Engineering Leadership & Technical HiringPlaybook3 min readUpdated September 2026

Terraform vs. Pulumi: Building Real Governance Into Your IaC

Most teams adopt infrastructure as code for speed and only think about governance after a bad apply takes down production. Terraform and Pulumi solve the same core problem, turning infrastructure into versioned, reviewable code, but they differ enough in how state, policy, and modules work that your governance model has to fit the tool you picked, not a generic checklist.

This is a practical comparison of where each tool makes governance easy and where it makes you build the guardrails yourself.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

State Locking and Drift Are Where Both Tools Actually Break

Terraform's state file is the ground truth for what it thinks exists, and if two engineers run apply against the same workspace without a remote backend that locks state, you get a corrupted or conflicting state file. Pulumi has the same problem with its own state backend. Neither tool fixes this by default. The fix is the same for both: a remote backend (S3 with DynamoDB locking, Terraform Cloud, or Pulumi's managed service) so applies queue instead of racing. Drift, someone changing a resource by hand in the console, is the other failure mode, and both tools need a scheduled plan-only run that alerts on any diff, not just a manual check before the next deploy.

Policy as Code: Sentinel and OPA vs. Pulumi CrossGuard

Terraform's policy layer is bolted on: Sentinel if you're on Terraform Cloud/Enterprise, or Open Policy Agent's Rego language if you're running open source with a tool like Conftest. Pulumi's CrossGuard runs policy checks in the same general-purpose language (TypeScript, Python, Go) as your infrastructure code, so a rule like "no public S3 buckets" or "every resource needs a cost-center tag" reads like a unit test instead of a separate DSL. If your engineers already write policy exceptions in code review comments instead of enforced checks, that's the gap. The choice between Rego and a general-purpose language is really a choice about who's writing the policies: a dedicated platform team can learn Rego; a smaller team reuses skills it already has in CrossGuard.

Module Registries and Who's Allowed to Publish Them

Both tools support reusable modules or components, and both let any engineer publish one without review unless you set up a registry with an approval step. The governance question isn't whether modules exist, it's whether a module that provisions a database or opens a security group has been reviewed once, centrally, instead of copy-pasted and modified twenty times across repos. A private registry (Terraform's or Pulumi's) with a required review on new module versions turns "everyone reinvents the VPC module" into "everyone imports the same reviewed one."

For example, if three teams each copy and modify a VPC module, a security fix made in one copy never reaches the others. Publish one reviewed VPC module in a private registry, require review on every new version, and have teams import it instead of copying it. When the security team later tightens ingress rules, that change ships once, passes through the same approval step as everything else, and appears in every team's next plan as a visible diff. The common mistake is setting up the registry but leaving publishing open to everyone, which recreates the sprawl with extra steps.

Where Compliance Evidence Actually Comes From

Federal binding operational directives put a hard clock on remediating known, internet-facing vulnerabilities once they're detected1, and the same discipline applies to infrastructure drift: if a plan shows an unapproved change, treat it the way you'd treat an unpatched CVE, on a clock, not a backlog. Compliance platforms like Vanta and Drata can pull evidence directly from your CI pipeline, the plan output, the approval, the apply log, instead of an engineer manually screenshotting a console for an auditor. That only works if your pipeline actually gates on a human approval step; if applies run unattended on merge, there's no evidence to collect.

A Governance Baseline That Fits Either Tool

Regardless of which tool you use: require a plan on every pull request with the diff visible to the reviewer, require a second approver before apply on production workspaces, lock state with a remote backend, run policy checks in CI before the plan is even shown for review, and schedule a nightly drift check that pages someone instead of waiting for the next deploy to surface it. None of this depends on Terraform versus Pulumi specifically. It depends on treating infrastructure changes with the same review discipline as application code, not a faster, looser path around it.

The same baseline as a checklist you can adopt this week:

  • Require a plan on every pull request, with the diff visible to the reviewer.
  • Require a second approver before apply on production workspaces.
  • Lock state with a remote backend so applies queue instead of racing.
  • Run policy checks in CI before the plan is even shown for review.
  • Schedule a nightly drift check that pages someone instead of waiting for the next deploy to surface a diff.
Executive Capability Standard

What Good Looks Like

Good IaC governance means every change to production infrastructure goes through the same pull request, plan, and review path, with no console click-ops, and the state file stays the single source of truth.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Read your team's actual Terraform or Pulumi plan diffs for a month before writing any policy rules.
2. Do Manually:Require a second engineer to read every plan output before apply runs against a production workspace.
3. Delegate:Give a platform or infrastructure engineer ownership of the module registry and the policy rule set.
4. Automate:Wire policy-as-code checks into the CI pipeline so a plan that violates a rule fails the pull request, not the apply.
5. Buy:Adopt a compliance platform that pulls evidence straight from your IaC pipeline instead of manual screenshots for every audit cycle.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Vanta

Pulls plan and approval evidence straight from your IaC pipeline for SOC 2 or ISO audits instead of manual screenshots.

Visit Vanta→
Drata

Maps infrastructure change controls to your compliance framework so an auditor can trace a plan back to its approval.

Visit Drata→

Frequently Asked Questions

Do we need Sentinel or OPA if we're a five-person engineering team?

Probably not yet. A required pull request review plus a remote state backend with locking covers most of the risk at that size. Add policy as code once you have more than one team touching shared infrastructure, or once a mistake in a plan has actually reached production.

Can we migrate from Terraform to Pulumi without a rewrite?

Pulumi can import existing Terraform-managed resources into its own state, and there are converters for straightforward modules, but anything with heavy use of Terraform-specific functions or provider quirks needs manual review. Treat it as a resource-by-resource migration, not a one-shot conversion, and validate each imported resource's plan shows no unexpected changes.

What's the actual risk of letting applies run unattended on merge?

An unattended apply skips the last human check on a plan that might delete or replace a resource the plan output described ambiguously. It also means there's no evidence trail of who approved a given change, which is exactly the artifact a compliance platform or an auditor asks for.

Sources

Where we quote a benchmark, we show its source. Other figures in this guide are estimates or general guidance, so check them against your own numbers.

  1. Security patch remediation SLAs (CISA federal mandates, used as industry norm). CISA Binding Operational Directives 19-02 and 22-01 (CISA briefing hosted at NIST CSRC), 2022.

Related Guides