Pulumi vs. Spacelift: Pricing, Lock-in, and the Layer Most Buyers Get Wrong
Sources
- Pulumi pricing — Free/Essentials/Pro/Enterprise editions, credit rates (verified 2026-09-29)
- pulumi/pulumi — Apache-2.0 open-source engine, 25.7k stars (verified via GitHub API 2026-09-29)
- Pulumi's own comparison page — Pulumi vs. Spacelift (vendor marketing; treat accordingly)
- Pulumi's own comparison page — Pulumi vs. Terraform Cloud (vendor marketing; treat accordingly)
- Spacelift pricing — Free/Starter+/Business/Enterprise/Enterprise+ plans (verified 2026-09-29)
- Spacelift docs — Pulumi support is a feature preview; module CI/CD and import unavailable (verified 2026-09-29)
- Spacelift Series C — $51M led by Five Elms Capital, July 2025
- Spacelift statement on HashiCorp's BSL license change, August 2023
- Spacelift — Spacelift vs. Terraform Cloud comparison page (vendor marketing; treat accordingly)
- HashiCorp docs — HCP Terraform plans, features, concurrency limits, billing models (verified 2026-09-29)
- HashiCorp docs — HCP Terraform cost estimation, $0.0001359/resource-hour Essentials worked example (verified 2026-09-29)
- IBM — completed acquisition of HashiCorp for $6.4B, February 27, 2025
- OpenTofu — Linux Foundation project, drop-in Terraform alternative, 3,900+ providers
- opentofu/opentofu — MPL-2.0 license, 30.3k stars (verified via GitHub API 2026-09-29)
- runatlantis/atlantis — Apache-2.0 Terraform pull-request automation, self-hosted
- Hacker News — Pulumi 3.0 announcement thread, 321 points (April 2021)
- Hacker News — 'Pulumi AI is poisoning Google search results with AI answers' criticism thread, 95 points (April 2024)
You typed "pulumi vs spacelift" because you are about to spend money on an infrastructure-as-code platform and the shortlist came down to these two names. Here is the procurement-grade answer, and the first thing you need to know is that this comparison contains a category error that most buyers discover only after signing. Pulumi and Spacelift are not competitors. Pulumi is an engine — the thing that translates code into cloud resources. Spacelift is an orchestration platform — the thing that runs whatever engine you already use, adds policies, and manages state and runs at scale. Spacelift can literally run Pulumi stacks for you (in feature-preview status). The real market is four-way: Pulumi Cloud, HCP Terraform, Spacelift, and the free OpenTofu-plus-Atlantis stack — and which one wins depends on which layer you are actually shopping for.
Every price below was verified from the vendors' own pricing pages and documentation on 2026-09-29 — treat any number older than a quarter as stale and re-verify before you sign. We have no financial relationship with any vendor on this page; all links are direct and untracked, and no vendor saw this page before publication.
TL;DR — the 30-second verdict
| Your situation | Pick | Why |
|---|---|---|
| Your team wants real programming languages (TypeScript, Python, Go) and one vendor for engine + control plane | Pulumi Cloud | Apache-2.0 engine, generous free tier, $40/month entry; component reuse and Automation API are genuine productivity multipliers — but the control plane bills every declared resource, including components and stacks |
| You have Terraform or OpenTofu in production, multiple IaC flavors (Ansible, Kubernetes, CloudFormation), and need governance above them | Spacelift | The strongest orchestration layer on the market: policies, drift detection, private workers, OpenTofu-first posture — but real features start at $20,000/year and its Pulumi support is still preview-grade |
| You are an all-Terraform shop that wants the least-friction managed control plane and already lives in the HashiCorp ecosystem | HCP Terraform | Cheapest per-resource billing of the three ($0.0001359/resource/hour at Essentials — about $98/month per 1,000 resources), but governance features gate you into quote-only tiers, and the platform is now owned by IBM |
| License terms matter more than features, or budget is near zero and you have platform-engineering capacity | OpenTofu + Atlantis | OpenTofu is a Linux Foundation, MPL-2.0 drop-in Terraform replacement; Atlantis gives you PR-based plan/apply for free — you pay with operational toil instead of dollars |
| You came here to run Pulumi inside Spacelift | Pulumi Cloud, for now | Spacelift's Pulumi support is a documented feature preview — no module CI/CD, no import — fine to pilot, risky to standardize on in 2026 |
The two layers, and where each vendor sits
The IaC market is a two-layer stack, and vendors deliberately blur the boundary because the layer you pay for is the layer they want you to think is inseparable from theirs. It is not. The engine layer is free and open source in every direction; the control plane is where every dollar on this page goes.
