released (v1.33.0, Sep 2026).",
    "AWS, Azure, GCP (and OCI) credentials. Runs OpenTofu, Terraform <=1.5, Terragrunt, Pulumi, CloudFormation, Helm, K8s and Ansible."
   ],
   "variants": {
    "17": {
     "slack": 2,
     "teams": 2
    },
    "18": {
     "github": 3,
     "gitlab": 3,
     "bitbucket": 3,
     "azure_devops": 3
    }
   },
   "gates": {
    "G1": {
     "pass": true,
     "evidence": "Two agent types documented: Kubernetes (Helm) and a standalone Docker agent (`docker run ghcr.io/env0/deployment-agent`), with ECS credential guidance. Kubernetes is not required; the old claim that self-hosting needs K8s is outdated.",
     "url": "https://docs.envzero.com/guides/admin-guide/self-hosted-kubernetes-agent/standalone-docker-agent"
    },
    "G2": {
     "pass": true,
     "evidence": "Self-hosted Docker agent runs in our AWS account, needs outbound-only internet, and can use the ECS task role via ADDITIONAL_ENV_VARS. Subscription docs say the agent is on every plan (1 on Free, unlimited on paid).",
     "url": "https://docs.envzero.com/guides/billing/subscription-tiers"
    },
    "G3": {
     "pass": true,
     "evidence": "Custom flows (env0.yml) run arbitrary sh/bash before or after init/plan/apply. The deployment image ships node 22/npm and allows sudo npm install, so pnpm/turbo cdktn synth can run before plan.",
     "url": "https://docs.envzero.com/guides/admin-guide/custom-flows"
    },
    "G4": {
     "pass": true,
     "evidence": "Actively maintained: terraform-provider-env0 v1.33.0 (2026-09-23), Helm agent chart v5.5.4 (2026-09-20), MCP server 1.1.2 (2026-09-02), docs changelog entries through Aug 2026.",
     "url": "https://docs.envzero.com/changelogs"
    },
    "G5": {
     "pass": true,
     "evidence": "OpenTofu is the default, first-class binary, with version pinning via template setting, ENV0_OPENTOFU_VERSION or .opentofu-version. env zero is an OpenTofu founding member.",
     "url": "https://docs.envzero.com/guides/admin-guide/templates/iac-binaries-versions"
    }
   },
   "disqualified": false,
   "tagline": "Formerly env0. Mature OpenTofu TACOS: Docker agents, Workflows DAG, OPA, drift; costly at 250 envs"
  },
  {
   "id": "scalr",
   "name": "Scalr",
   "url": "https://scalr.com",
   "icon": "Scale",
   "color": "#8B5CF6",
   "scores": [
    1,
    3,
    2,
    3,
    1,
    3,
    3,
    2,
    1,
    2,
    2,
    3,
    3,
    2,
    3,
    1,
    3,
    3,
    3,
    1,
    2,
    2,
    3,
    3
   ],
   "rationales": [
    "No native CDKTF/cdktn. Synth possible via pre-init/pre-plan hook + custom runner image; affected-stack detection only via hand-set trigger globs.",
    "OpenTofu is first-class and version-pinned per workspace; Terraform capped at MPL 1.5.x (BSL versions unsupported).",
    "Docker agent on EC2, ECS Fargate or serverless Lambda+Fargate; custom runner image. Docker driver needs socket; rootless builds undocumented.",
    "SAML SSO and SCIM on all plans, custom roles, access policies at account/env/workspace scope. Audit logs Enterprise-only.",
    "Run triggers fire downstream after upstream success, cross-env via federation. No DAG, no in-change multi-apply (except Terragrunt run-all/stacks).",
    "Scheduled per-env drift with tag/name filters and time windows, not billed; Teams/Slack alerts with Ignore/Sync/Revert actions.",
    "Native AWS OIDC provider configurations per env/workspace; agents can also use EC2/ECS role. No static keys needed.",
    "Business ≈ $1,881/mo at the default calculator inputs",
    "No codegen. No-code workspaces are UI deploys of registry modules; wiring can be declared via Scalr TF provider. Terragrunt stacks supported.",
    "Managed state with version history & export; state-versions:read gates human access per scope. No resource-level RBAC; own-S3 storage is Enterprise.",
    "Atlantis-style /scalr plan|apply PR comments and GitHub check actions; no atlantis.yaml import or dedicated migration guide.",
    "Hooks at pre-init..post-apply, non-zero exit fails run; hook registry, agent-level hooks, custom runner images. Available on all plans.",
    "Private module registry with monorepo tag prefixes, OCI sources, namespaces, module tests; plus private provider registry (2026).",
    "Native Infracost integration as a run phase with cost data exposed to OPA; requires Infracost API key.",
    "Native OPA/Rego pre-plan and post-plan checks, VCS-managed policy groups, advisory/soft/hard enforcement, impact analysis.",
    "Scalr AI (vendor-hosted Claude) explains errors and summarises plans/approvals to PRs. Plan-only input, no BYO model, no trusted instructions.",
    "Teams app: run approve/decline and drift remediation buttons with RBAC checks. Slack equivalent plus approval DMs. Google Chat via webhooks only.",
    "GitHub: PR comments, checks with Apply/Restart actions, comment-driven runs, merge-error gating. GitLab/ADO comments; checks GitHub-only.",
    "Datadog events, metrics integration and audit-log streaming; EventBridge and webhooks; agent OTel metrics/tracing. Audit streaming Enterprise.",
    "Visual Plan diff, metrics/runs digest and reports; no resource or workspace dependency graph.",
    "Remote MCP server (~50 RBAC tools, drift reports, run logs); writes limited to workspaces/variables. No agents opening remediation PRs.",
    "Ephemeral workspaces with TTL (1-14 days) auto-destroy; no PR-preview environments.",
    "Official Scalr Terraform provider (v3.19.0, Aug 2026) covering workspaces, triggers, hooks, policies, IAM, agent pools.",
    "Provider configurations for AWS, Azure, GCP plus any Terraform/OpenTofu provider."
   ],
   "variants": {
    "17": {
     "slack": 3,
     "teams": 3
    },
    "18": {
     "github": 3,
     "gitlab": 2,
     "bitbucket": 2,
     "azure_devops": 2
    }
   },
   "gates": {
    "G1": {
     "pass": true,
     "evidence": "Agent runs as a Docker service, on ECS Fargate/Cloud Run (local driver), or serverless via Lambda+Fargate; Kubernetes is optional.",
     "url": "https://docs.scalr.io/docs/installation"
    },
    "G2": {
     "pass": true,
     "evidence": "Self-hosted agent pools on Docker/EC2/Fargate in customer account; agent can use EC2 instance/ECS task role for AWS credentials; mTLS option.",
     "url": "https://docs.scalr.io/docs/agent-pools"
    },
    "G3": {
     "pass": true,
     "evidence": "pre-init/pre-plan hooks run arbitrary shell in the run container; custom runner image (SCALR_AGENT_CONTAINER_TASK_IMAGE) can bundle node/pnpm. No first-party CDKTF/cdktn docs; community example (hoo29/scalr-cdktf) uses a pre-plan synth hook. Needs POC.",
     "url": "https://docs.scalr.io/docs/hooks-1"
    },
    "G4": {
     "pass": true,
     "evidence": "Scalr Agent 1.7.0 released 2026-09-18; monthly SaaS release notes through September 2026; Terraform provider 3.19.0 (2026-08-21).",
     "url": "https://docs.scalr.io/docs/changelog"
    },
    "G5": {
     "pass": true,
     "evidence": "OpenTofu is first-class (per-workspace IaC platform, versions incl. 1.12.x). Note: Terraform is only supported up to 1.5.7 (MPL); newer versions must use OpenTofu.",
     "url": "https://docs.scalr.io/docs/iac-platform"
    }
   },
   "disqualified": false,
   "tagline": "Per-run TACO with OpenTofu, OPA, Teams approvals and hooks on every plan"
  },
  {
   "id": "terramate",
   "name": "Terramate",
   "url": "https://terramate.io",
   "icon": "Mountain",
   "color": "#F97316",
   "scores": [
    2,
    3,
    3,
    1,
    2,
    3,
    2,
    1,
    3,
    1,
    1,
    3,
    0,
    1,
    1,
    1,
    0,
    3,
    1,
    2,
    2,
    0,
    0,
    3
   ],
   "rationales": [
    "No CDK docs. Synth runs as a CI/script step; git change detection per stack dir plus stack `watch` files, so shared-TS-package affected detection is DIY.",
    "Terraform and OpenTofu both first-class incl. tofu plan files and .tofu files; binary/version per stack is set by you via codegen/scripts.",
    "Runs entirely in your own CI (e.g. GitHub Actions self-hosted EC2 runners); you own image and tooling, so rootless builds are possible. You run the runners.",
    "Cloud roles are admin/member only below Enterprise; RBAC, SAML 2.0 and audit logs are Enterprise-only. Apply rights live in your CI/GitHub settings.",
    "Explicit DAG (after/before/wants), ordered runs in one CI job, dependency selection flags. Output sharing is experimental and plans against mock values.",
    "Scheduled drift runs in your CI per stack/tag, synced to Cloud with alerts, AI explanations and reconciliation jobs. Alerts are Slack-only.",
    "No credential brokering; AWS OIDC comes from your CI (e.g. GitHub OIDC) with per-stack roles wired via codegen. No static keys needed.",
    "Enterprise — contact sales at the default calculator inputs",
    "generate_hcl/generate_file with hierarchical globals is a true fogg-style generator; Catalyst bundles/components/environments now in the OSS CLI.",
    "Does not manage state; keep your S3 backend with IAM isolation. No state RBAC, locking UI or export features; cross-state tracking only via outputs sharing.",
    "No Atlantis migration guide or atlantis.yaml import; `terramate create --all-terraform` can adopt existing root modules as stacks.",
    "Arbitrary commands in your CI plus Terramate Scripts with multi-job pre/post steps; custom gates (e.g. cosign verify) are straightforward.",
    "No private module registry; use Git sources or a third-party registry. Catalyst bundles can be sourced remotely but are not a module registry.",
    "No native cost estimation; Infracost can be run in your CI (docs list it as an integration).",
    "Cloud ships 500+ built-in CIS policies on resources/drift; custom OPA/Conftest on plan is DIY in your CI with no Cloud gating.",
    "AI Mate explains plans, failures and drift using vendor-chosen LLMs on all plans. No BYO model, no trusted instruction source.",
    "Slack app with targeted DMs and alerts; Microsoft Teams claimed on the docs landing page but undocumented. No generic webhooks.",
    "GitHub/GitLab first-class: PR previews, plan comments via your CI, conflict detection, safeguards. Bitbucket supported; Azure DevOps DIY only.",
    "Cloud dashboards and DORA metrics; no documented Datadog, OTel, webhook or audit-stream export. Audit logs Enterprise-only.",
    "Cloud stack/deployment/PR preview views and resource browser; CLI can print run order and dependency graphs.",
    "Open-source MCP server (read-only, local Docker) over stacks, drift, deployments, resources; agent skills repo. Autonomous agents not documented.",
    "No ephemeral environment lifecycle; environments/promote in Catalyst are long-lived.",
    "No Terraform provider for Terramate Cloud (Go SDK and API only).",
    "Tool-agnostic orchestrator: any cloud/provider Terraform, OpenTofu or Terragrunt can target."
