A Kubernetes operator for Terraform

Magos runs Terraform inside Kubernetes. The controller spawns a short-lived pod for every plan and every apply, then tears it down. No shared runner, no long-lived shell, no company behind it.

Built by folks who worked on Terraform, Atlantis, Kubernetes.

VCS

Infrastructure

Sync
MagosGitOps Orchestrator
Orchestrate

Execution

State

Three properties we will not trade away.

Every decision in Magos has to preserve them. Compromise one and the feature does not ship. Opinionated software, written by engineers with backgrounds at HashiCorp, Microsoft, GitHub, AWS, and Google who have run Terraform at scale.

  • Per-Workspace pod isolation. Every plan and every apply runs in its own short-lived pod with its own PVC. Two Workspaces never see each other's plan, credentials, or providers.
  • Policy gates on plan output. Magos uses Kyverno ValidatingPolicy. The plan pod evaluates every matching policy against the plan JSON. A violation blocks apply before any cloud API has been touched.
  • Bring your own backend. State lives wherever your module's backend block puts it. S3, GCS, Postgres, or whatever your team already runs. Magos does not store, lock, or proxy state.