The company that defined modern infrastructure automation — the HashiStack (Terraform, Vault, Consul, Nomad, Boundary) that provisions, secures, networks, orchestrates & grants access to infrastructure as code. Now an IBM company. This hub is your complete intel file.
Buy through TechBag
Same software. Better outcome — at a lower cost.
The company, at a glance
Quick answer
The complete HashiCorp stack — every linked card is a full intel page, from the Infrastructure-as-Code flagship to identity-based secure access.
Infrastructure as Code, the standard.
The flagship — the de-facto-standard Infrastructure as Code (IaC) tool that provisions multi-cloud & hybrid infrastructure as declarative, version-controlled code (HCL). Write, Plan, Apply — with the biggest provider registry and ecosystem in IaC. The #1 honest story lives here: the August 2023 BSL relicense (MPL → Business Source License) triggered the truly-open OpenTofu fork (Linux Foundation) — some teams now choose OpenTofu for licensing freedom. TechBag names both, honestly.
Secure every secret.
Secrets management & encryption — centralise, secure, rotate and control access to every secret (API keys, passwords, certificates, cloud credentials) with DYNAMIC (short-lived, auto-revoked) secrets as its signature, plus encryption-as-a-service, full PKI and Vault Radar secret scanning. The multi-cloud/hybrid secrets leader. Honest: powerful but operationally heavy (HA, unseal, upgrades — HCP Vault eases it), and complementary to CyberArk’s PAM (TechBag sells it).
Services find, connect & secure.
Service networking & service mesh — service discovery (find services by name, health-aware), a full mesh (automatic mTLS, intentions-based authorization, traffic management, observability) and zero-trust networking. Its distinctive edge: reach across MULTIPLE datacenters, clouds, and BOTH VMs and containers — not just Kubernetes. Honest: for PURE-Kubernetes environments, the CNCF meshes (Istio/Linkerd/Cilium) own the mindshare — Consul wins where you span beyond K8s.
The simpler K8s alternative.
Workload orchestration & scheduling — a single, lightweight BINARY that schedules, self-heals and scales containers, VMs, Java apps and raw binaries. Genuinely SIMPLER than Kubernetes, and it runs non-container (legacy) workloads too. The honest truth: Nomad is elegant, but KUBERNETES WON the orchestration war (bigger ecosystem, deeper hiring pool), and under IBM (which owns Red Hat OpenShift) Nomad’s long-term investment is a fair question. Choose it where simplicity or non-container workloads genuinely matter.
Identity-based infra access.
Identity-based secure remote access — ZTNA for infrastructure: engineers reach servers & databases without VPNs, bastions, shared keys or standing credentials, via Authenticate (IdP), Authorize (RBAC to specific targets) and Access (just-in-time, short-lived, brokered credentials from Vault, with session recording). Honest: newer/less mature than Teleport or StrongDM; strongest inside the HashiStack (Vault). It overlaps with Zscaler ZPA and CyberArk — both of which TechBag also sells and scopes honestly.
Everything HashiCorp builds shares ONE design philosophy — declarative, API-driven, multi-cloud, infrastructure-as-code — and the tools integrate: Terraform provisions, Vault secures secrets and PKI, Consul networks, Nomad orchestrates, Boundary grants access. That coherence (one operational model across provisioning, secrets, networking, orchestration and access) is the ‘HashiStack’ and a genuine reason teams standardise on it. Also in the family but folded into this hub, not their own pages: Packer (build machine images as code), HCP (the managed HashiCorp Cloud Platform — Terraform/Vault/Consul/Boundary as SaaS, easing ops), and Waypoint (an app-deployment tool, ARCHIVED in January 2024).
HashiCorp is now ‘HashiCorp, an IBM Company’ — the IBM acquisition closed on February 27, 2025 (never say it’s pending) — within IBM Software, integrating with Red Hat Ansible and the wider portfolio. Two honest stories run through every page: (1) the AUGUST 2023 BSL RELICENSE (Terraform and other tools moved from open-source MPL to the source-available Business Source License) triggered the truly-open OpenTofu fork (Linux Foundation, MPL) — a real trust and licensing consideration; and (2) IBM ownership raises fair questions about multi-cloud NEUTRALITY, roadmap, and overlap with IBM/Red Hat products (Ansible, OpenShift). TechBag names both openly rather than pretending they don’t exist.
HashiCorp sells across 3 of the products TechBag carries in devops. The DevOps guide shows how the category splits and which part is yours. →
Clicking consoles and brittle scripts don’t scale, and infrastructure sprawls across clouds. HashiCorp bet on infrastructure as code — declarative, multi-cloud, one coherent stack— declarative, multi-cloud infrastructure as code, from provisioning (Terraform) through secrets (Vault), networking (Consul), orchestration (Nomad) and access (Boundary) — now an IBM company (honest: the 2023 BSL relicense spawned the open OpenTofu fork) doubled down on it.