   ],
   "variants": {
    "17": {
     "slack": 2,
     "teams": 0
    },
    "18": {
     "github": 3,
     "gitlab": 3,
     "bitbucket": 2,
     "azure_devops": 1
    }
   },
   "gates": {
    "G1": {
     "pass": true,
     "evidence": "CLI is a single Go binary run inside your own CI (GitHub Actions/GitLab/Bitbucket); Cloud is SaaS. No Kubernetes anywhere.",
     "url": "https://terramate.io/docs/how-it-works"
    },
    "G2": {
     "pass": true,
     "evidence": "Terramate has no runners of its own: all plan/apply runs in your CI, e.g. GitHub Actions self-hosted runners on EC2 in your AWS account. Terramate Cloud needs no cloud creds, state or source access; only sanitized plan/log data is synced.",
     "url": "https://terramate.io/docs/security/"
    },
    "G3": {
     "pass": true,
     "evidence": "Any command can run before plan via your CI workflow or Terramate Scripts (`terramate script run`), so pnpm/turbo cdktn synth is possible. No vendor docs or examples for CDKTF/cdktn.",
     "url": "https://terramate.io/docs/cli/orchestration/scripts"
    },
    "G4": {
     "pass": false,
     "evidence": "Fails. One engineer made every commit in the last 90 days; the founders now build to11 (an LLM platform); no maintainer reply on sampled issues opened Jun–Sep 2026.",
     "url": "https://github.com/terramate-io/terramate/releases"
    },
    "G5": {
     "pass": true,
     "evidence": "OpenTofu first-class: --tofu-plan-file for Cloud sync, .tofu extension support (v0.15.4), OpenTofu stdlib functions, OpenTofu quickstart.",
     "url": "https://terramate.io/docs/get-started/opentofu"
    }
   },
   "disqualified": true,
   "tagline": "OSS orchestrator + codegen in your own CI; fogg-grade generation, DIY pipelines"
  },
  {
   "id": "stategraph",
   "name": "Stategraph",
   "url": "https://stategraph.com",
   "icon": "Network",
   "color": "#06B6D4",
   "scores": [
    2,
    3,
    3,
    2,
    3,
    3,
    3,
    2,
    1,
    3,
    2,
    3,
    0,
    3,
    3,
    1,
    1,
    3,
    2,
    3,
    2,
    0,
    0,
    3
   ],
   "rationales": [
    "Native CDKTF engine plus custom pre-plan steps; affected detection via file_patterns/tree_builder scripts. IaaD: no terraform test, .tf.json support unverified.",
    "OpenTofu first-class in Orchestration. The Stategraph CLI runs tofu by default (TF_CMD). Engine version pinnable per workflow.",
    "Runs are GitHub Actions jobs; self-hosted EC2/Docker runners with custom images. No K8s. IaaD server never runs Terraform.",
    "Orchestration: GitHub/GitLab login, tag-scoped RBAC. Unified console adds OIDC sign-in (Sep 2026 changelog). SAML on pricing only; IaaD RBAC Enterprise.",
    "In-PR ordered layers; multi-state plan with real unknowns, applied as one atomic transaction; resource-level conflict checks, not project locks.",
    "Scheduled drift per tag query; opens a GitHub issue; optional auto-reconcile. More than one schedule per repo needs Enterprise (every hosted tier).",
    "Documented AWS OIDC setup plus an OIDC hardening guide; per-workflow and per-environment role selection.",
    "Professional ≈ $1,499/mo at the default calculator inputs",
    "config_builder, tree_builder, indexer and centralized config generate orchestrator config only. No backend/provider codegen like fogg.",
    "IaaD: Postgres state, plan/apply tokens scoped per state and resource pattern, OIDC group rules, SQL, tfstate export. RBAC is Enterprise-tier.",
    "Same PR-comment plan/apply model as Atlantis. Stategraph docs cover running under Atlantis; no atlantis.yaml import.",
    "Arbitrary pre/post hooks and workflow steps, custom engines, apply requirements. Gatekeeper approval gates (Enterprise, every hosted tier).",
    "No private module registry. The indexer only maps module usage to trigger runs.",
    "Built-in cost estimates on PRs with approval thresholds, incl. OpenInfraQuote (MPL-2.0, runs in CI, AWS-only). IaaD adds plan-time cost deltas.",
    "OPA/Rego, Conftest and Checkov are built in and run on plan output. Policies are portable.",
    "Native agent skills summarise state, blast radius and plan-time cost deltas with your own model, but on demand; no automated PR review.",
    "No native Slack, Teams or Google Chat integration. Notifications only via curl webhooks in hooks or workflow steps.",
    "GitHub and GitLab: PR comments, per-dirspace status checks, apply requirements, automerge. No Bitbucket or Azure DevOps.",
    "Self-hosted Prometheus /metrics, queryable audit trail and console audit view, hook webhooks. IaaD webhooks (Pro). No native Datadog/OTel export.",
    "IaaD Graph Explorer, blast radius and transaction timeline; console Stacks view shows apply order with live plan/apply state (Sep 2026).",
    "Documented SKILL.md skills drive the CLI/SQL API, with plan-only, resource-scoped agent tokens. No MCP server; no agent drift fixes or PRs.",
    "No ephemeral environment feature.",
    "No Terraform provider for Orchestration or Stategraph.",
    "AWS, GCP and Azure OIDC guides. Engine-agnostic: works with any Terraform/OpenTofu provider."
