Stackorder vs Atlantis: an Atlantis alternative that runs on GitHub Actions
In short
- Both
- Free, Apache-2.0 and self-hosted; plan on pull requests and apply from a comment.
- Atlantis
- Runs Terraform on its own server, which holds your cloud credentials; works with six Git hosts and any state backend except local state.
- Stackorder
- Runs on your GitHub Actions runners with no cloud credentials on the server, and applies in waves from a graph of stacks and modules; GitHub and S3 only.
Atlantis and Stackorder are both free, open source under the Apache License 2.0, and self-hosted, and both bring Terraform and OpenTofu into the pull request. Atlantis is a CNCF Sandbox project. The main difference is where the work runs.
Atlantis is a Go server that receives webhooks from your Git host, runs plan and apply on its own host, and posts the output back to the pull request. Stackorder's server never runs Terraform: GitHub Actions runs every plan and apply on your runners, and the server decides which stacks run and in what order.
Stackorder and Atlantis side by side
Numbers link to the sources at the end of the page. Prices are as published on . A dash means we have not verified that fact for Atlantis, not that it is missing.
| Feature | Stackorder | Atlantis |
|---|---|---|
| License | Apache-2.0, open source27 | Apache-2.0, open source; a CNCF Sandbox project1, 2 |
| Deployment | Self-hosted; setup mode creates the GitHub App from a manifest20, 24 | Self-hosted only: Helm chart, Kubernetes manifests or Kustomize, OpenShift, an AWS Fargate module, GKE or GCE, or Docker3 |
| Pricing | Free and open source; you run the server27 | Free; no paid tier or hosted offering1 |
| Maturity | v0.1.0, first released 2026-09-30; tested end to end against LocalStack, not yet against real AWS or a real GitHub organization by default25, 26 | A CNCF Sandbox project, actively released; v0.48.0 added slim images2, 15 |
| Where Terraform runs | Your GitHub Actions runners, GitHub-hosted or self-hosted; it manages no runners or agents16 | On the Atlantis server itself, not on CI runners3 |
| State backend | Bring your own S3; never takes or releases the state lock16 | Bring your own; any backend except local state4 |
| Modules | No registry; lists each module's consumers, and for git modules the version each pins and how far behind it is16 | No registry; the opt-in --autoplan- plans the projects that use a changed local module7 |
| Self-hosted footprint | One container of about 30 MB and Postgres; actions that use no Docker16 | One Go binary or container with no external database; a persistent disk for plans and BoltDB locks, or Redis for locks3 |
| Cross-stack dependencies | A graph of stacks and modules from depends_, module sources and terraform_ reads, including cross-repository edges; applies in waves17, 18 | execution_ for a global plan or apply, and depends_ between projects in one atlantis.6 |
| Cloud credentials | Not held by the server; the runner assumes your IAM role with its own GitHub OIDC token19 | Held by the server, which runs Terraform: instance or workload roles, environment variables, credential files or Vault12 |
| Human sign-in | GitHub OAuth through the App, read:org scope only20 | —not verified |
| Git hosts | GitHub only, by design16 | GitHub, GitLab, Gitea and Forgejo, Bitbucket Cloud and Server, Azure DevOps4 |
| OpenTofu | Yes, with tool: tofu; tested end to end with OpenTofu 1.1223, 25 | Yes, with --default- or terraform_ per project11 |
| Drift detection | Scheduled per stack with drift.; with open_, one GitHub issue per drifted stack, closed when the drift is gone; never applies to fix drift21 | Alpha API endpoints since v0.45.0, off by default; no built-in scheduler, so an external job has to call them8 |
| Policy checks | Not a policy engine; run OPA, conftest, Checkov or Infracost in hooks, and stackorder check records a named check the apply gate honors22 | Built-in Conftest (OPA) checks with policy-owner approval; custom_ for other tools9 |
| Pull request workflow | A check per stack, one sticky comment, and stackorder plan, apply and unlock comments; applies before merge by default, or on merge17 | atlantis plan and atlantis apply comments and autoplan on each commit; applies before merge by default; a lock per directory and workspace until the pull request merges or closes5, 10 |
Why look for an Atlantis alternative
- The Atlantis server runs Terraform, so it holds your cloud credentials, and Atlantis's own security documentation names malicious pull request code as a way to exploit them.12, 13
- Every plan and apply runs on that one server, not on CI runners.3
- Drift detection is alpha API endpoints, off by default, with no built-in scheduler.8
- Ordering covers the projects in one
atlantis..6yaml
Key differences
Where plan and apply run
Atlantis runs Terraform on its own long-lived server, so that server needs your cloud credentials, and its security documentation names malicious pull request code as a way to exploit them. Stackorder runs Terraform in GitHub Actions jobs that assume your AWS roles with their own OIDC token; its server has no cloud access at all. Both servers must be reachable from your Git host.