WHAT YOU WRITE -- the engine layer (free, open source)
+----------------+-------------------+-------------------+
| Pulumi SDKs | Terraform (HCL) | OpenTofu (HCL) |
| TypeScript, | HashiCorp core, | Linux Foundation, |
| Python, Go, | BSL-licensed | MPL-2.0, drop-in |
| .NET, Java,YAML| | Terraform clone |
+--------+-------+---------+---------+--------+----------+
| | |
v v v
WHO RUNS IT -- the control-plane layer (this is what you pay for)
+----------------+----------------+----------------+----------------+
| Pulumi Cloud | HCP Terraform | Spacelift | Atlantis / DIY |
| runs Pulumi | runs Terraform | orchestrates | self-hosted |
| programs only | (IBM-owned) | every engine | CI; runs |
| $40/mo entry | ~$98/mo per | above; $20k/yr | whatever you |
| | 1k resources | entry | feed it; $0 |
+----------------+----------------+----------------+----------------+
Read the diagram literally: "pulumi vs spacelift" is a question about two different rows. If you pick Pulumi the engine, your control-plane choices are Pulumi Cloud, Spacelift (preview), or DIY CI. If you pick Spacelift the control plane, your engine choices are OpenTofu, Terraform, Terragrunt, Pulumi, Ansible, CloudFormation, or Kubernetes manifests — Spacelift is engine-agnostic by design. Vendors on both sides run comparison pages against each other anyway: Pulumi publishes a Spacelift comparison and Spacelift publishes a Terraform Cloud one — both are marketing documents from parties with a horse in the race; treat their claims as leads, not evidence.
| Product | What it actually is | Engine(s) it runs | License of the core | What you pay for |
|---|---|---|---|---|
| Pulumi | IaC engine + first-party cloud control plane (Pulumi Cloud) | Pulumi programs (TS, Python, Go, .NET, Java, YAML); can consume any Terraform provider | Apache-2.0 (engine) | Managed resources, secrets, workflow minutes — metered in credits |
| Spacelift | Orchestration and governance platform for IaC (a "TACOS" — Terraform Automation and Collaboration Software) | OpenTofu, Terraform, Terragrunt, Pulumi (preview), Ansible, CloudFormation, Kubernetes | Proprietary SaaS (self-hosted option at top tier) | Workers and plan tier — annual contract, not usage |
| HCP Terraform | HashiCorp's managed control plane for Terraform (formerly Terraform Cloud) | Terraform only | BSL 1.1 (engine) — no longer open source | Managed resources per hour, pay-as-you-go or contract |
| OpenTofu + Atlantis | Community engine + self-hosted PR automation | OpenTofu (drop-in Terraform alternative) | MPL-2.0 (OpenTofu), Apache-2.0 (Atlantis) | Nothing — you pay with your own engineering time |
Pricing models, translated (as of 2026-09-29 — verify with each vendor)
The three commercial platforms meter three different things, and none of the pricing pages says the failure mode out loud. Pulumi Cloud bills declared resources — every resource in every Pulumi program, including component resources and stacks themselves, billed hourly with partial hours rounded up. HCP Terraform bills managed resources per hour — resources actually in state, with each hour billed at that hour's peak resource count, so a bad pipeline that creates 500 throwaway resources at 2 PM inflates that hour's bill. Spacelift doesn't meter resources at all — it sells capacity and tiers: an annual contract with a fixed worker count, which makes cost predictable but makes the entry price a five-figure commitment.