   ],
   "variants": {
    "17": {
     "slack": 1,
     "teams": 1
    },
    "18": {
     "github": 3,
     "gitlab": 3,
     "bitbucket": 0,
     "azure_devops": 0
    }
   },
   "gates": {
    "G1": {
     "pass": true,
     "evidence": "No Kubernetes required. The Orchestration server self-hosts via Docker Compose or the ECS/Fargate Terraform module. The IaaD server offers Compose, ECS, Cloud Run or K8s. Runs execute on GitHub Actions runners.",
     "url": "https://docs.terrateam.io/quickstart/self-hosted/aws/"
    },
    "G2": {
     "pass": true,
     "evidence": "Plans and applies run as GitHub Actions jobs, which can use self-hosted runners on EC2 or Docker. The IaaD server never runs Terraform and never sees cloud credentials. The CLI runs where you run it.",
     "url": "https://docs.terrateam.io/security/private-runners/"
    },
    "G3": {
     "pass": true,
     "evidence": "Custom workflow steps and hooks run arbitrary commands before init/plan, so a pnpm/turbo synth step works. There is a native CDKTF engine. The cdktn binary is not named in the docs, so it needs a custom run step.",
     "url": "https://docs.terrateam.io/integrations/iac-tools/cdktf/"
    },
    "G4": {
     "pass": true,
     "evidence": "Releases 3.0.0-3.0.3 between 2026-09-21 and 2026-09-27. Three humans visible committing in the last 90 days (Josh Pollara, Malcolm, Tamiya). The OSS repo is a Copybara export of a private monorepo, so the real count is likely higher.",
     "url": "https://github.com/stategraph/releases/releases"
    },
    "G5": {
     "pass": true,
     "evidence": "Advisory: pass. The Stategraph CLI runs tofu by default (TF_CMD, default tofu), and Orchestration supports OpenTofu natively. The IaaD engine is closed source, and self-hosting it needs Enterprise and a licence key, but the 'no OpenTofu' premise does not hold.",
     "url": "https://stategraph.com/docs/cli/tf"
    }
   },
   "disqualified": false,
   "tagline": "Formerly Terrateam. Ex-Terrateam GitOps plus a graph state engine; agent-ready via skills and scoped tokens"
  },
  {
   "id": "hcp-terraform",
   "name": "HCP Terraform",
   "url": "https://www.hashicorp.com/products/terraform",
   "icon": "Cloud",
   "color": "#7C3AED",
   "scores": [
    1,
    0,
    2,
    3,
    3,
    3,
    3,
    0,
    2,
    2,
    1,
    2,
    3,
    2,
    2,
    0,
    2,
    2,
    2,
    2,
    2,
    2,
    3,
    3
   ],
   "rationales": [
    "CDKTF deprecated by HashiCorp. Workspaces can synth in agent pre-plan hooks or CI; Stacks cannot run hooks. Affected detection only via trigger patterns.",
    "Terraform only. No OpenTofu version option for workspaces or Stacks as of Sep 2026.",
    "Self-hosted agents on Docker/EC2, custom images. Hooks max 10 min, not for Stacks; agent concurrency tier-limited (Standard 10).",
    "SAML SSO from Essentials, team/project permissions, SCIM, IP allowlists. Custom RBAC Premium-only.",
    "Stacks GA: component DAG, planning with unknowns/deferred changes, linked Stacks, per-deployment approvals. Custom auto-approve groups Premium.",
    "Health assessments (drift + continuous validation) on Standard/Premium, notifications on drift; remediation via new run.",
    "Dynamic provider credentials (OIDC) for AWS per workspace/Stack, separate plan/apply roles, quick setup added 2026.",
    "Standard ≈ $8,651/mo at the default calculator inputs",
    "No fogg-style codegen. Stacks declare providers/deployments once per stack; workspace wiring via tfe provider; no-code modules.",
    "Managed state, per-team state read/write permissions, state download as standard tfstate, restore. No resource-level RBAC.",
    "No Atlantis migration tooling; tf-migrate deprecated. Generic workspace and workspace-to-Stacks migration guides.",
    "Run tasks at 4 stages (org/project scope), agent hooks can fail runs (e.g. cosign gate). No arbitrary pipeline steps; hooks not for Stacks.",
    "Mature private registry with test-integrated and monorepo publishing, tagging. Terraform only; Essentials capped at 10 modules.",
    "Native cost estimation for AWS/Azure/GCP on Standard+. No Infracost-style PR comment.",
    "Native OPA/Rego and Sentinel policy sets, tfpolicy (HCL, beta, cloud-only). OPA input is HCP-specific; unlimited sets need Standard+.",
    "No native LLM plan summary or PR review. AI plan review only via third-party run tasks (e.g. Terracotta); official agent skills cover authoring.",
    "Teams and Slack formatted webhook notifications per workspace/project; no interactive approvals. Google Chat via generic webhook.",
    "GitHub, GitLab, Bitbucket, Azure DevOps VCS: commit status checks, speculative plans. No PR-comment plans or comment-driven ops.",
    "Official Datadog integration (audit logs, notification events, resource metadata), Metrics API. Audit trails need Premium.",
    "Explorer, Stacks deployment/component views, published-outputs inspector; Infragraph graph explorer in LA (US only).",
    "Terraform MCP server GA (self-hosted, state/run tools, writes gated), official agent skills and tfctl skill, Infragraph LA (US). No agent drift fixes or PRs.",
    "Ephemeral workspaces with auto-destroy schedules; Stacks destroy_all. Not a full preview-env product.",
    "Official hashicorp/tfe provider manages orgs, workspaces, Stacks, policies, teams.",
    "Provider-agnostic: any Terraform provider; dynamic credentials for AWS, Azure, GCP, Vault."
   ],
   "variants": {
    "17": {
     "slack": 2,
     "teams": 2
    },
    "18": {
     "github": 2,
     "gitlab": 2,
     "bitbucket": 2,
     "azure_devops": 2
    }
   },
   "gates": {
    "G1": {
     "pass": true,
     "evidence": "SaaS control plane; self-hosted agents run as a binary or Docker container on any Linux host (EC2 fine). K8s operator optional only.",
     "url": "https://developer.hashicorp.com/terraform/cloud-docs/agents/requirements"
    },
    "G2": {
     "pass": true,
     "evidence": "HCP Terraform agents run in your own network/account (Docker/EC2); agent pools per workspace/Stack; AWS-IA module for EC2 agents. Note concurrency: Free/Essentials 1 agent run, Standard 10.",
     "url": "https://developer.hashicorp.com/terraform/cloud-docs/agents"
    },
    "G3": {
     "pass": true,
     "evidence": "Workspaces: synth possible in agent pre-plan hook (arbitrary executable, non-zero exit fails run) or in CI with CLI-driven runs. Caveat: agent hooks do not support Stack workflows, so Stacks need synth in CI + config upload.",
     "url": "https://developer.hashicorp.com/terraform/cloud-docs/agents/hooks"
    },
    "G4": {
     "pass": true,
     "evidence": "Actively developed: HCP Terraform changelog has entries through 2026-09-16; TFE 2.0.5 Aug 2026.",
     "url": "https://developer.hashicorp.com/terraform/cloud-docs/changelog"
    },
    "G5": {
     "pass": false,
     "evidence": "Workspace/Stack settings only select Terraform (BSL) versions; no OpenTofu binary option announced or documented as of Sep 2026; OpenTofu cannot use HCP Terraform as a backend-runner platform.",
     "url": "https://developer.hashicorp.com/terraform/cloud-docs/workspaces/settings"
    }
   },
   "disqualified": false,
   "tagline": "Best-in-class Stacks orchestration and registry, but Terraform-only and RUM-priced"
  },
  {
   "id": "opentaco",
   "name": "OpenTaco",
   "url": "https://opentaco.dev",
   "icon": "Terminal",
   "color": "#10B981",
   "scores": [
    1,
    2,
    3,
    1,
    2,
    3,
    3,
    1,
    1,
    2,
    2,
    3,
    0,
    2,
    3,
    1,
    0,
    3,
    1,
    1,
    0,
    0,
    1,
    3
   ],
   "rationales": [
    "No CDKTF docs. You can add synth as a CI/run step, but generate_projects only finds .tf dirs, so cdktn stacks need hand-listed projects and include_patterns.",
    "OpenTofu is first-class ('opentofu: true' per project). The version is set via action inputs, so pinning per stack is weaker.",
    "Jobs run in your own GitHub Actions, on self-hosted EC2 runners with any image you like, so rootless builds work. No K8s and no vendor agent.",
    "Apply RBAC comes from GitHub teams plus OPA access policies. Self-hosted UI login needs WorkOS. State RBAC and OIDC SSO are CLI-only. No platform audit log.",
    "depends_on plus respect_layers gives layer-by-layer plan/apply in one PR. Statesman flags stale edges. No plan with unknowns; PR-comment UX only.",
    "Scheduled per-project drift runs via the service or backendless GHA. Alerts go to Slack or GitHub Issues, with issue-driven apply to remediate.",
    "Uses native GHA OIDC to AWS, with aws_role_to_assume per project for separate plan/apply roles. No static keys.",
    "Pro — contact sales at the default calculator inputs",
    "generate_projects only builds the project list from dir globs. It does not generate backend/provider boilerplate, so it is no fogg replacement.",
    "Self-hosted Statesman has TFE-compatible state, prefix-wildcard RBAC, versions/rollback, dependency edges. Dormant since Mar 2026; you run it.",
    "Same PR-comment plan/apply model as Atlantis, but with no atlantis.yaml import and no migration guide.",
    "Arbitrary run steps before/after init/plan/apply plus your own runner image. A failing step (e.g. cosign verify) blocks apply.",
    "No private module registry.",
    "Documented Infracost integration via a custom workflow step. Not native.",
    "Rego/OPA access, plan and drift policies are evaluated in the CLI, and conftest works as an inline step. Portable, no proprietary DSL.",
    "AI Summaries of multi-project plans are invite-only, vendor-run and undocumented beyond one page. No trusted-branch prompts, no bring-your-own model.",
    "Slack gets drift webhook notifications only. No MS Teams or Google Chat integration, and no interactive approvals.",
    "GitHub App: PR comments, checks, apply-before-merge, merge gating. GitLab/Bitbucket need an EE licence; Azure DevOps goes via an Azure Function.",
    "Logs live in GHA runs. No Datadog/OTel export, audit stream or run-event webhooks beyond the drift webhook.",
    "PR comments list impacted projects and layers. The basic UI lists projects and drift. No resource or dependency graph view.",
    "No MCP server and no agentic ops.",
    "No ephemeral environment feature.",
    "The opentaco provider manages Statesman units and dependency edges only. It cannot manage PR automation, drift or orgs.",
    "AWS, GCP and Azure are documented, each with OIDC and lock/plan storage."