The de-facto IaC standard — provision multi-cloud/hybrid infrastructure as declarative code (Write/Plan/Apply) with the biggest provider registry. The anchor of the stack. (Honest: the 2023 BSL relicense spawned the open OpenTofu fork.)
Centralise, secure and rotate every secret — with dynamic (short-lived) secrets, encryption-as-a-service and PKI. The multi-cloud secrets leader. (Honest: operationally heavy; HCP Vault eases it; complementary to CyberArk’s PAM.)
Service discovery and a full service mesh (mTLS, intentions, zero-trust) across multi-DC, multi-cloud, VMs and containers — beyond Kubernetes. (Honest: pure-K8s shops often default to the CNCF meshes.)
A single lightweight binary that schedules, heals and scales workloads — containers, VMs, Java and raw binaries — simpler than Kubernetes. (Honest: Kubernetes won the ecosystem war; IBM owns OpenShift too.)
Boundary grants identity-based, zero-trust access to infrastructure (no VPNs/bastions; Vault-native). HCP (HashiCorp Cloud Platform) delivers the stack as managed SaaS — easing the operational burden. (Honest: Boundary is newer than Teleport/StrongDM and overlaps with Zscaler/CyberArk, which TechBag sells.) TechBag adds scoping, INR/GST and support.
Start with Terraform (Infrastructure as Code, the standard) — then add Vault (secrets), Consul (networking), Nomad (orchestration) and Boundary (access). One coherent, multi-cloud stack.
Every claim on this hub traces to one of these public signals.
Terraform — the standard
provision, secure, network, run, access
Vault — dynamic secrets
now an IBM company
Hashimoto & Dadgar
the open fork
huge community & registry
deep platform-eng community
The HashiStack, explained.
Write, Plan, Apply — the standard.
Two company-level views you won’t find on any vendor site — tap any dot for the rationale. The category-level grid lives on the product page.
Each dot is a HashiStack tool: competitive position vs category momentum.
The flagship — the IaC standard.
Infrastructure-as-code & multi-cloud strength vs the field — where the HashiStack leads (and where rivals win).
The de-facto IaC standard; the HashiStack.
Positions are TechBag’s illustrative synthesis of public review-platform standings and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Zero-jargon starting points, in reading order. Each links into the deep education on the product page.
Answer three questions; we’ll point you at the right starting product. No email required — this isn’t that kind of quiz.
1. What’s your priority?
2. Which sentence sounds most like you?
3. What does success look like?
The de-facto IaC standard — provision multi-cloud infrastructure as declarative code (Write/Plan/Apply) with the biggest provider registry.
Read →Why the 2023 licence change spawned the truly-open OpenTofu fork — and how to choose Terraform vs OpenTofu honestly.
Read →How short-lived, auto-revoked (dynamic) secrets shrink the blast radius — and where Vault fits vs CyberArk’s PAM.
Read →Service discovery, mesh and zero-trust across multi-DC, VMs and containers — and when the CNCF meshes win instead.
Read →A single lightweight binary for containers, VMs and raw binaries — and the honest truth that Kubernetes won.
Read →Identity-based access to servers/DBs without VPNs or bastions — and the honest overlap with Zscaler and CyberArk.
Read →The procurement playbook TechBag runs with IT buyers — steps, licensing cheat-sheet, and the pitfalls that cost quarters.
Which layers you need — provision (Terraform), secrets (Vault), network (Consul), orchestrate (Nomad), access (Boundary) — and your clouds, team and governance. TechBag scopes it honestly, including the OpenTofu licensing question, self-hosted vs HCP, and where TechBag-sold rivals (CyberArk, Zscaler) fit.
Codify your infrastructure as declarative Terraform (or the open OpenTofu fork) — Write/Plan/Apply across your clouds, with modules and policy-as-code. The provisioning core the rest builds on.
Centralise secrets in Vault (dynamic, short-lived) and network services with Consul (discovery, mesh, zero-trust) — securing and connecting what Terraform provisioned. Honest: both are operationally heavy — HCP eases it.
Add Nomad (orchestration — where simplicity/non-container workloads matter) and Boundary (identity-based, just-in-time infra access). One integrated stack. Honest: weigh Nomad vs Kubernetes, and Boundary vs Teleport/StrongDM/Zscaler/CyberArk.
Open-source vs OpenTofu (licensing)? Vault vs cloud-native manager (single-cloud)? Consul vs CNCF meshes (pure-K8s)? Nomad vs Kubernetes/OpenShift? Boundary vs Zscaler/CyberArk (TechBag sells both)? TechBag advises candidly — including the IBM-ownership context.
