Automation ensures that landing-zone capabilities are reproducible, versioned, and tested instead of manually configured.
For migration landing zones, automation is the delivery backbone that connects platform APIs, IaC tools, developer workflows, and release controls into one reliable operating model.
STACKIT API: Use the API as the foundational control surface for platform automation and integration patterns. Documentation
Terraform Provider: Use the official provider for declarative infrastructure provisioning and lifecycle control. Documentation
OpenTofu Provider: Use OpenTofu with the STACKIT provider as an open IaC option with comparable declarative workflows. Documentation
Pulumi: Use Pulumi when teams prefer general-purpose languages for infrastructure automation. Documentation
Ansible: Use Ansible primarily for post-provisioning configuration and operational tasks. In a combined model, Terraform/OpenTofu provision infrastructure while Ansible applies OS and middleware configuration.
STACKIT CLI: Standardize CLI-based operations for scripting, troubleshooting, and repeatable operational run tasks. Documentation
SDKs (Go, Python, Java): Use SDKs for custom automation and service integrations where IaC abstractions are not sufficient. Go SDK, Python SDK, Java SDK.
STACKIT Git: Use Git as the source of truth for IaC modules, policies, and delivery workflows. Documentation
CI/CD Pipeline: Use pipelines for validation, policy checks, controlled promotion, and auditable releases. Documentation
Container Registry: Use a central registry for versioned build artifacts and deployment consistency across environments. Documentation
Terraform or OpenTofu and Ansible solve different parts of one delivery workflow. Keep the boundary
explicit so infrastructure changes remain reviewable and host configuration remains repeatable.
Terraform / OpenTofu
Own the infrastructure lifecycle: projects, networks, security controls, compute, storage,
managed services, and the outputs required by configuration management.
Ansible
Own configuration inside the reachable target: operating-system packages, middleware,
application artifacts, service units, and workload-level validation.
Version infrastructure inputs, configuration, and application artifact references in Git.
Validate and review the Terraform/OpenTofu plan, including replacement and security effects.
Apply the approved plan and expose only the target inventory and outputs required by Ansible.
Run Ansible idempotently to configure the operating system, middleware, workload, and telemetry.
Validate infrastructure state, service health, and operational controls, then retain the evidence.
Promote the same versioned workflow through environments instead of repeating manual setup.
Do not use provisioners or ad hoc scripts to blur ownership between both layers. Triggering Ansible
from Terraform can be a practical bridge, but each tool must remain independently understandable,
testable, and rerunnable.