   ],
   "variants": {
    "17": {
     "slack": 2,
     "teams": 0
    },
    "18": {
     "github": 3,
     "gitlab": 2,
     "bitbucket": 1,
     "azure_devops": 1
    }
   },
   "gates": {
    "G1": {
     "pass": true,
     "evidence": "Orchestrator/UI/drift/statesman self-host via Docker Compose, single Docker image, binary or Railway; Helm is optional. Jobs run in your CI, so no cluster is needed.",
     "url": "https://docs.opentaco.dev/self-hosting/docker-compose"
    },
    "G2": {
     "pass": true,
     "evidence": "Terraform runs inside your own GitHub Actions jobs. Docs recommend self-hosted GHA runners on EC2 (runs-on: my-selfhosted-runner). Cloud creds never leave the runner. Hosted orchestrator only dispatches workflows.",
     "url": "https://docs.opentaco.dev/ce/features/private-runners"
    },
    "G3": {
     "pass": true,
     "evidence": "You own the GHA workflow, so you can add setup-node/pnpm/turbo synth steps before the digger action runs. digger.yml workflows also support arbitrary 'run:' steps before init/plan.",
     "url": "https://docs.opentaco.dev/ce/howto/custom-commands"
    },
    "G4": {
     "pass": false,
     "evidence": "Fails. 7 commits in the last 90 days (0 in Aug 2026); the founders now build OpenComputer; 16 of 22 issues since April have no reply. Releases continue but are maintenance-only.",
     "url": "https://github.com/diggerhq/digger/releases"
    },
    "G5": {
     "pass": true,
     "evidence": "OpenTofu is first-class: set 'opentofu: true' per project and use the setup-opentofu/opentofu-version action inputs. There is a with-opentofu getting-started guide.",
     "url": "https://docs.opentaco.dev/ce/getting-started/with-opentofu"
    }
   },
   "disqualified": true,
   "tagline": "Formerly Digger. MIT-licensed PR automation in your own GitHub Actions; vendor focus has moved to AI agents"
  },
  {
   "id": "pulumi",
   "name": "Pulumi Cloud",
   "url": "https://www.pulumi.com",
   "icon": "Layers",
   "color": "#8A3391",
   "scores": [
    3,
    1,
    2,
    3,
    1,
    3,
    3,
    0,
    2,
    2,
    1,
    3,
    2,
    0,
    2,
    1,
    2,
    3,
    2,
    2,
    3,
    3,
    2,
    3
   ],
   "rationales": [
    "Requires migrating from CDK Terrain; Pulumi TS needs no synth. Per-stack path filters; shared TS package changes fan out via listed globs, not a dep graph.",
    "Pulumi programs don't run TF/OpenTofu. TF providers reused via bridge/Any TF Provider; no Pulumi-to-HCL or tfstate export, so exit is a re-migration.",
    "Customer-managed agents on EC2 with Docker, runner pools, custom executor images; Enterprise only; agent needs host Docker daemon; rootless builds unverified.",
    "SAML SSO and custom roles (Pro+), SCIM and unlimited roles (Enterprise), team/stack-scoped permissions, audit logs.",
    "Stack refs + deployment webhooks/Auto Deploy (preview) cascade after upstream apply; no DAG preview with unknowns or ordered multi-apply per change.",
    "Scheduled per-stack drift detection with remediate-drift runs and webhook/Teams alerts (Pro+; on own agents Enterprise).",
    "Native AWS OIDC in Deployments settings and via ESC environments per stack; no static keys.",
    "Enterprise ≈ $9,477/mo at the default calculator inputs",
    "Backend/provider boilerplate mostly disappears; templates, Automation API and pulumiservice provider wire stacks as code, but no fogg-style codegen.",
    "Managed encrypted state, per-stack team RBAC, local dev previews, CI-only prod via agents; export is Pulumi JSON not tfstate; no resource-level RBAC.",
    "Convert/import tools and Neo migration exist, but ~250 roots incl. CDK Terrain L2s need synth→convert→refactor; module resources skip bulk import.",
    "preRunCommands, custom executor images, env vars, policy packs and in-program checks allow arbitrary gates (e.g. cosign verify before up).",
    "Private Registry for Pulumi components/templates; components can be sourced from monorepo git paths; TF module registry also offered.",
    "No native PR cost estimation for Pulumi previews; Infracost does not natively support Pulumi.",
    "CrossGuard in TS/Python plus stable OPA/Rego analyzer over Pulumi resource inputs (not TF plan JSON); mandatory enforcement Pro+, remediation Enterprise.",
    "Neo reviews PRs natively, with BYO model on Enterprise only. PR-intent input and default-branch instructions are undocumented; would be 2 if intent is verified.",
    "Slack- and Teams-formatted webhooks for stack/deployment/drift events; notifications only, no interactive approvals in chat.",
    "GitHub app: PR preview comments, commit checks, review stacks, Neo reviews, policy results; GitLab/Azure DevOps/Bitbucket supported with fewer features.",
    "Audit log API and automated S3 export (Pro+), deployment/stack webhooks; no native Datadog or OTel integration.",
    "Per-stack resource graph, resource search, Insights, Context API graph (preview) across stacks and relationships.",
    "Neo agent acts on drift, opens PRs, runs previews; remote MCP server over stacks and resources.",
    "Review stacks per PR and TTL stacks with scheduled destroy.",
    "Platform fully manageable as code via the Pulumi Service Provider v1.0 (Pulumi-native); no official Terraform provider.",
    "AWS, Azure, GCP, Kubernetes and any bridged TF provider; ESC covers AWS/Azure/GCP dynamic creds."
   ],
   "variants": {
    "17": {
     "slack": 2,
     "teams": 2
    },
    "18": {
     "github": 3,
     "gitlab": 2,
     "bitbucket": 2,
     "azure_devops": 2
    }
   },
   "gates": {
    "G1": {
     "pass": true,
     "evidence": "Customer-managed agents run in Docker mode on a plain VM/bare-metal host ('requires only a Docker daemon on the host'); Kubernetes mode is optional. SaaS control plane. The Pulumi Kubernetes Operator is a separate, K8s-only product and is not needed.",
     "url": "https://www.pulumi.com/docs/deployments/deployments/customer-managed-agents/"
    },
    "G2": {
     "pass": true,
     "evidence": "Customer-managed agents (multiple runner pools, stacks assigned per pool, up to 150 concurrent workflows) run on EC2 with Docker inside our AWS account, so credentials stay in our boundary. This needs the Enterprise edition.",
     "url": "https://www.pulumi.com/docs/deployments/deployments/customer-managed-agents/"
    },
    "G3": {
     "pass": true,
     "evidence": "Passes because no synth step is needed after migration: Pulumi TypeScript programs run directly with no synth step. If a build is needed anyway, Deployments support preRunCommands and a custom executor image (pnpm/turbo), and dependency install is built in.",
     "url": "https://www.pulumi.com/docs/deployments/guides/custom-images/"
    },
    "G4": {
     "pass": true,
     "evidence": "CLI v3.264.0 was released 2026-09-23, with weekly releases. The changelog has entries through Sept 2026.",
     "url": "https://github.com/pulumi/pulumi/releases"
    },
    "G5": {
     "pass": false,
     "evidence": "Pulumi programs never run Terraform or OpenTofu. TF providers are reused via the bridge, but going back to OpenTofu would mean a second full migration. The engine is Apache-2.0 with self-managed state backends, so there's no licence lock-in.",
     "url": "https://www.pulumi.com/docs/iac/guides/migration/migrating-to-pulumi/from-terraform/"
    }
   },
   "disqualified": false,
   "tagline": "Migrate to Pulumi: strong platform on own EC2 agents, but costly and a full rewrite"
  },
  {
   "id": "terragrunt-scale",
   "name": "Terragrunt Scale",
   "url": "https://terragrunt.com/terragrunt-scale",
   "icon": "Blocks",
   "color": "#5B21B6",
   "scores": [
    1,
    3,
    3,
    1,
    2,
    2,
    3,
    1,
    3,
    2,
    1,
    2,
    1,
    2,
    1,
    0,
    0,
    2,
    1,
    1,
    0,
    1,
    0,
    2
   ],
   "rationales": [
    "No CDK Terrain support; synth possible via Terragrunt before_hook or forked workflow step. Affected detection only if units declare the TS files they read.",
    "OpenTofu is the Pipelines default; Terraform selectable. Versions pinned via .mise.toml; Terragrunt can pin binary/version per unit.",
    "Runs entirely in your own GitHub Actions/GitLab runners (self-hosted EC2 OK, custom image, no K8s). Self-hosted needs the workflow forked into your org.",
    "No platform RBAC: access control = GitHub repo permissions/branch protection + separate plan/apply IAM roles. SSO/audit for the Gruntwork app not documented.",
    "Strong explicit DAG (dependency blocks, Stacks, cycle checks, ordered apply on merge), but plans across unapplied deps use mock_outputs; no downstream re-plan.",
    "Scheduled drift detection GHA workflow with account/path filters; opens a remediation PR per run. Team tier and up; alerting is the PR itself.",
    "Native AWS OIDC per environment/unit with separate read-only plan and read-write apply roles; no static credentials.",
    "Enterprise — contact sales at the default calculator inputs",
    "Terragrunt itself is the fogg-class tool: root.hcl includes, generate blocks for backend/provider, remote_state, Stacks codegen. No JS workspace wiring.",
    "No managed state: you run S3 backends (Terragrunt can bootstrap them). Env isolation via IAM roles; standard tfstate; dependency blocks track cross-state links.",
    "No Atlantis migration tooling or atlantis.yaml import; migration means restructuring the repo into Terragrunt units (Terralith-to-Terragrunt guides only).",
    "OSS Terragrunt before/after/error hooks can gate any command (e.g. cosign verify before apply). Pipeline-level pass/warn/deny hooks are Enterprise only.",
    "No private registry. Modules sourced via git/go-getter; Terragrunt catalog/scaffold browse module repos.",
    "Infracost estimates in PR comments since Aug 2026, Enterprise tier only. OSS path: add Infracost yourself in the workflow.",
    "No built-in policy engine. Conftest/OPA can be run from Terragrunt hooks or Enterprise Pipeline Hooks against plan files; nothing native.",
    "No AI PR review.",
    "No native chat integration documented for Slack, Teams or Google Chat; notifications are GitHub PR comments. DIY via hooks or workflow steps.",
    "GitHub and GitLab (incl. GHES/self-managed): consolidated PR comments, status checks, plan on PR/apply on merge. No Bitbucket or Azure DevOps.",
    "Terragrunt emits OpenTelemetry traces/metrics (OTLP, can go to Datadog); run reports JSON/CSV. No platform audit stream or webhooks.",
    "Terragrunt DAG graph export (DOT) and an Infrastructure Dashboard in preview; no resource graph.",
    "No ops MCP/agent. Gruntwork's MCP server only searches the Gruntwork module library.",
    "No ephemeral environment feature; Stacks make cloning an environment easy but lifecycle is manual.",
    "No Terraform provider for managing the platform; configuration lives in .gruntwork/*.hcl in the repo.",
    "Terragrunt is cloud-agnostic; Pipelines has AWS, Azure and GCP OIDC plus custom auth. Free tier limited to AWS."
