How Zip's Security Team Led Infrastructure Modernization
Zip transformed their infrastructure management by empowering their security team to lead the Terraform rollout, implementing secure GitOps practices with Stategraph.
"We wanted to keep everything in the pull request flow. Stategraph gave us everything we needed, and it was significantly cheaper."
— Victor Chen
Security-First IaC
Security team-led infrastructure modernization with built-in guardrails
Lightning Fast
Near-instant Terraform plans with self-hosted runners
Team Empowerment
130+ engineers confidently managing infrastructure
The Challenge
With over 130 engineers and growing AWS usage, Zip needed to shift from manual infrastructure management to Infrastructure as Code while maintaining security and control.
Key Pain Points
- Manual AWS console configuration
- Limited visibility and auditability
- Risk of human error in changes
"We were importing all the infrastructure and creating the IaC from scratch. There weren't any Terraform workflows, just a lot of manual config in the console or CLI."
— Security Engineer at ZipWhy Stategraph
After evaluating Atlantis, Spacelift, and Terraform Cloud, Zip chose Stategraph for its GitHub-native approach, powerful security controls, and cost-effectiveness.
Key Benefits
- GitHub-native workflow
- Built-in security controls
- CDK support
"You only need to know three commands. It's all in the pull request. No navigating to another UI. No extra fluff."
— Security Engineer at ZipThe Results
Zip successfully transformed their infrastructure management with a security-first, GitOps-native approach that enables safe, efficient changes at scale.
- Manual AWS console changes
- No standardized workflows
- Risk of accidental deletions
- GitOps-native IaC workflow
- Built-in security guardrails
- Lightning-fast deployments
"With self-hosted runners, it was just lightning fast. Instant plans. Amazing experience."
— Security Engineer at ZipShip Terraform through pull requests
Stategraph Orchestration brings plan, policy, and apply to the pull request, on the infrastructure database.