If you run Terraform or OpenTofu across several teams, you know the pain: hand-built CI pipelines, credentials in pipeline variables, scattered state files, and compliance checks after deployment. StackGuardian is an infrastructure as code (IaC) automation and governance platform that brings execution, credentials, state, and policy as code into one place, so every infrastructure change follows one trusted standard.
What you need
A StackGuardian account, a Git repo with a small Terraform project, an AWS, Azure, or GCP sandbox, and permission to create an IAM role or equivalent. For GitHub, you also need organization admin rights to install the StackGuardian GitHub App.
Connect Git and your cloud
On first sign-in, choose GitOps for IaC and name your organization. If you signed up with GitHub, onboarding asks you to install the GitHub App, which becomes your first VCS connector, so don't create it again. Instead of projects, StackGuardian organizes workflows into Workflow Groups, usually mapped to environments or teams. Connect GitHub, GitLab, Bitbucket, or Azure DevOps to trigger runs on pull requests, pushes, or tags. For AWS, use OIDC federation: runs get temporary credentials, and no long-lived secrets are stored. Azure and GCP have their own connectors.
Create a workflow
In a Workflow Group, create a Terraform or OpenTofu workflow pointing to your repo, branch, and working directory. Add parameters, and reference secrets from the StackGuardian vault or a supported external vault so they never appear in your configuration. Select your cloud connector, keep the managed backend on for versioned state, and enable approvals. Use a private runner if executions must stay in an environment you control. Beyond built-in types like Ansible, Kubernetes, and CloudFormation, custom workflows bring any toolset onto the platform.
Plan, review, apply
Click Create Run. StackGuardian plans, evaluates policies, and pauses for approval. The summary shows resource changes and Infracost estimates, using a built-in key or your own. Approve, and the apply runs.
Add a guardrail
Policies use Tirith, StackGuardian's open-source policy as code framework, and you can bring existing Open Policy Agent (OPA) and Checkov policies (see supported policy types). Start from 250+ marketplace templates or a no-code builder. For example, a rule allowing only t3.micro for aws_instance stops non-compliant plans before they reach your cloud.
Where to go next
Add PR-triggered plans and Stacks for multi-layer infrastructure. To catch changes made outside Terraform, ask the StackGuardian team to enable drift detection. For resources never written as code, SGCode discovers them and generates code for review, then opens a pull request and runs a plan. The managed runtime supports Terraform up to 1.5.7; for newer versions, use OpenTofu or a custom runtime image.
Check out https://www.stackguardian.io/ for more details.
Top comments (0)