| Plan | Pulumi Cloud | HCP Terraform | Spacelift |
|---|---|---|---|
| Free tier | $0 — 1 user, unlimited projects/stacks, state management, Pulumi Deployments, up to 500 workflow minutes, 25 secrets, 10K ESC API calls/month. "Free forever for open source and individuals" | $0 — up to 500 managed resources, 1 concurrent remote run, VCS integration, SAML SSO | $0 — 2 users, 1 public worker, no time limit ("always free for small teams") |
| Entry paid tier | Essentials $40/month (includes 40 credits ≈ up to 500 managed resources); unlimited users | Essentials — $0.0001359 per managed resource-hour (≈$0.10/resource/month); their own worked example: 1,000 resources ≈ $97.85/month | Starter+ $20,000/year — unlimited users, 2 public workers, 1 private worker; annual contract, 14-day post-signing cancellation window only |
| Mid tier | Pro $400/month (400 credits ≈ up to 2,000 resources; SAML/SSO, preventative policies, drift detection, TTL stacks) | Standard — quote-only; adds policy enforcement, cost estimation, 10 remote + 10 agent concurrent runs | Business — quote-only; 3 private workers, blueprints, advanced scheduling, private provider registry |
| Top tier | Enterprise $2,000/month (2,000 credits ≈ up to 4,750 resources; self-hosting, SCIM, conformance packs, remediation policies) | Premium — quote-only; audit logging, 200 remote + 300 agent concurrent runs, priority support | Enterprise / Enterprise+ — quote-only; 5–30 private workers, SSO, audit trail, self-hosted / FedRAMP / air-gapped at the top tier |
| What is NOT in the sticker | Secrets ($0.50–$1.00/secret/month), workflow minutes ($0.01/min beyond the pool), Neo AI tokens ($3/million); unused monthly credits expire | Additional concurrency is a separate purchase on Standard/Premium; agents for private infra are an Enterprise feature | Additional private workers are quote-priced; annual-only above the free tier |
Two mechanics worth internalizing before you sign anything. First, Pulumi's credit system: one credit = $1, your edition's base fee pre-purchases a pool (40/400/2,000), usage draws it down at list rates, unused credits expire monthly, and overage is billed in arrears. Second, HCP Terraform's peak-hour rule: "the peak number of managed resources in a given hour determines the cost for that hour," per HashiCorp's billing docs — ephemeral environments are billed like permanent ones for every hour they exist.
Worked cost: the same 1,000 / 3,000 / 10,000-resource estate
List prices, full-month continuous operation, no discounts, rounded to the dollar. Pulumi figures assume the cheapest edition that makes sense at that size; HCP Terraform is Essentials pay-as-you-go; Spacelift is the Starter+ annual contract divided by twelve.
| Managed resources | Pulumi Cloud | HCP Terraform | Spacelift |
|---|---|---|---|
| 1,000 | $131/month (Essentials: $40 base + 500 × $0.1825) | $98/month (Essentials PAYG) | $1,667/month equivalent (Starter+ $20,000/yr) |
| 3,000 | $765/month (Pro: $400 base + 1,000 × $0.365) | $294/month (Essentials PAYG) | $1,667/month equivalent |
| 10,000 | $3,320/month (Pro: $400 base + 8,000 × $0.365) | $978/month (Essentials PAYG) | $1,667+/month equivalent (worker count needs a quote) |
Read that table twice, because the ordering surprises people: at pure resource-metering, HCP Terraform is the cheapest control plane per resource, by roughly 3× at every size — until you need policies, cost estimation, or more than 3 concurrent runs, at which point Standard (quote-only) takes over and the public math ends. Pulumi's premium buys you the language layer and component model, not cheaper metering. And Spacelift's flat fee only wins as a value proposition when governance, multi-engine support, and private workers are requirements you would otherwise build yourself — no one should choose Spacelift to save money on state storage.
The plot twist: Spacelift can run Pulumi — but read the fine print
Because the layers are separable, the "vs" question has a secret fourth answer: both. Spacelift added Pulumi as a supported platform, which makes the combination a legitimate pilot for polyglot teams. But Spacelift's own documentation is unusually blunt about maturity: Pulumi support is a feature preview — "subject to change, may contain bugs, and have not yet been refined based on real production usage" — with two hard limitations: module CI/CD is not available for Pulumi, and import is not supported (you must run a manual task to import existing resources into state).
# Initialization
pulumi login "$PULUMI_LOGIN_URL"
pulumi stack select --create --select "$PULUMI_STACK_NAME" # vendor-specific setting
# Planning
pulumi preview --refresh --diff --show-replacement-steps
# Applying
pulumi up --refresh --diff --show-replacement-steps
The integration is real — plans flow into Spacelift's policy engine as a pulumi JSON document (secrets masked as [secret]), so plan policies, approvals, drift detection, and worker isolation all apply. But the engine's own control plane (Pulumi Cloud) is where Pulumi's Deployments, ESC secrets, and OIDC integrations live, and running Pulumi through Spacelift means paying for the Pulumi state backend separately or self-managing it. For a Pulumi-primary team, Spacelift currently adds governance while subtracting maturity. That trade is only worth it if the rest of your estate is already on Spacelift's supported, non-preview engines.
