Terraform, Kubernetes, vCenter and Proxmox — one governed workflow
Most orchestration platforms assume everything you run is in a public cloud. Realm9 treats the racks you already own as first-class infrastructure, with the same policy, state and audit model.
The on-prem estate nobody else covers properly
vCenter, Proxmox, site-to-site VPN, CIS benchmark scanning and Zabbix integration. If a meaningful share of your infrastructure lives in your own building, this is the difference between a tool that fits and one that does not.
- Provision and reclaim VMs on vCenter and Proxmox from the same catalogue
- CIS benchmark scanning with exportable evidence
- Site-to-site VPN and private connectivity for hybrid estates
- Monitoring integration so bookings and alerts share one view
| Provider | Status | Managed | Last sync |
|---|---|---|---|
| aws/prod | 🟢 Connected | 412 | 14s ago |
| azure/eu | 🟢 Connected | 88 | 22s ago |
| gcp/analytics | 🟢 Connected | 31 | 18s ago |
| vcenter/ldn-1 | 🟢 Connected | 240 | 9s ago |
| proxmox/build | 🟢 Connected | 96 | 11s ago |
| baremetal/gpu | 🟢 Connected | 32 | 30s ago |
Projects, workspaces and runs, connected to Git
Each project points at a repository, branch and path in Git. Workspaces hold the variables for each deployment, and every plan, apply, destroy or refresh is recorded as a run with its logs and plan summary.
- Runs started manually, through the API, or from repository webhooks
- Each run executes as an isolated Kubernetes job with its own streamed logs
- Remote state with locking so two runs cannot change the same workspace at once
- Templates expose selected variables as simple forms, so teams can create workspaces without editing code
Policy checks with the enforcement level you set
Attach a policy profile to a project to scan each run for misconfiguration, exposed secrets, vulnerabilities and cost. You decide whether findings are advisory or whether they block the run.
- Scanners include Checkov, Trivy, TruffleHog, Infracost and OPA, plus your own scanner image
- Advisory, soft-mandatory and hard-mandatory enforcement modes
- Block thresholds and exclusions tuned per profile
- Policy results reviewed on the run, and overrides recorded in the audit log
Approval gates for changes that matter
Projects can require approval before apply. Named approvers and a minimum approval count keep production changes with the people responsible for them.
- Approve or reject from the run page, with notes kept on the run
- Approver lists and minimum approvals configured per project
- Role-based permissions separate viewing, running and managing Terraform
- Run creation, approvals and overrides captured in the Terraform audit trail
Know when code, permissions and reality diverge
When a repository changes, Realm9 re-analyses the project and raises drift alerts — new or removed resources, changed variables or modules, and permission gaps in the cloud role used to deploy.
- Drift alerts graded by severity, with acknowledge, ignore and resolve actions
- Missing and excess cloud-role permissions identified for each project
- Runs blocked while a project has unresolved drift or pending variables
- Credentials kept in AWS Secrets Manager, Azure Key Vault or HashiCorp Vault
| Workspace | Diverged | Since | Severity |
|---|---|---|---|
| production-network | 2 | 09-11 | 🟠 Medium |
| payments-prod | 0 | — | 🟢 Clean |
| data-lake | 5 | 09-08 | 🔴 High |
Changed out of band. Run blocked until drift is resolved.
The Realm9 edge
Infrastructure Management is a governed Terraform/IaC orchestration layer built for hybrid estates. Here is where it goes further than the leading dedicated IaC platforms.
| Capability | Realm9 | Spacelift | env0 | HCP Terraform |
|---|---|---|---|---|
| Native vCenter & Proxmox providers | First-class vCenter and Proxmox providers alongside AWS, Azure and GCP — no custom glue code | On-prem only via self-hosted workers, no native hypervisor provider | On-prem reachable only through custom Terraform providers | Cloud-focused; on-prem only via community Terraform providers |
| Security & cost scanning built in, not bolted on | Checkov and TruffleHog run on every plan based on config; Trivy and Infracost switch on per policy profile — all four native, none require custom integration | External scanners require custom workflow steps to integrate | Security & cost visibility requires separate Cloud Compass/Navigator add-ons | Cost estimation is built in; security scanning needs a third-party integration |
| Configurable enforcement per profile | Advisory, soft-mandatory or hard-mandatory — tuned per policy profile, not all-or-nothing | Unlimited OPA policies, but enforcement is stage-based, not level-based | Policy engine with guardrails, less granular enforcement tuning | Sentinel/OPA policy sets gated by workspace |
| Continuous drift + permission-gap analysis | Drift detection graded by severity, plus missing/excess cloud-role permissions flagged automatically | Drift detection runs on a schedule, not continuously | Drift detection with no permission-gap analysis | Drift/health checks limited to Terraform Cloud/Enterprise plans |
| One governed workflow, not per-tool silos | Terraform on a single unified project/workspace/run model shared with the rest of Realm9 — cost, policy and drift on the same record | Broad tool support, but each tool runs its own workflow | Broad tool support, but per-tool workflows with no shared model | Single-tool focus with no shared governance layer across modules |
Sources: Spacelift, env0 and HCP Terraform product documentation, reviewed 2024. Feature sets change frequently — verify against current vendor docs before quoting externally.
Put a review step between Terraform plan and apply
Infrastructure Management shares users, approvals and audit with the rest of Realm9, so infrastructure changes and the environments they serve are governed together.