   ],
   "variants": {
    "17": {
     "slack": 0,
     "teams": 0
    },
    "18": {
     "github": 2,
     "gitlab": 2,
     "bitbucket": 0,
     "azure_devops": 0
    }
   },
   "gates": {
    "G1": {
     "pass": true,
     "evidence": "Runs as GitHub Actions / GitLab CI jobs; no Kubernetes anywhere in the architecture.",
     "url": "https://docs.terragrunt.com/terragrunt-scale/overview/"
    },
    "G2": {
     "pass": true,
     "evidence": "All plan/apply runs execute in the customer's own CI runners; the reusable workflow takes a `runner` input for self-hosted GitHub runners (workflow must be forked into your own org).",
     "url": "https://github.com/gruntwork-io/pipelines-workflows/blob/main/.github/workflows/pipelines.yml"
    },
    "G3": {
     "pass": true,
     "evidence": "Conditional pass: arbitrary pre-plan steps possible via Terragrunt before_hook (e.g. `pnpm synth` on init/plan) or by adding custom actions to a forked pipelines-workflows. No native CDK Terrain support; unverified end-to-end.",
     "url": "https://docs.gruntwork.io/2.0/docs/pipelines/guides/extending-pipelines/"
    },
    "G4": {
     "pass": true,
     "evidence": "Terragrunt v1.1.6 released 2026-09-21; pipelines-workflows pushed 2026-09-24; Pipelines changelog entries through 2026-08-27.",
     "url": "https://github.com/gruntwork-io/terragrunt/releases"
    },
    "G5": {
     "pass": true,
     "evidence": "Gruntwork co-founded OpenTofu; Pipelines defaults to OpenTofu (tf-binary switchable to terraform); versions pinned via .mise.toml.",
     "url": "https://docs.gruntwork.io/2.0/reference/pipelines/terragrunt-version-compatibility/"
    }
   },
   "disqualified": false,
   "tagline": "Terragrunt-native GitOps in your own CI; fogg-class codegen, but mock-output planning"
  },
  {
   "id": "atmos",
   "name": "Atmos",
   "url": "https://atmos.tools",
   "icon": "Atom",
   "color": "#0EA5E9",
   "scores": [
    2,
    3,
    3,
    1,
    2,
    3,
    3,
    2,
    3,
    2,
    2,
    3,
    1,
    2,
    2,
    1,
    1,
    3,
    2,
    1,
    2,
    1,
    0,
    3
   ],
   "rationales": [
    "No native CDK Terrain type. Synth via hooks/custom commands; affected detection via dependencies.folders is manual; custom types skip describe affected.",
    "Terraform and OpenTofu both first-class; per-component command/version pinning, toolchain auto-install, OpenTofu-only features supported.",
    "Runs entirely in your own GitHub Actions (self-hosted EC2 runners OK), no K8s; custom images; built-in container/buildx build component type.",
    "Atmos Pro login is GitHub OAuth only; workspace-level roles (Viewer/Auditor/Member/Admin/Owner); no SAML/OIDC SSO or per-stack scoping documented.",
    "Explicit component DAG, dependency-ordered apply on merge, stack locking; PR plans mock unknown upstream outputs via yq defaults; GitHub Env approvals.",
    "Atmos Pro: daily + post-merge per-instance drift plans, optional auto-remediate apply, post-apply verification, Slack alerts; available on all tiers.",
    "GitHub OIDC to AWS/Azure/GCP via Atmos Auth identities per stack; no static credentials; Pro API also authenticated via GitHub OIDC.",
    "Pro Team ≈ $2,400/mo at the default calculator inputs",
    "Reference-class fogg equivalent: YAML stacks with imports/inheritance generate backend, provider, required_providers and arbitrary files per component.",
    "State stays in your own backend (e.g. S3), access governed by your IAM; Pro stores no state. No resource-level RBAC; standard tfstate.",
    "Generates atlantis.yaml from stacks (`atmos atlantis generate repo-config`), allowing incremental migration; migration skills for Terragrunt/Terramate.",
    "Workflows, custom commands, and lifecycle hooks (kind: command, on_failure: fail) before/after init/plan/apply; can block apply on e.g. cosign verify.",
    "No private module registry; vendoring pulls modules from git/OCI/registries with lock files. Registry cache proxy for providers only.",
    "Built-in `infracost` hook kind on plan events; results in CI output rather than a native cost UI.",
    "Native OPA/JSON Schema validation of stack config; plan-level checks via checkov/trivy/kics hooks or a conftest command hook.",
    "Atmos Pro posts AI PR summaries from the vendor's model (credits). No native PR-intent review or trusted instruction source.",
    "Slack app with interactive approve/reject and drift alerts. No Microsoft Teams or Google Chat integration; only audit-log webhooks.",
    "GitHub App with status checks, PR summaries, merge-queue support, GHES. Other VCS: CLI only, no Pro orchestration.",
    "Audit log streaming as CloudEvents webhooks or Datadog-formatted logs, batched; native CI outputs; no OTel metrics export documented.",
    "Pro dashboards for deployments/drift and a streaming plan UI; no documented resource or dependency graph visualization.",
    "Atmos MCP server plus Atmos Pro MCP (runs, failures, drift analytics); agent write tools and remediation PRs not yet shipped.",
    "Stacks can be templated per env, but no native PR preview/ephemeral environment lifecycle.",
    "No Terraform provider to manage Atmos Pro; configuration is GitOps YAML in the repo (cloudposse/utils provider only reads stack config).",
    "Cloud-agnostic: any Terraform/OpenTofu provider; Atmos Auth covers AWS, Azure and GCP identities."
   ],
   "variants": {
    "17": {
     "slack": 3,
     "teams": 1
    },
    "18": {
     "github": 3,
     "gitlab": 1,
     "bitbucket": 1,
     "azure_devops": 1
    }
   },
   "gates": {
    "G1": {
     "pass": true,
     "evidence": "Atmos is a single Go CLI; Atmos Pro is SaaS that dispatches your own GitHub Actions workflows. No Kubernetes needed.",
     "url": "https://atmos-pro.com/docs"
    },
    "G2": {
     "pass": true,
     "evidence": "All plans/applies run in the customer's GitHub Actions workflows (workflow_dispatch from Atmos Pro); self-hosted EC2 runners work; cloud creds via GitHub OIDC -> AWS, never held by Atmos Pro.",
     "url": "https://atmos-pro.com/docs/learn/ordered-deployments"
    },
    "G3": {
     "pass": true,
     "evidence": "Steps are your own GHA workflow plus Atmos hooks (before.terraform.init/plan kind: command), custom commands and workflows, so pnpm/turbo synth can run pre-plan. No first-class CDK Terrain support.",
     "url": "https://atmos.tools/stacks/hooks"
    },
    "G4": {
     "pass": true,
     "evidence": "v1.229.0 released 2026-09-17; RCs 2026-09-25; 20+ minor releases since Feb 2026.",
     "url": "https://github.com/cloudposse/atmos/releases"
    },
    "G5": {
     "pass": true,
     "evidence": "OpenTofu first-class: per-component `command: tofu`, toolchain installs pinned tofu versions, OpenTofu-specific features (OCI module packages, module source interpolation) supported.",
     "url": "https://atmos.tools/cli/commands/terraform/usage"
    }
   },
   "disqualified": false,
   "tagline": "YAML stack framework (fogg-class codegen) + SaaS that orchestrates your own GitHub Actions"
  },
  {
   "id": "otf",
   "name": "OTF",
   "url": "https://github.com/leg100/otf",
   "icon": "Server",
   "color": "#64748B",
   "scores": [
    1,
    3,
    2,
    2,
    1,
    0,
    2,
    3,
    0,
    2,
    0,
    1,
    2,
    0,
    0,
    0,
    0,
    2,
    1,
    0,
    1,
    0,
    2,
    2
   ],
   "rationales": [
    "No pre-plan hooks. CDK only via CLI-driven runs after CI synth (TFC pattern); no affected-stack detection beyond VCS trigger path patterns.",
    "terraform and tofu are both first-class engines, with engine and version selectable per workspace.",
    "otf-agent binary/Docker image on EC2 with no K8s; custom image possible; no documented hook or asset-build support.",
    "OIDC/GitHub/GitLab/IAP SSO in the free OSS build; TFC-style teams with org and workspace permissions. No SAML, no IdP group sync, no audit log.",
    "TFC-style run triggers (Apr 2026) queue downstream runs after upstream apply; no DAG, no in-change sequencing, no stacks.",
    "No drift detection or health assessments. Would need scheduled runs driven externally via the API.",
    "TFC-compatible dynamic provider credentials for AWS, but docs say only GCP is fully tested; EC2 agent instance roles are an alternative.",
    "Self-hosted (TCO) ≈ $135/mo at the default calculator inputs",
    "No codegen or scaffolding. Workspaces can be managed with the tfe provider/API instead.",
    "State in own Postgres, per-workspace read/plan/write/admin, remote-state sharing toggle, standard state pull; no resource-level RBAC.",
    "No Atlantis migration docs or atlantis.yaml import; only a TFC/local-state migration guide.",
    "No pre/post hooks, run tasks or custom gates. Only a custom agent image and CI-side steps in CLI-driven workflows.",
    "Private module registry publishes from VCS semver tags, one module per repo; not monorepo-friendly.",
    "No cost estimation. The org setting exists only for TFE API compatibility.",
    "No policy-as-code (no Sentinel/OPA). It would have to run in CI before a CLI-driven apply.",
    "No AI features.",
    "Notifications are generic webhook, Slack and GCP Pub/Sub, API-only (no UI). No Microsoft Teams destination.",
    "GitHub App/PAT, GitLab and Forgejo; speculative PR plans with commit status checks, no PR comments; no Bitbucket or Azure DevOps.",
    "Generic webhook notifications and some Prometheus metrics; no audit stream or OTel export.",
    "No resource or dependency graphs.",
    "No MCP. The maintainer suggests using HashiCorp's terraform-mcp-server through TFE API compatibility (untested).",
    "No ephemeral environment feature.",
    "Much of the TFE API is implemented, so hashicorp/tfe provider works for many resources, with documented gaps and bugs.",
    "Provider-agnostic TF/tofu runner; dynamic creds support AWS, GCP and Azure (only GCP fully tested)."