Git hosts and state backends
Atlantis works with GitHub, GitLab, Gitea and Forgejo, Bitbucket Cloud and Server, and Azure DevOps, and with any state backend except local state. Stackorder is GitHub only, by design, and supports the S3 backend only.
Dependencies between stacks
Atlantis orders projects in one atlantis.yaml: execution_order_group orders a global plan or apply, and depends_on holds a project's apply until its dependencies have applied. Stackorder builds a graph from depends_on, module sources and terraform_remote_state reads, plans downstream stacks when something they depend on changes, and applies in waves. Cross-repository edges appear in its graph and can trigger plan-only runs downstream, but each run applies one repository.
Drift detection
Atlantis added alpha drift detection and remediation endpoints in v0.45.0. They are off by default, keep results in memory, and have no scheduler, so a cron job or CI job must call them. Stackorder runs drift checks on a cron schedule you set in stackorder.yaml and, with open_issue, keeps one GitHub issue per drifted stack. It never applies to fix drift; that stays a pull request.
Policy
Atlantis runs Conftest policy checks against the plan, and a failure blocks the apply until a policy owner approves. Stackorder is not a policy engine: you run OPA, conftest, Checkov or Infracost in a hook, and stackorder check records the verdict as a named check that the apply gate honors.
Locking
Atlantis locks each directory and workspace when it plans, until the pull request merges or closes. Stackorder takes stack-level locks in Postgres, all or nothing, before the first wave of an apply, and releases them on merge or when the run completes. Neither replaces Terraform's own state lock.
Where Atlantis is strong
- Free and open source under Apache-2.0, and governed as a CNCF Sandbox project.1, 2
- Six Git hosts: GitHub, GitLab, Gitea and its forks such as Forgejo, Bitbucket Cloud, Bitbucket Server and Azure DevOps.4
- Any Terraform state backend except local state.4
- Built-in Conftest policy checks that hold an apply until a policy owner approves.9
- One binary or container with no external database; Redis is an option for locks.3
- OpenTofu as a first-class distribution, with versions detected from
.tofufiles since v0.46.0.11 - Metrics for StatsD or Prometheus, and a web UI that shows and releases locks.14
- Actively released: v0.48.0 added slim images without bundled binaries.15
When to choose which
Choose Stackorder when
- Your code is on GitHub and you want Terraform or OpenTofu to run on your own GitHub Actions runners, under AWS roles the runner assumes with its own GitHub OIDC token.
- You have many stacks that depend on each other or on shared modules, and you want a change planned everywhere it lands and applied in dependency waves.
- You want a small open-source server you host yourself, which holds no cloud credentials and no state, and whose outage pauses applies but not pull request plans.
Choose Atlantis when
- Your repositories live on GitLab, Gitea, Bitbucket or Azure DevOps, or your state is in a backend other than S3.
- You want Conftest policy checks built into the tool, with approval by policy owners.
- You want one server to run Terraform with no CI runners involved, and you are comfortable securing a long-lived server that holds cloud credentials.
- You want a tool governed by the CNCF.
- You want more production use behind the tool than Stackorder has yet: its first release, v0.1.0, came out on .
Try Stackorder on your own repositories
Free and open source under the Apache License 2.0. The getting started guide takes one repository from nothing to a first stackorder apply; the local demo runs on one machine with no GitHub App and no AWS account.
Frequently asked questions
Is Stackorder an alternative to Atlantis?
terraform_remote_state reads.Does the Stackorder server need cloud credentials like the Atlantis server does?
Do both support OpenTofu?
--default-tf-distribution=opentofu on the server or terraform_distribution per project. Stackorder supports it with tool: tofu, set at the root or per stack, and its end-to-end tests run OpenTofu 1.12.Does Atlantis support GitLab and Bitbucket? Does Stackorder?
Which one has scheduled drift detection?
More comparisons
- All tools in one feature matrix
- Stackorder vs HCP Terraform (formerly Terraform Cloud)
- Stackorder vs Stategraph (formerly Terrateam)
- Stackorder vs Spacelift
- Stackorder vs env zero (formerly env0)
- Stackorder vs Scalr
- Stackorder vs Terrakube
- Stackorder vs OpenTaco (formerly Digger)
- What Stackorder is and how it works