Open source infrastructure-as-code projects
Every project in the registry tagged infrastructure-as-code, ranked by real GitHub adoption.
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
Software to automate the management and configuration of infrastructure and applications at scale.
The AWS Cloud Development Kit is a framework for defining cloud infrastructure in code
The Cloud Native Control Plane
Meshery, the cloud native manager
Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by
GoCD - Continuous Delivery server main repository
Tfsec is now part of Trivy
Quick and Easy server testing/validation
Terraform automation with pull request workflows
Tools for managing DNS across multiple providers
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS b
The simplest, most powerful way to build a functional web app (fwa)
Testinfra test your infrastructures
KCL Programming Language Core and API (CNCF Sandbox Project). https://kcl-lang.io
Fix Inventory helps you identify and remove the most critical risks in AWS, GCP, Azure and Kubernetes.
Cloud-native framework for infrastructure from code
GitOps orchestration for infrastructure as code
Related tags
Frequently asked questions
How many open source infrastructure-as-code projects are there?
This registry tracks 18 projects tagged infrastructure-as-code, with 144,267 GitHub stars between them. The most-adopted is trivy at 37,961 stars.
Are these infrastructure-as-code projects free to use?
Yes — 18 of the 18 carry an explicit open-source licence across 3 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.
Which infrastructure-as-code project should I choose?
The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.
Are these infrastructure-as-code projects still maintained?
15 of the 18 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.