A coordinator, not an executor
The server holds no cloud credentials, no state and no plan files with secrets. A compromised server can trigger workflows and post comments. It cannot touch infrastructure.
Security model
Lightweight Terraform and OpenTofu orchestration on GitHub Actions
A repository needs a root stackorder.yaml, two thin workflow files, and the Stackorder GitHub App installed. Everything has a default, so the smallest valid configuration is one line:
version: 1Stacks are discovered under stacks/** wherever a directory holds a terraform block with a backend "s3". A change to a local module, a directory a module block points at with a relative source, reaches every stack that uses it. Explicit dependencies between stacks go in a .stackorder.yaml next to the stack:
depends_on:
- stacks/prod/vpc
- acme/network-infra//stacks/prod/tgwContinue with Getting started, or read How it works first.