Vendor verdicts
Pulumi (engine + Pulumi Cloud)
What it does: an Apache-2.0 IaC engine (25.7k GitHub stars) that lets you define infrastructure in TypeScript, Python, Go, .NET, Java, or YAML — and can consume any Terraform provider — plus a first-party cloud for state, deployments, secrets (ESC), policy, and AI (Neo).
Who it's for: teams whose platform group wants software-engineering leverage — components, unit tests, loops, real IDE support — and prefers one vendor owning engine and control plane. The free tier (individuals, unlimited stacks, 500 workflow minutes) is the most generous on this page.
Honest strength: component resources and the Automation API genuinely collapse boilerplate; the pulumi convert path from HCL lowers migration friction; self-hosting exists at the Enterprise edition if the SaaS dependency bothers you.
Honest weakness: the meter counts every declared resource, including components and stacks — an architecture built from many small components bills like a much larger estate than the cloud console shows. Hiring pools skew Terraform. And community trust took a measurable hit in 2024 when Pulumi AI's SEO-optimized answer pages were called out on Hacker News for polluting Google results with AI-generated content — a pattern worth remembering when you evaluate any of their AI features (Neo is metered at $3/million tokens).
Pricing as of 2026-09-29: Free $0 · Essentials $40/mo · Pro $400/mo · Enterprise $2,000/mo; resources $0.1825–$0.5475/resource/month by edition; secrets $0.50–$1.00/secret/month; verify at the Pulumi pricing page. Docs: pulumi.com/docs.
Spacelift (orchestration platform)
What it does: a proprietary orchestration and governance layer that runs OpenTofu, Terraform, Terragrunt, Pulumi (preview), Ansible, CloudFormation, and Kubernetes — with policy-as-code (OPA), drift detection, dependencies, blueprints, and a choice of shared public or customer-hosted private workers.
Who it's for: organizations with multiple IaC flavors and a compliance story to tell. Spacelift's positioning after HashiCorp's BSL license change was explicitly neutral ("no impact to your current operations"), and it has leaned into OpenTofu support — a real differentiator for license-sensitive buyers.
Honest strength: engine neutrality is the whole product — you can adopt OpenTofu or Pulumi without replacing your control plane; private workers run in your cloud; the top tier covers self-hosted, FedRAMP, and air-gapped deployments, which neither Pulumi Cloud (self-host at Enterprise only) nor HCP Terraform matches at every tier.
Honest weakness: pricing structure. The free tier is 2 users with a shared public worker; everything with a private worker starts at $20,000/year, annual, with a 14-day cancellation window that closes once the software is activated. Above Starter+ there are no list prices at all — your procurement process, not your engineers, will spend weeks here. Pulumi support is preview-grade (no module CI/CD, no import). The $51M Series C (July 2025) buys runway, but you are standardizing on a mid-stage vendor, not an IBM.
Pricing as of 2026-09-29: Free $0 (2 users, 1 public worker) · Starter+ $20,000/yr · Business/Enterprise/Enterprise+ quote-only; verify at the Spacelift pricing page. Docs: docs.spacelift.io. Trial: spacelift.io/free-trial.
HCP Terraform (HashiCorp / IBM)
What it does: the managed control plane for Terraform — remote runs, VCS integration, private module registry, workspaces and Stacks — now inside IBM's automation portfolio after the $6.4B acquisition completed February 27, 2025.
Who it's for: all-Terraform organizations that want the path of least resistance and already run other HashiCorp products. The per-resource PAYG model (Essentials) is transparent and cheap at small scale.
Honest strength: the cheapest managed metering on this page (~$98/month at 1,000 resources, ~$978 at 10,000), an enormous ecosystem of modules and providers, and SAML SSO even on the free tier.
Honest weakness: the feature ladder is a quote wall — policy enforcement and cost estimation start at Standard (no list price), audit logging waits for Premium (no list price), and the engine itself is BSL-licensed, which is the single reason OpenTofu exists. IBM ownership cuts both ways: enterprise stability improves; the license question and roadmap attention do not disappear. If your organization has any open-source-policy pressure, this is the vendor it applies to.
Pricing as of 2026-09-29: Free (≤500 resources) · Essentials $0.0001359/resource/hour (their worked example: $97.85/mo at 1,000 resources) · Standard/Premium quote-only; verify at the HCP Terraform plans documentation.
OpenTofu + Atlantis (the $0-license stack)
What it does: OpenTofu is the Linux-Foundation-stewarded, MPL-2.0, drop-in replacement for Terraform — same HCL, 3,900+ providers, 23,600+ modules in its registry. Atlantis is a self-hosted server that turns pull requests into plan/apply workflows.
