TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Folks who use Atlantis for Terraform Self Service – what pains you?

2 点作者 ujnproduct大约 2 年前
We are building an Open Source GitOps tool for Terraform (https:&#x2F;&#x2F;github.com&#x2F;diggerhq&#x2F;digger) and are looking for what’s missing. We also read &amp; asked around. We found the following pain points already, curious for more:<p>1. In Atlantis,anyone who can run a plan, can exfiltrate your root credentials(https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=H9KvPe09f5A). This was talked about by others (https:&#x2F;&#x2F;alex.kaskaso.li&#x2F;post&#x2F;terraform-plan-rce) and was highlighted at the Defcon 2021 conference(https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=3ODhxYY9-9U). (CloudPosse)<p>2. “Atlantis shows plan output, if it&#x27;s too long it splits it to different comments in the PR which is not horrible, just need to get used to it.” (User feedback)<p>3. Anyone that stumbles upon your Atlantis instance can disable apply commands, i.e. stopping production infrastructure changes. This isn’t obvious at all, and it would be a real head scratcher to work out why Atlantis suddenly stopped working! (Loveholidays blog - https:&#x2F;&#x2F;tech.loveholidays.com&#x2F;enforcing-best-practice-on-self-serve-infrastructure-with-terraform-atlantis-and-policy-as-code-911f4f8c3e00)<p>4. “Atlantis does not have Drift Detection.” (Multiple users)<p>5. “The OPA support in atlantis is very basic.” (Multiple users)<p>As CloudPosse themselves explain (https:&#x2F;&#x2F;cloudposse.com&#x2F;faqs&#x2F;why-do-you-recommend-spacelift&#x2F;) - “Atlantis was the first project to define a GitOps workflow for Terraform, but it&#x27;s been left in the dust compared to newer alternatives.” The problem though is that none of the newer alternatives are Open Source, and this is what we want to change. Would be super grateful for any thoughts&#x2F;insights and pain points you have faced.

暂无评论

暂无评论