   ],
   "variants": {
    "17": {
     "slack": 1,
     "teams": 0
    },
    "18": {
     "github": 2,
     "gitlab": 2,
     "bitbucket": 0,
     "azure_devops": 0
    }
   },
   "gates": {
    "G1": {
     "pass": true,
     "evidence": "Single Go binary otfd + PostgreSQL; docker compose and plain binary installs documented. The default fork executor runs terraform/tofu as child processes. Kubernetes is only used by the optional kubernetes executor / Helm charts.",
     "url": "https://github.com/leg100/otf/blob/master/docs/docs/install.md"
    },
    "G2": {
     "pass": true,
     "evidence": "otf-agent (binary or leg100/otf-agent Docker image) joins an agent pool with a pool token and runs plans/applies in agent execution mode. Works like TFC agents and can run on EC2 in our own account.",
     "url": "https://github.com/leg100/otf/blob/master/docs/docs/runners.md"
    },
    "G3": {
     "pass": true,
     "evidence": "No pre-plan hooks in the runner, so VCS-driven runs cannot synth. The CLI-driven workflow works: CI runs pnpm/turbo synth, then terraform plan/apply with the cloud/remote backend uploads cdktf.out stacks, and they execute on an agent.",
     "url": "https://github.com/leg100/otf/blob/master/docs/docs/tfc_migration.md"
    },
    "G4": {
     "pass": false,
     "evidence": "Fails. 1 commit and 0 releases in the last 90 days; single maintainer silent since Jul 2026.",
     "url": "https://github.com/leg100/otf/releases"
    },
    "G5": {
     "pass": true,
     "evidence": "First-class engines are terraform and tofu. The default is set per install and can be overridden per workspace along with the engine version.",
     "url": "https://github.com/leg100/otf/blob/master/docs/docs/engines.md"
    }
   },
   "disqualified": true,
   "tagline": "Free MPL-2.0 open-source TFE clone (Go + Postgres), OpenTofu-ready; single-maintainer risk"
  },
  {
   "id": "atlantis",
   "name": "Atlantis",
   "url": "https://www.runatlantis.io",
   "icon": "GitBranch",
   "color": "#2563EB",
   "scores": [
    2,
    3,
    2,
    1,
    2,
    2,
    2,
    3,
    1,
    1,
    3,
    3,
    0,
    0,
    3,
    0,
    1,
    3,
    2,
    0,
    0,
    0,
    0,
    3
   ],
   "rationales": [
    "Pre-workflow hook can synth before plan; per-project when_modified globs scope autoplan, but they are hand-kept, not dependency-aware; hook reruns per command.",
    "OpenTofu is first-class: server default or per-project terraform_distribution, per-project terraform_version pinning, .tofu file support, bundled binary.",
    "Runs on your own EC2/Docker/Fargate, no K8s; custom image supported. No separate runner pool: all runs execute on the server; no native container builds.",
    "No SSO; web UI has basic auth only. Command authz via GitHub team allowlist or GitLab group allowlist, or an external authz script. No audit log.",
    "depends_on + execution_order_group give ordered plan/apply in one PR; all plans are taken up front, so no auto re-plan on upstream outputs or unknowns.",
    "Alpha drift detect/remediate APIs (v0.45+) with Slack/HTTP drift webhooks; no built-in scheduler, you trigger it (cron/CI). Remediation apply is opt-in.",
    "No credential brokering or OIDC per stack. Uses the server's identity (e.g. EC2 instance role) plus provider assume_role per account; no static keys needed.",
    "Self-hosted, business hours (TCO) ≈ $90/mo at the default calculator inputs",
    "Project autodiscovery, per-project autoplan when_modified and a hook to load a generated atlantis.yaml; no backend/provider codegen of its own.",
    "Does not manage state; uses your backend (e.g. S3) with isolation via IAM. No state RBAC, versioning UI, export or cross-state dependency tracking.",
    "It is Atlantis: the baseline the other platforms migrate from.",
    "Custom workflows with arbitrary run steps, pre/post workflow hooks, custom images, command requirements and custom gates before apply. All free.",
    "No module registry. Modules come from Git, local paths or an external registry.",
    "No native cost estimation. Infracost can be added as a custom workflow step.",
    "Native Conftest/OPA policy_check on the plan JSON, portable Rego, owner users/teams approve failures, sticky approvals (v0.44+).",
    "No native AI or LLM plan review.",
    "Webhooks only for apply and drift events: native Slack messages, or generic HTTP JSON a Teams Workflows flow can consume. No interactivity or approvals.",
    "PR-comment driven plan/apply, commit statuses, approved/mergeable/undiverged gates and automerge on GitHub and GitLab; Bitbucket, Azure DevOps and Gitea too.",
    "Prometheus or StatsD metrics and structured logs; apply/drift HTTP webhooks. No audit stream, OpenTelemetry export or run-event feed.",
    "Web UI shows locks and job log streams only; no resource, dependency or deployment graphs.",
    "No MCP server or agentic features.",
    "No ephemeral or preview environment feature.",
    "No official Terraform provider; configuration is server flags, repos.yaml and atlantis.yaml.",
    "Provider-agnostic: runs any Terraform/OpenTofu provider; deployment guides cover AWS, GCP and Azure."
   ],
   "variants": {
    "17": {
     "slack": 1,
     "teams": 1
    },
    "18": {
     "github": 3,
     "gitlab": 3,
     "bitbucket": 2,
     "azure_devops": 2
    }
   },
   "gates": {
    "G1": {
     "pass": true,
     "evidence": "Single Go binary or official Docker image with no external database; runs on a VM, Docker, ECS/Fargate or GCE. Helm chart and K8s manifests are optional.",
     "url": "https://www.runatlantis.io/docs/deployment"
    },
    "G2": {
     "pass": true,
     "evidence": "Fully self-hosted in your own cloud account; Terraform runs locally on the Atlantis server using its host credentials (instance role / assume_role).",
     "url": "https://www.runatlantis.io/docs/provider-credentials"
    },
    "G3": {
     "pass": true,
     "evidence": "Server-side pre_workflow_hooks run arbitrary commands (e.g. pnpm install + synth) before plan, and can even generate atlantis.yaml dynamically.",
     "url": "https://www.runatlantis.io/docs/pre-workflow-hooks"
    },
    "G4": {
     "pass": true,
     "evidence": "Passes. 146 commits from 14 people in 90 days and 5 releases; security fixes ship within days. Issue triage is slow (~10% of new issues get a maintainer reply within 14 days).",
     "url": "https://github.com/runatlantis/atlantis/releases"
    },
    "G5": {
     "pass": true,
     "evidence": "OpenTofu first-class: --tf-distribution / --default-tf-distribution server-wide and terraform_distribution: opentofu per project; full images bundle OpenTofu.",
     "url": "https://www.runatlantis.io/docs/terraform-versions"
    }
   },
   "disqualified": false,
   "tagline": "Free, self-hosted PR-comment plan/apply with hooks, Conftest policy and OpenTofu"
  }
 ],
 "scoreLabels": [
  "None",
  "Limited",
  "Good",
  "Excellent"
 ],
 "categories": {
  "critical": {
   "label": "Critical",
   "color": "#EF4444"
  },
  "high": {
   "label": "High",
   "color": "#F59E0B"
  },
  "medium": {
   "label": "Medium",
   "color": "#3B82F6"
  },
  "low": {
   "label": "Low",
   "color": "#64748B"
  },
  "nice": {
   "label": "Nice-to-have",
   "color": "#94A3B8"
  }
 },
 "pricing": {
  "sliders": {
   "users": {
    "min": 1,
    "max": 100,
    "default": 24,
    "step": 1,
    "label": "Team Size",
    "unit": "users"
   },
   "resources": {
    "min": 100,
    "max": 50000,
    "default": 18406,
    "step": 100,
    "label": "Resources Under Management",
    "unit": "RUM"
   },
   "runs": {
    "min": 50,
    "max": 5000,
    "default": 1900,
    "step": 50,
    "label": "Monthly Runs (per-state plans + applies)",
    "unit": "runs/mo"
   },
   "stacks": {
    "min": 1,
    "max": 1000,
    "default": 277,
    "step": 1,
    "label": "Terraform States (workspaces)",
    "unit": "states"
   }
  },
  "featureLabels": {
   "privateWorkers": "Self-hosted runners",
   "opa": "Policy enforcement",
   "driftDetection": "Drift detection",
   "samlSso": "SAML SSO",
   "auditLog": "Audit log",
   "registry": "Module registry"
  },
  "pricingScore": {
   "bands": [
    {
     "max": 750,
     "score": 3
    },
    {
     "max": 2500,
     "score": 2
    },
    {
     "max": 7500,
     "score": 1
    }
   ],
   "above": 0,
   "quoteOnly": 1
  },
  "platforms": {
   "spacelift": {
    "model": "Annual subscription, worker-gated",
    "description": "Flat annual tiers; private workers (runners in your account) start at Starter+",
    "tiers": [
     {
      "name": "Free",
      "basePrice": 0,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": 2,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": false,
      "features": {
       "privateWorkers": false,
       "opa": true,
       "driftDetection": false,
       "samlSso": false,
       "auditLog": false,
       "registry": false
      },
      "notes": "2 users, 1 public worker, no private workers — not usable for a team",
      "source": "https://spacelift.io/pricing",
      "billing": null,
      "monthlyBasePrice": null
     },
     {
      "name": "Starter+",
      "basePrice": 1667,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": false,
       "auditLog": false,
       "registry": false
      },
      "notes": "$20,000/yr; unlimited users; 1–2 private workers; OIDC SSO; no registry/Blueprints",
      "source": "https://spacelift.io/pricing",
      "billing": "annual",
      "monthlyBasePrice": null
     },
     {
      "name": "Business",
      "basePrice": 0,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": true,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": false,
       "auditLog": false,
       "registry": true
      },
      "notes": "Quote only; 3 private workers, Blueprints/Templates, module registry",
      "source": "https://spacelift.io/pricing",
      "billing": "annual",
      "monthlyBasePrice": null
     },
     {
      "name": "Enterprise",
      "basePrice": 0,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": true,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": true,
       "auditLog": true,
       "registry": true
      },
      "notes": "Quote only; 5–30 private workers, SAML SSO, audit trail",
      "source": "https://spacelift.io/pricing",
      "billing": "annual",
      "monthlyBasePrice": null
     }
    ]
   },
   "env0": {
    "model": "Platform fee + active environments",
    "description": "Tiers capped by active environments (one Terraform state each); list prices from AWS Marketplace",
