Infrastructure Management

Terraform, Kubernetes, vCenter and Proxmox — one governed workflow

Most orchestration platforms assume everything you run is in a public cloud. Realm9 treats the racks you already own as first-class infrastructure, with the same policy, state and audit model.

Terraformand OpenTofu, with remote state, locking and versioning
AWS · AzureGCP and OCI, with per-account and per-project scoping
vCenterProxmox and bare metal through the same control plane
3 scannersCheckov, Trivy and TruffleHog gating every plan

The on-prem estate nobody else covers properly

vCenter, Proxmox, site-to-site VPN, CIS benchmark scanning and Zabbix integration. If a meaningful share of your infrastructure lives in your own building, this is the difference between a tool that fits and one that does not.

  • Provision and reclaim VMs on vCenter and Proxmox from the same catalogue
  • CIS benchmark scanning with exportable evidence
  • Site-to-site VPN and private connectivity for hybrid estates
  • Monitoring integration so bookings and alerts share one view
Connected providers
ProviderStatusManagedLast sync
aws/prod🟢 Connected41214s ago
azure/eu🟢 Connected8822s ago
gcp/analytics🟢 Connected3118s ago
vcenter/ldn-1🟢 Connected2409s ago
proxmox/build🟢 Connected9611s ago
baremetal/gpu🟢 Connected3230s ago

Projects, workspaces and runs, connected to Git

Each project points at a repository, branch and path in Git. Workspaces hold the variables for each deployment, and every plan, apply, destroy or refresh is recorded as a run with its logs and plan summary.

  • Runs started manually, through the API, or from repository webhooks
  • Each run executes as an isolated Kubernetes job with its own streamed logs
  • Remote state with locking so two runs cannot change the same workspace at once
  • Templates expose selected variables as simple forms, so teams can create workspaces without editing code
Realm9 Terraform Projects list, each connected to a Git repository and branch
Realm9 Terraform Workspaces dashboard with totals, success rate and recent activity
Realm9 Terraform runs list across all projects and workspaces

Policy checks with the enforcement level you set

Attach a policy profile to a project to scan each run for misconfiguration, exposed secrets, vulnerabilities and cost. You decide whether findings are advisory or whether they block the run.

  • Scanners include Checkov, Trivy, TruffleHog, Infracost and OPA, plus your own scanner image
  • Advisory, soft-mandatory and hard-mandatory enforcement modes
  • Block thresholds and exclusions tuned per profile
  • Policy results reviewed on the run, and overrides recorded in the audit log
Realm9 Edit Policy Profile dialog showing enforcement rules by severity, from advisory to hard-mandatory

Approval gates for changes that matter

Projects can require approval before apply. Named approvers and a minimum approval count keep production changes with the people responsible for them.

  • Approve or reject from the run page, with notes kept on the run
  • Approver lists and minimum approvals configured per project
  • Role-based permissions separate viewing, running and managing Terraform
  • Run creation, approvals and overrides captured in the Terraform audit trail
Realm9 apply run pending approval, with Approve and Reject actions and run details

Know when code, permissions and reality diverge

When a repository changes, Realm9 re-analyses the project and raises drift alerts — new or removed resources, changed variables or modules, and permission gaps in the cloud role used to deploy.

  • Drift alerts graded by severity, with acknowledge, ignore and resolve actions
  • Missing and excess cloud-role permissions identified for each project
  • Runs blocked while a project has unresolved drift or pending variables
  • Credentials kept in AWS Secrets Manager, Azure Key Vault or HashiCorp Vault
Drift · 12 workspaces
WorkspaceDivergedSinceSeverity
production-network209-11🟠 Medium
payments-prod0—🟢 Clean
data-lake509-08🔴 High
mediumproduction-network / aws_security_group.api
ingress[3].cidr_blocks — declared10.0.0.0/8
ingress[3].cidr_blocks — actual0.0.0.0/0

Changed out of band. Run blocked until drift is resolved.

The Realm9 edge

Infrastructure Management is a governed Terraform/IaC orchestration layer built for hybrid estates. Here is where it goes further than the leading dedicated IaC platforms.

CapabilityRealm9Spaceliftenv0HCP Terraform
Native vCenter & Proxmox providersFirst-class vCenter and Proxmox providers alongside AWS, Azure and GCP — no custom glue codeOn-prem only via self-hosted workers, no native hypervisor providerOn-prem reachable only through custom Terraform providersCloud-focused; on-prem only via community Terraform providers
Security & cost scanning built in, not bolted onCheckov and TruffleHog run on every plan based on config; Trivy and Infracost switch on per policy profile — all four native, none require custom integrationExternal scanners require custom workflow steps to integrateSecurity & cost visibility requires separate Cloud Compass/Navigator add-onsCost estimation is built in; security scanning needs a third-party integration
Configurable enforcement per profileAdvisory, soft-mandatory or hard-mandatory — tuned per policy profile, not all-or-nothingUnlimited OPA policies, but enforcement is stage-based, not level-basedPolicy engine with guardrails, less granular enforcement tuningSentinel/OPA policy sets gated by workspace
Continuous drift + permission-gap analysisDrift detection graded by severity, plus missing/excess cloud-role permissions flagged automaticallyDrift detection runs on a schedule, not continuouslyDrift detection with no permission-gap analysisDrift/health checks limited to Terraform Cloud/Enterprise plans
One governed workflow, not per-tool silosTerraform on a single unified project/workspace/run model shared with the rest of Realm9 — cost, policy and drift on the same recordBroad tool support, but each tool runs its own workflowBroad tool support, but per-tool workflows with no shared modelSingle-tool focus with no shared governance layer across modules

Sources: Spacelift, env0 and HCP Terraform product documentation, reviewed 2024. Feature sets change frequently — verify against current vendor docs before quoting externally.

Put a review step between Terraform plan and apply

Infrastructure Management shares users, approvals and audit with the rest of Realm9, so infrastructure changes and the environments they serve are governed together.