Stackorder vs env zero (formerly env0)
In short
- Both
- Plan on pull requests and deploy dependent stacks in order.
- env zero
- A SaaS control plane with hosted or self-hosted agents, approval policies, cost estimation, a private registry and drift remediation.
- Stackorder
- Free and entirely self-hosted; runs on your GitHub Actions runners and holds no cloud credentials; GitHub and S3 only.
env0 now goes by env zero: www.env0.com redirects to envzero.com, and in March 2026 it merged with CloudQuery under the env zero brand. It is a proprietary SaaS platform for automating and governing infrastructure as code, with OpenTofu as its default binary. Deployments run on env zero's hosted agents or on self-hosted agents, and the platform adds a remote backend, a private registry, OPA approval policies, cost estimation and drift remediation.
Stackorder has no hosted agents and no remote backend. GitHub Actions runs every plan and apply on your runners, state stays in your S3 bucket, and a server you host, one container and Postgres, decides which stacks run and in what order without ever holding cloud credentials.
Stackorder and env zero side by side
Numbers link to the sources at the end of the page. Prices are as published on . A dash means we have not verified that fact for env zero, not that it is missing.
| Feature | Stackorder | env zero |
|---|---|---|
| License | Apache-2.0, open source33 | Proprietary SaaS; its Terraform provider, Terratag and MCP server are open source3 |
| Deployment | Self-hosted; setup mode creates the GitHub App from a manifest26, 30 | SaaS only, optionally with self-hosted agents; the control plane cannot be self-hosted4 |
| Pricing | Free and open source; you run the server33 | Free: 250 runs a month, 30 active environments, 1 concurrent run, 1 self-hosted agent. Cloud Navigator and Cloud Pilot: custom, priced per successful apply or environment1, 4 |
| Maturity | v0.1.0, first released 2026-09-30; tested end to end against LocalStack, not yet against real AWS or a real GitHub organization by default31, 32 | —not verified |
| Where Terraform runs | Your GitHub Actions runners, GitHub-hosted or self-hosted; it manages no runners or agents22 | env zero-hosted agents by default, or self-hosted Kubernetes or Docker agents in your infrastructure5, 6 |
| State backend | Bring your own S3; never takes or releases the state lock22 | Optional env zero remote backend with locking and versioning, which can store state in your own S3 bucket; or a standard backend such as S38 |
| Modules | No registry; lists each module's consumers, and for git modules the version each pins and how far behind it is22 | Private module and provider registry, with download counts and the environments using each module11 |
| Self-hosted footprint | One container of about 30 MB and Postgres; actions that use no Docker22 | SaaS control plane. Kubernetes agent: Kubernetes 1.24 or later, one pod per deployment requesting at least 460m CPU and 1500Mi memory7 |
| Cross-stack dependencies | A graph of stacks and modules from depends_, module sources and terraform_ reads, including cross-repository edges; applies in waves23, 24 | Workflows, in which each environment lists what must deploy first under needs; Workflow Triggers chain deploys9, 10 |
| Cloud credentials | Not held by the server; the runner assumes your IAM role with its own GitHub OIDC token25 | On hosted agents, env zero authenticates to your cloud: assume-role, stored keys, or OIDC tokens it issues; self-hosted agents read your own secret store7, 21 |
| Human sign-in | GitHub OAuth through the App, read:org scope only26 | —not verified |
| Git hosts | GitHub only, by design22 | GitHub, GitLab, Bitbucket and Azure DevOps; self-hosted GitHub Enterprise Server, Bitbucket Data Center and GitLab through an agent19 |
| OpenTofu | Yes, with tool: tofu; tested end to end with OpenTofu 1.1229, 31 | Yes; OpenTofu is the default binary20 |
| Drift detection | Scheduled per stack with drift.; with open_, one GitHub issue per drifted stack, closed when the drift is gone; never applies to fix drift27 | Scheduled per environment, with alerts; optional automatic remediation by redeploying or opening a pull request12, 13 |
| Policy checks | Not a policy engine; run OPA, conftest, Checkov or Infracost in hooks, and stackorder check records a named check the apply gate honors28 | OPA approval policies after plan and cost estimation, not enforced on pull request plans; cost estimates through Infracost14, 15 |
| Pull request workflow | A check per stack, one sticky comment, and stackorder plan, apply and unlock comments; applies before merge by default, or on merge23 | Plans on pull requests as a comment and status checks; plan and apply from comments, open to any commenter unless RBAC enforcement is turned on16, 17 |
Key differences
A SaaS control plane or a server you run
env zero is SaaS only: self-hosted agents can run deployments in your infrastructure, but the control plane cannot be self-hosted. Stackorder is open source and self-hosted: one container and a Postgres database.
