Integrations
Stategraph works with the cloud providers, infrastructure as code tools, CI systems, and external tools that you already use.
Orchestration runs plans and applies for pull requests on your GitHub Actions or GitLab CI runners. The stategraph CLI runs where your pipeline runs today. Both authenticate to your cloud like any other job there. The Stategraph server does not run your plans and applies.
Cloud providers
Give Orchestration credentials for the cloud that your code manages. Each guide covers static credentials for a quick start and OIDC for production.
- AWS: IAM access keys or an IAM role assumed through OpenID Connect
- GCP: a service account key or Workload Identity Federation
- Azure: a service principal secret or Entra ID federated credentials
- Other providers: the pattern for any provider that reads a token from an environment variable
IaC tools
Orchestration runs Terraform by default. To run OpenTofu, the stategraph CLI, Terragrunt, Pulumi, CDKTF, or a custom command, set engine in .stategraph/config.yml.
- Terraform: the default engine, and how to pin its version
- OpenTofu: the
tofuengine - Terragrunt: the
terragruntengine - Pulumi: the
pulumiengine - CDKTF: the
cdktfengine - Migrate from Terraform Cloud: move to Orchestration
CI and orchestrators
Use Infrastructure as a Database under your current CI system or orchestrator. Your triggers and approvals stay, and the stategraph CLI plans and applies.
- GitHub Actions: plan on pull requests and apply on merge, in plain workflow YAML
- GitLab CI: the same flow on GitLab, with a sticky merge request note
- Atlantis: keep comment-driven automation, and replace the Terraform commands with two
runsteps - Spacelift: run the CLI through the Spacelift custom workflow tool
External tools
- OPA: enforce policies on plans with Open Policy Agent and Conftest
- Infracost: cost estimates in pull requests
- Security scanning: static analysis with Checkov
- Webhooks: connect external systems
- AI integrations: AI feedback on plan and apply results in pull requests
- Installing packages: add packages to the runner