Available Now

Managed Infrastructure
Automation

Managed, secure Infrastructure-as-Code execution. Credentials encrypted at rest and in transit. Every run isolated by gVisor and secured behind a network proxy.

🔐 AES-256 encrypted
🛡️ gVisor sandboxed
🌐 Network proxy isolated

Everything your team needs
to ship infrastructure with confidence.

🔁

OpenTofu Execution Engine

Plans and applies run in isolated, ephemeral environments. No shared state, no blast radius surprises. Full compatibility with OpenTofu and Terraform.

🔐

Secure Credential Management

Provider credentials are encrypted at rest and in transit using AES-256. Secrets are injected at execution time and never written to disk.

🛡️

gVisor Sandboxed Execution

Every run executes inside a gVisor sandbox, a user-space kernel that intercepts all system calls. Compromised modules can't escape the container boundary.

🌐

Network Proxy Isolation

Outbound traffic from each run is routed through a dedicated network proxy. Egress is controlled, audited, and locked to your approved cloud provider endpoints.

Governance & Approval Gates

Define automated boundaries and multi-party approval policies by environment, resource type, or blast radius. Agents handle the rest.

🚀

Environment Promotion

Promote infrastructure changes from alpha through beta to production with delineated lineage tracking. Know exactly what changed, when, and who approved it.

📋

Full Audit Trail

Every plan, apply, approval, and change is logged with complete context. Immutable run history for compliance without the busywork.

🔔

Notifications & Webhooks

Real-time Slack notifications and webhook dispatches for run events. Teams stay informed from plan through apply, at any scale.

🔍

Seamless Migration

Forgecroft picks up where the last generation of Terraform management left off. Bring existing state and workspaces without re-architecting.

Infrastructure for the AI era

Security and governance aren't add-ons. They're the foundation every capability is built on.

Full audit trail, no exceptions

Every apply, approval, and change is logged with full context. See who triggered it, what changed, and why. Compliance that doesn't require extra work.

Agent-native by design

Every API, approval flow, and state operation is built for machines as first-class operators. Not bolted on after the fact.

Limited blast radius by default

Context-aware planning means an agent changing one resource never has the power to alter an entire environment unless explicitly authorized.

Self-healing infrastructure

Continuous drift reconciliation between declared state and live infrastructure. Automated remediation, not just alerts.

Ready to ship infrastructure with confidence?

Start with the managed IaC offering. Enable secure, automated infrastructure delivery for your team.