Where Terraform runs
env zero runs deployments on its own hosted agents by default, or on self-hosted Kubernetes or Docker agents that make outbound connections only. It does not use GitHub Actions to execute runs; its CLI can drive env zero from any CI. Stackorder runs every plan and apply on your GitHub Actions runners and manages no agents.
Credentials
On hosted agents, env zero's own infrastructure authenticates to your cloud, by assuming a role from its AWS account with an External ID, with stored access keys, or with OIDC tokens that env zero issues. Self-hosted agents instead read credentials from your own secret store by default. The Stackorder server never touches cloud credentials: each GitHub Actions job assumes your role with its own GitHub OIDC token.
Dependencies
env zero groups environments into Workflows, where each one lists the environments that must deploy before it, and Workflow Triggers chain deploys between environments. Stackorder infers edges from module sources and terraform_remote_state reads as well as depends_on, plans downstream stacks in the pull request, and applies in waves.
Governance
env zero evaluates OPA approval policies after plan and cost estimation, estimates cost through Infracost, and can remediate drift by redeploying or opening a pull request. Stackorder is not a policy engine and never applies to fix drift: it records the verdicts of the tools you run in hooks, and keeps one GitHub issue per drifted stack when open_issue is on.
Git hosts and pricing
env zero works with GitHub, GitLab, Bitbucket and Azure DevOps. On 2026-09-30 its free plan allowed 250 runs a month, and its paid tiers were priced by quote. Stackorder is GitHub only, by design, and free under Apache-2.0.
Where env zero is strong
- A managed platform: there is no control plane for you to run.4
- OpenTofu as the default binary, from a founding member of OpenTofu.20
- Scheduled drift detection with alerts, and automatic remediation by redeploying or opening a pull request.12, 13
- OPA approval policies evaluated after plan and cost estimation.14
- An optional managed remote backend that can store state in your own S3 bucket.8
- A private registry for modules and providers that shows which environments use each module.11
- GitHub, GitLab, Bitbucket and Azure DevOps, plus self-hosted Git servers through an agent.19
- Self-hosted agents that make outbound connections only and keep secrets in your infrastructure.6
- A free plan with 250 runs a month and one self-hosted agent.4
When to choose which
Choose Stackorder when
- Your code is on GitHub and you want Terraform or OpenTofu to run on your own GitHub Actions runners, under AWS roles the runner assumes with its own GitHub OIDC token.
- You have many stacks that depend on each other or on shared modules, and you want a change planned everywhere it lands and applied in dependency waves.
- You want a small open-source server you host yourself, which holds no cloud credentials and no state, and whose outage pauses applies but not pull request plans.
Choose env zero when
- You want a managed governance layer with approval policies, cost estimation, drift remediation and a private registry.
- Your code is on GitLab, Bitbucket or Azure DevOps, or spread across several Git hosts.
- You accept a vendor-hosted control plane with quote-based paid tiers, and want no server of your own to run.
- You want more production use behind the tool than Stackorder has yet: its first release, v0.1.0, came out on .
Try Stackorder on your own repositories
Free and open source under the Apache License 2.0. The getting started guide takes one repository from nothing to a first stackorder apply; the local demo runs on one machine with no GitHub App and no AWS account.