    "tiers": [
     {
      "name": "Free",
      "basePrice": 0,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": 250,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": 250,
      "maxStacks": 30,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": false,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": true,
       "auditLog": false,
       "registry": true
      },
      "notes": "30 active environments, 250 runs, 1 concurrent run",
      "source": "https://docs.envzero.com/guides/billing/subscription-tiers",
      "billing": null,
      "monthlyBasePrice": null
     },
     {
      "name": "Cloud Navigator",
      "basePrice": 1500,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": 100,
      "estimated": true,
      "quoteOnly": false,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": true,
       "auditLog": false,
       "registry": true
      },
      "notes": "Marketplace list $18k/yr platform fee; up to 100 active environments; quote-based",
      "source": "https://aws.amazon.com/marketplace/pp/prodview-t2j5oberppp7e",
      "billing": "annual",
      "monthlyBasePrice": null
     },
     {
      "name": "Cloud Pilot",
      "basePrice": 3000,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 30.42,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": true,
      "quoteOnly": false,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": true,
       "auditLog": true,
       "registry": true
      },
      "notes": "Marketplace list $36k/yr + $365/yr per active env (worst case, bundling unpublished)",
      "source": "https://aws.amazon.com/marketplace/pp/prodview-t2j5oberppp7e",
      "billing": "annual",
      "monthlyBasePrice": null
     }
    ]
   },
   "scalr": {
    "model": "Per run",
    "description": "Same features on Free and Business; billed per run (PR dry runs count, drift runs don't)",
    "tiers": [
     {
      "name": "Free",
      "basePrice": 0,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": 50,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": 50,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": true,
       "auditLog": false,
       "registry": true
      },
      "notes": "50 runs/month",
      "source": "https://scalr.com/pricing",
      "billing": null,
      "monthlyBasePrice": null
     },
     {
      "name": "Business",
      "basePrice": 0,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0.99,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": true,
       "auditLog": false,
       "registry": true
      },
      "notes": "$0.99/run, volume discounts",
      "source": "https://docs.scalr.io/docs/pricing-faq",
      "billing": "usage",
      "monthlyBasePrice": null
     },
     {
      "name": "Enterprise",
      "basePrice": 0,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": true,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": true,
       "auditLog": true,
       "registry": true
      },
      "notes": "Quote only; from 20,000 runs/yr commit with volume discounts; audit log streaming, own-bucket state, BYOK",
      "source": "https://scalr.com/pricing",
      "billing": "annual",
      "monthlyBasePrice": null
     }
    ]
   },
   "terramate": {
    "model": "Resources under management",
    "description": "Flat tiers capped by managed resources; runs in your own CI",
    "tiers": [
     {
      "name": "Community",
      "basePrice": 0,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": 2,
      "maxResources": 1000,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": false,
       "auditLog": false,
       "registry": false
      },
      "notes": "2 users, 1,000 resources",
      "source": "https://terramate.io/pricing",
      "billing": null,
      "monthlyBasePrice": null
     },
     {
      "name": "Teams",
      "basePrice": 449,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": 5000,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": false,
       "auditLog": false,
       "registry": false
      },
      "notes": "Unlimited users, 5,000 resources; no RBAC/SAML/audit",
      "source": "https://terramate.io/pricing",
      "billing": "monthly",
      "monthlyBasePrice": null
     },
     {
      "name": "Enterprise",
      "basePrice": 0,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": true,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": true,
       "auditLog": true,
       "registry": false
      },
      "notes": "Quote only; RBAC, SAML, audit logs, custom resource limits",
      "source": "https://terramate.io/pricing",
      "billing": "annual",
      "monthlyBasePrice": null
     }
    ]
   },
   "stategraph": {
    "model": "Billable infrastructure units (BIUs)",
    "description": "Orchestration (formerly Terrateam) is bundled from Professional up; BIUs count only resources that appear on the cloud bill",
    "tiers": [
     {
      "name": "Free",
      "basePrice": 0,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": 4348,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": false,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": false,
       "samlSso": true,
       "auditLog": false,
       "registry": false
      },
      "notes": "1,000 BIUs, shared tenant; no Terraform orchestration",
      "source": "https://stategraph.com/pricing",
      "billing": null,
      "monthlyBasePrice": null
     },
     {
      "name": "Starter",
      "basePrice": 999,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": 43478,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": false,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": false,
       "samlSso": true,
       "auditLog": false,
       "registry": false
      },
      "notes": "$11,988/yr; 10k BIUs, single tenant, multi-state plan/apply; no Terraform orchestration (PR automation, drift)",
      "source": "https://stategraph.com/pricing",
      "billing": "annual",
      "monthlyBasePrice": 1200
     },
     {
      "name": "Professional",
      "basePrice": 1499,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": 43478,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": true,
       "auditLog": true,
       "registry": false
      },
      "notes": "$17,988/yr; 10k BIUs (≈43k managed resources at an estimated 0.23 BIUs per resource); adds Terraform orchestration (PR automation, drift), inventory, webhooks; no RBAC or self-hosting",
      "source": "https://stategraph.com/pricing",
      "billing": "annual",
      "monthlyBasePrice": 1800
     },
     {
      "name": "Enterprise",
      "basePrice": 2083,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": 43478,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": true,
       "auditLog": true,
       "registry": false
      },
      "notes": "$25k/yr; 10k BIUs; RBAC, full API, self-hosted/BYOC, air-gapped",
      "source": "https://stategraph.com/pricing",
      "billing": "annual",
      "monthlyBasePrice": 2500
     },
     {
      "name": "Enterprise (above 10k BIUs)",
      "basePrice": 0,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": true,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": true,
       "auditLog": true,
       "registry": false
      },
      "notes": "BIU packs ~$1.20–1.80 per BIU (period unpublished); quote builder only",
      "source": "https://stategraph.com/pricing",
      "billing": "annual",
      "monthlyBasePrice": null
     }
    ]
   },
   "hcp-terraform": {
    "model": "Resources under management",
    "description": "Billed per peak managed resource per hour",
    "tiers": [
     {
      "name": "Free",
      "basePrice": 0,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": 500,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": false,
       "samlSso": false,
       "auditLog": false,
       "registry": true
      },
      "notes": "500 resources, 1 concurrent run, no SSO",
      "source": "https://developer.hashicorp.com/terraform/cloud-docs/overview",
      "billing": null,
      "monthlyBasePrice": null
     },
     {
      "name": "Essentials",
      "basePrice": 0,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0.1,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": false,
      "features": {
       "privateWorkers": true,
       "opa": false,
       "driftDetection": false,
       "samlSso": true,
       "auditLog": false,
       "registry": true
      },
      "notes": "$0.10/resource/mo; 1 concurrent agent run, no drift or policy enforcement",
      "source": "https://www.hashicorp.com/en/pricing",
      "billing": "usage",
      "monthlyBasePrice": null
     },
     {
      "name": "Standard",
      "basePrice": 0,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0.47,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": true,
       "auditLog": false,
       "registry": true
      },
      "notes": "$0.47/resource/mo pay-as-you-go; 10 agent runs, drift, policy, Stacks. Flex annual/multi-year discounts via sales (unpublished)",
      "source": "https://www.hashicorp.com/en/pricing",
      "billing": "usage",
      "monthlyBasePrice": null
     },
     {
      "name": "Premium",
      "basePrice": 0,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0.99,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": true,
       "auditLog": true,
       "registry": true
      },
      "notes": "$0.99/resource/mo pay-as-you-go; audit logging, custom RBAC, Stack auto-approve groups. Flex discounts via sales (unpublished)",
      "source": "https://www.hashicorp.com/en/pricing",
      "billing": "usage",
      "monthlyBasePrice": null
     }
    ]
   },
   "opentaco": {
    "model": "Per user (hosted) / self-hosted",
    "description": "'Free' options lack UI/drift at team scale; hosted Pro is the realistic entry",
    "tiers": [
     {
      "name": "Backendless (OSS action)",
      "basePrice": 0,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": false,
      "features": {
       "privateWorkers": true,
       "opa": false,
       "driftDetection": false,
       "samlSso": false,
       "auditLog": false,
       "registry": false
      },
      "notes": "No UI, policy store or drift service — demo scale only",
      "source": "https://docs.opentaco.dev/ce/howto/backendless-mode",
      "billing": null,
      "monthlyBasePrice": null
     },
     {
      "name": "Cloud Free",
      "basePrice": 0,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": 3,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": false,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": false,
       "auditLog": false,
       "registry": false
