// the find
padok-team/burrito
🌯 Burrito is a TACoS Kubernetes Operator - "Argo CD for Terraform"
Burrito is a Kubernetes operator that runs Terraform/OpenTofu continuously inside your cluster — planning on a schedule, applying when needed, and posting plan output as PR/MR comments instead of you writing that CI/CD glue yourself. It's aimed at teams already running Kubernetes who want Terraform Cloud-like behavior (drift detection, a state UI) without paying for Terraform Cloud or Spacelift.
The CRD split (TerraformRepository, TerraformLayer, TerraformRun, TerraformPullRequest) maps cleanly onto the actual Terraform workflow and each controller has its own test suite with YAML fixtures rather than one monolithic reconciler. It supports Terraform, OpenTofu, and Terragrunt as pluggable tools, and the datastore component abstracts state storage behind S3/GCS/Azure backends with its own encryption layer rather than assuming one cloud. GitHub App, GitHub token, and GitLab token auth are all implemented separately with real webhook handlers, not just a single hardcoded path.
It's explicitly pre-1.0 with breaking changes between minor versions, so anyone adopting it now is signing up for migration work on every upgrade — there's even a dedicated migration-guides doc for a credential system change already. Running plans/applies as pods inside your own cluster means the operator's RBAC and the runner pod's permissions need real scrutiny since it's executing arbitrary Terraform code with cluster-adjacent credentials. It's Kubernetes-only, so teams not already running k8s get zero value and have to stand up a cluster just to automate Terraform. Maintainer bandwidth is thin — two current maintainers listed, two marked former — for something that wants to sit in the critical path of your infra changes.