Terrakube
A free, self-hosted platform for running Terraform and OpenTofu as a team — shared remote runs, a private module registry, and single sign-on — built to replace what Terraform Cloud or Terraform Enterprise charge for.
🔗 Visit TerrakubeDescription
If you've used Terraform beyond a solo project, you've hit the same wall every team hits: someone needs to own the shared state file, control who can run 'apply' against production, and keep reusable modules somewhere private. Terraform Cloud and Terraform Enterprise sell that as a product; Terrakube gives you the same capability as free, open-source software you run yourself — like the difference between renting a shared office and just owning the building.
Terrakube is an Apache 2.0-licensed platform for running Terraform and OpenTofu remotely, with a visual UI for inspecting state and runs, a private module and provider registry, role-based access control, and single sign-on across a long list of identity providers (Azure Entra ID, Google Cloud Identity, AWS Cognito, GitHub, Keycloak, OIDC, SAML). It supports dynamic short-lived credentials for AWS/Azure/GCP/Vault/OpenBao instead of long-lived secrets, integrates OPA for policy checks and Infracost for cost estimates in plans, and connects to GitHub, GitLab, Bitbucket, or Azure DevOps for version control. It deploys to Kubernetes (Helm) or Docker Compose. With ~950 GitHub stars and over 2,200 commits, it's one of the more established projects in this open-source Terraform-platform niche.
💬 Our review
The short version: Terrakube is the most mature, feature-complete open-source alternative to Terraform Cloud/Enterprise available today — if you're going to self-host this category of tool instead of paying HashiCorp, this is the safer default to start evaluating.
What sets it apart from newer entrants like Terrapod is track record: nearly a thousand stars, 2,000+ commits, and years of iteration mean the rough edges of a young open-source infra tool have mostly been sanded off. Feature-for-feature it covers what teams actually need — SSO across enterprise identity providers, dynamic cloud credentials instead of static secrets, OPA policy gates, and cost estimates via Infracost — which is a genuinely enterprise-grade feature set for a free tool.
The honest limits: it's still self-hosted infrastructure you're responsible for operating, patching, and backing up — there's no managed cloud option here, unlike Terraform Cloud's free tier for small teams. And while it's the most established open-source option in its niche, that niche itself is small; you're trading the safety of a vendor-backed product for full control and zero license fees. If you want the same idea with an even leaner footprint that runs inside your existing CI rather than as a standalone server, Digger/OpenTaco or Atlantis are worth comparing before you commit to running another service.
💰 Pricing
📊 Global score
🤖 AI-enriched data
Open source (licence Apache 2.0), gratuit, auto-hébergé via Kubernetes (Helm) ou Docker Compose.
Pros
Projet mature (~950 étoiles, 2200+ commits) — le plus établi de sa catégorie open source
SSO large (Azure Entra ID, Google, AWS Cognito, GitHub, Keycloak, OIDC, SAML)
Credentials cloud dynamiques (pas de secrets statiques) pour AWS/Azure/GCP/Vault
Intégration OPA (policy-as-code) et Infracost (estimation de coûts) intégrées
Cons
Auto-hébergement obligatoire — pas d'offre cloud managée, contrairement à Terraform Cloud (palier gratuit)
Responsabilité complète de l'exploitation, des mises à jour et des sauvegardes
Alternative plus légère existe (Atlantis, Digger) si vous voulez éviter de faire tourner un serveur dédié