      },
      "notes": "Hard-capped at 3 drift-monitored projects",
      "source": "https://github.com/diggerhq/digger/blob/develop/backend/models/orgs.go",
      "billing": null,
      "monthlyBasePrice": null
     },
     {
      "name": "Self-hosted CE (TCO)",
      "basePrice": 300,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": true,
      "quoteOnly": false,
      "autoSelect": false,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": true,
       "auditLog": false,
       "registry": false
      },
      "notes": "MIT; ~$150–250 AWS + WorkOS SSO $125/connection; excludes engineering time, no vendor support",
      "source": "https://github.com/diggerhq/digger",
      "billing": "usage",
      "monthlyBasePrice": null
     },
     {
      "name": "Pro",
      "basePrice": 0,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": true,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": false,
       "auditLog": false,
       "registry": false
      },
      "notes": "Quote only; vendor pricing page removed (an unverified third-party listing shows ~$250 for 5 users + $10/user)",
      "source": "https://toolradar.com/tools/digger",
      "billing": "monthly",
      "monthlyBasePrice": null
     },
     {
      "name": "Enterprise",
      "basePrice": 0,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": true,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": true,
       "auditLog": true,
       "registry": false
      },
      "notes": "Quote only (third-party $3–5k/mo)",
      "source": "https://toolradar.com/tools/digger",
      "billing": "annual",
      "monthlyBasePrice": null
     }
    ]
   },
   "pulumi": {
    "model": "Resources under management (hourly)",
    "description": "Every Pulumi-managed resource counts; customer-managed deployment agents need Enterprise",
    "tiers": [
     {
      "name": "Free",
      "basePrice": 0,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": 1,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": false,
      "features": {
       "privateWorkers": false,
       "opa": true,
       "driftDetection": false,
       "samlSso": false,
       "auditLog": false,
       "registry": false
      },
      "notes": "1 user; Pulumi-hosted deployments only",
      "source": "https://www.pulumi.com/pricing/",
      "billing": null,
      "monthlyBasePrice": null
     },
     {
      "name": "Essentials",
      "basePrice": 40,
      "includedUsers": null,
      "includedResources": 500,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0.1825,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": false,
      "features": {
       "privateWorkers": false,
       "opa": false,
       "driftDetection": false,
       "samlSso": false,
       "auditLog": false,
       "registry": false
      },
      "notes": "~500 resources included; no customer-managed agents, advisory policies only",
      "source": "https://www.pulumi.com/pricing/",
      "billing": "monthly",
      "monthlyBasePrice": null
     },
     {
      "name": "Pro",
      "basePrice": 400,
      "includedUsers": null,
      "includedResources": 2000,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0.365,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": false,
      "features": {
       "privateWorkers": false,
       "opa": true,
       "driftDetection": true,
       "samlSso": true,
       "auditLog": true,
       "registry": true
      },
      "notes": "~2,000 resources included; SAML, drift; Pulumi-hosted deployments only (no own agents). Annual-commit discount via sales (unpublished)",
      "source": "https://www.pulumi.com/pricing/",
      "billing": "monthly",
      "monthlyBasePrice": null
     },
     {
      "name": "Enterprise",
      "basePrice": 2000,
      "includedUsers": null,
      "includedResources": 4750,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0.5475,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": true,
      "quoteOnly": false,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": true,
       "auditLog": true,
       "registry": true
      },
      "notes": "Month-to-month list rate; customer-managed agents (EC2/Docker); annual-commit and volume discounts via sales (unpublished)",
      "source": "https://www.pulumi.com/pricing/",
      "billing": "monthly",
      "monthlyBasePrice": null
     }
    ]
   },
   "terragrunt-scale": {
    "model": "Units (one state each)",
    "description": "Billed by units: each directory with a terragrunt.hcl, i.e. one Terraform state (a Terragrunt stack is a group of units)",
    "tiers": [
     {
      "name": "Free",
      "basePrice": 0,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": 25,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": false,
      "features": {
       "privateWorkers": true,
       "opa": false,
       "driftDetection": false,
       "samlSso": false,
       "auditLog": false,
       "registry": false
      },
      "notes": "25 units; personal/small commercial use",
      "source": "https://terragrunt.com/terragrunt-scale",
      "billing": null,
      "monthlyBasePrice": null
     },
     {
      "name": "Team",
      "basePrice": 500,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": 200,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": false,
       "driftDetection": true,
       "samlSso": false,
       "auditLog": false,
       "registry": false
      },
      "notes": "200 units; Patcher + drift; annual billing (~$600 month-to-month)",
      "source": "https://terragrunt.com/terragrunt-scale",
      "billing": "annual",
      "monthlyBasePrice": 600
     },
     {
      "name": "Enterprise",
      "basePrice": 0,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": true,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": false,
       "driftDetection": true,
       "samlSso": false,
       "auditLog": false,
       "registry": false
      },
      "notes": "Quote only; unlimited units, pipeline hooks, Infracost",
      "source": "https://terragrunt.com/terragrunt-scale",
      "billing": "annual",
      "monthlyBasePrice": null
     }
    ]
   },
   "atmos": {
    "model": "Licensed users",
    "description": "Atmos CLI is free; Atmos Pro billed per licensed user (viewers free)",
    "tiers": [
     {
      "name": "Pro Free",
      "basePrice": 0,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": 3,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": 100,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": false,
       "auditLog": false,
       "registry": false
      },
      "notes": "3 licensed users, 100 component instances",
      "source": "https://atmos-pro.com/pricing",
      "billing": null,
      "monthlyBasePrice": null
     },
     {
      "name": "Pro Team",
      "basePrice": 500,
      "includedUsers": 5,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 100,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": false,
       "auditLog": false,
       "registry": false
      },
      "notes": "5 users + $100/user, billed monthly (no annual discount); approvals may be Business-only",
      "source": "https://atmos-pro.com/pricing",
      "billing": "monthly",
      "monthlyBasePrice": null
     },
     {
      "name": "Pro Business",
      "basePrice": 3000,
      "includedUsers": 25,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": 25,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": false,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": false,
       "auditLog": true,
       "registry": false
      },
      "notes": "From $36k/yr, 25 users; governance/approvals, SLA",
      "source": "https://atmos-pro.com/pricing",
      "billing": "annual",
      "monthlyBasePrice": null
     },
     {
      "name": "Pro Enterprise",
      "basePrice": 0,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": false,
      "quoteOnly": true,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": true,
       "samlSso": false,
       "auditLog": true,
       "registry": false
      },
      "notes": "Quote only",
      "source": "https://atmos-pro.com/pricing",
      "billing": "annual",
      "monthlyBasePrice": null
     }
    ]
   },
   "otf": {
    "model": "Self-hosted (OSS)",
    "description": "Free MPL-2.0; cost is hosting plus operations",
    "tiers": [
     {
      "name": "Self-hosted (TCO)",
      "basePrice": 135,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": true,
      "quoteOnly": false,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": false,
       "driftDetection": false,
       "samlSso": true,
       "auditLog": false,
       "registry": true
      },
      "notes": "~$100–170/mo EC2 + RDS + ALB + agents; plus ~0.1–0.2 FTE ops; single maintainer",
      "source": "https://github.com/leg100/otf",
      "billing": "usage",
      "monthlyBasePrice": null
     }
    ]
   },
   "atlantis": {
    "model": "Self-hosted (OSS)",
    "description": "Free Apache-2.0; cost is one instance plus storage (no load balancer or NAT needed)",
    "tiers": [
     {
      "name": "Self-hosted, business hours (TCO)",
      "basePrice": 90,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": true,
      "quoteOnly": false,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": false,
       "samlSso": false,
       "auditLog": false,
       "registry": false
      },
      "notes": "One t4g.xlarge–2xlarge on a weekday schedule (~$50–100) + ~160 GB gp3 and a public IP (~$20); no plans/applies out of hours; excludes engineering time",
      "source": "https://www.runatlantis.io/docs/deployment",
      "billing": "usage",
      "monthlyBasePrice": null
     },
     {
      "name": "Self-hosted, 24/7 (TCO)",
      "basePrice": 190,
      "includedUsers": null,
      "includedResources": null,
      "includedRuns": null,
      "includedStacks": null,
      "perUser": 0,
      "perResource": 0,
      "perRun": 0,
      "perStack": 0,
      "maxUsers": null,
      "maxResources": null,
      "maxRuns": null,
      "maxStacks": null,
      "estimated": true,
      "quoteOnly": false,
      "autoSelect": true,
      "features": {
       "privateWorkers": true,
       "opa": true,
       "driftDetection": false,
       "samlSso": false,
       "auditLog": false,
       "registry": false
      },
      "notes": "Same instance always on (~$125–250) + storage/IP; DIY LLM plan review via hooks adds ~$0.06/review (Sonnet-class model)",
      "source": "https://www.runatlantis.io/docs/deployment",
      "billing": "usage",
      "monthlyBasePrice": null
     }
    ]
   }
  }
 }
}