Who it's for: license-sensitive buyers and teams with the capacity to operate their own control plane. If OpenTofu covers your engine needs, the only thing you were about to pay Spacelift $20k/year for is orchestration — and Atlantis plus your existing CI gets you a defensible 60% of it for free.
Honest strength: license risk drops to zero; OpenTofu tracks Terraform compatibility closely (1.12.x stable, 1.13 in release-candidate as of late September 2026) and adds community features like native state encryption.
Honest weakness: Atlantis is a component, not a platform — no drift detection, no policy engine, no resource visualization, no UI beyond PR comments. Everything Spacelift or HCP Terraform gives you as a product, you now own as a backlog. The cost moves from OpEx to headcount; it is only "cheaper" if your platform engineers were idle.
Pricing as of 2026-09-29: $0 license cost both; your infrastructure and engineering time are the bill. OpenTofu: opentofu.org · Atlantis: github.com/runatlantis/atlantis.
terraform {
required_version = ">= 1.6"
}
provider "aws" {
region = "eu-west-1"
}
resource "aws_s3_bucket" "assets" {
bucket = "pm-assets-example"
}
Feature matrix: what each control plane actually includes
| Capability | Pulumi Cloud | HCP Terraform | Spacelift | Atlantis (self-hosted) |
|---|---|---|---|---|
| State management | Included (all editions) | Included (all plans) | Included (uses engine state backends) | BYO S3/GCS/Azure backend |
| Drift detection | Pro and above | — | Starter+ and above | — |
| Policy as code | Advisory (Essentials) → enforced (Pro+) | Standard and above (OPA/Sentinel) | All paid tiers (OPA-based, plan policies) | — |
| OpenTofu support | Via bridged Terraform providers (HCL not native) | — | First-class, all tiers | First-class |
| Pulumi support | Native (it is the engine) | — | Feature preview — no module CI/CD, no import | — |
| Secrets management | ESC — metered per secret | Integration with Vault, not bundled | Environment-level contexts | BYO (Vault etc.) |
| Runs execute in your cloud | Customer-managed runners (Enterprise feature) | Agents (Standard+, purchasable) | Private workers — Starter+ and above | Always (you host the server) |
| Self-hosted control plane | Enterprise edition | Terraform Enterprise (separate product) | Enterprise+ tier (also FedRAMP / air-gapped) | It already is |
| Free tier for a real team | 1 user only | ≤500 resources, unlimited users | 2 users, shared public worker | Unlimited (you run it) |
Bottom line — what to actually buy
The query that brought you here decomposes into two decisions. Make them in order:
| If you are… | …buy this, because: |
|---|---|
| A platform team choosing an engine, with software engineers who will write IaC daily | Pulumi the engine, managed by Pulumi Cloud — the language layer is the productivity claim; budget for component-inflated metering and validate your resource count before the first bill, not after |
| A multi-team org with Terraform/OpenTofu in production, adding compliance requirements | Spacelift — engine-neutral orchestration with private workers from day one; go in knowing everything beyond Starter+ is a negotiated price, and pilot its Pulumi support rather than standardizing on it |
| An all-Terraform org with modest governance needs and existing HashiCorp contracts | HCP Terraform Essentials — the cheapest managed metering, no lock-in surprises you don't already have; move up only when a specific gated feature (policies, audit logs) becomes a compliance requirement, and get the Standard/Premium quote before you design around it |
| A license-sensitive or budget-constrained team with platform-engineering capacity | OpenTofu + Atlantis now, Spacelift later — MPL-2.0 engine with a free PR workflow; upgrade to a commercial TACOS only when the operational toil you are absorbing becomes measurable |
| Determined to run Pulumi through Spacelift anyway | Pilot it, don't bet on it — feature preview means Spacelift can change the integration under you; keep Pulumi Cloud as the fallback control plane so the exit is a configuration change, not a migration |
One last skepticism check before you sign anything: every vendor on this page also sells you the comparison document that recommends them. The independent signals that survive contact with production are the ones linked in the sources below — pricing pages, billing mechanics, license texts, and release notes. Verify every number in this guide against them the week you buy; per-resource rates and tier features on this page were accurate on 2026-09-29, and nothing in the IaC market stays accurate for long.
For the adjacent decisions this one creates, see our OpenTofu vs. Terraform comparison (the engine-layer license question), Crossplane vs. Terraform (what happens when the control plane moves into your Kubernetes cluster instead), and landing-zone design patterns (what you will actually build on whichever platform you pick).