HashiCorp is open-core with quote-priced HCP / Enterprise tiers — TechBag adds scoping, INR/GST invoicing (18%), DPDPA-residency help, IBM-channel options and local support.
| Product | Licensing model | How you enter | Best for |
|---|---|---|---|
| Terraform | Open-core / HCP / Enterprise — by quote | IaC: Write/Plan/Apply, providers, modules, policy | Multi-cloud IaC (or the open OpenTofu fork) |
| Vault | Open-core / HCP / Enterprise — by quote | Secrets, dynamic secrets, encryption, PKI, Radar | Multi-cloud secrets & encryption |
| Consul | Open-core / HCP / Enterprise — by quote | Discovery, service mesh (mTLS/intentions), zero-trust | Multi-DC/hybrid networking (beyond K8s) |
| Nomad | Open-core / Enterprise — by quote | Scheduling, self-healing, safe deploys, autoscaling | Simple / non-container orchestration |
| Boundary | Open-core / HCP / Enterprise — by quote | Identity-based access, JIT creds, session recording | Zero-trust infra access (HashiStack-native) |
Per-user/device plus appliances and MDR service — TechBag models the mix (managed vs self-managed) for your size.
In August 2023 HashiCorp relicensed Terraform (and other tools) from open-source MPL to the source-available Business Source License — which triggered the truly-open OpenTofu fork (Linux Foundation, MPL, community-governed). For most users, Terraform under the BSL is perfectly usable and retains the biggest ecosystem — but if open-source licensing/governance is a hard requirement, OpenTofu is a credible, drop-in alternative. Don’t make the decision without knowing both exist. TechBag names OpenTofu openly and scopes your licensing constraints.
Vault and Consul are powerful — but running them WELL (Vault’s HA/unseal/upgrades; any service mesh’s complexity) is real operational work. A single-cloud shop may find a cloud-native secrets manager simpler than Vault; a pure-Kubernetes shop may default to the CNCF meshes over Consul. The managed HCP options meaningfully ease this burden and are often the right answer. Don’t adopt the heavyweight self-hosted path without weighing HCP and the simpler alternatives. TechBag scopes self-hosted vs HCP honestly.
HashiCorp is now ‘HashiCorp, an IBM Company’ (the acquisition CLOSED February 27, 2025 — it is NOT pending). This brings stability and IBM/Red Hat integration — but raises fair questions: multi-cloud NEUTRALITY (does an IBM-owned Terraform stay cloud-agnostic?), ROADMAP, and OVERLAP with IBM/Red Hat products (Red Hat Ansible for config management; Red Hat OpenShift for Kubernetes, which overlaps Nomad). These are legitimate diligence questions, not deal-breakers. TechBag surfaces the honest context so you decide with eyes open.
Nomad is elegant, simpler than Kubernetes, and runs non-container workloads — real strengths. But the honest truth is that KUBERNETES WON the orchestration war: bigger ecosystem, deeper hiring pool, default status. Nomad’s community and ecosystem are much smaller, and under IBM (which owns OpenShift) its long-term investment is a fair question. Choose Nomad where its simplicity or non-container support GENUINELY matters — but for most, Kubernetes (or OpenShift/managed K8s) is the safer long-term bet. TechBag scopes Nomad vs Kubernetes candidly.
Two HashiCorp products overlap with TechBag-sold security tools, and it’s worth scoping honestly. VAULT (application/machine secrets) overlaps with CyberArk (privileged human access / PAM) — largely complementary; many run both. BOUNDARY (identity-based infra access) overlaps with both Zscaler ZPA (broad user-to-app ZTNA) and CyberArk (PAM). TechBag sells CyberArk and Zscaler too, so it can scope where each fits (rather than pretending one replaces the others) — the right mix depends on your primary need and existing stack.
The flagship intel page carries an 8-question vendor checklist and an automation-savings calculator:
Bring your requirements and current tool bills — a TechBag advisor models the whole decision for you.
Book a discovery call →Six trends with momentum scores (TechBag’s read of analyst and market signals) — and what each means for your next decision.
*Directionally consistent with public analyst forecasts; verify exact figures before quoting. The takeaway: Infrastructure as Code and zero-trust security compound fastest — exactly where the HashiStack (Terraform, Vault, Consul, Boundary) is placed.
Provisioning infrastructure as declarative, version-controlled code — rather than clicking consoles — is now the default for cloud-native and multi-cloud teams.
What it means for you
Terraform is the de-facto IaC standard with the biggest provider registry; TechBag scopes it (and names the open OpenTofu fork born of the 2023 BSL relicense honestly).
Getting secrets out of code/config, and moving from static shared credentials to short-lived, auto-revoked dynamic secrets, is a top security priority.
What it means for you
Vault is the multi-cloud secrets leader — dynamic secrets shrink the blast radius — with encryption-as-a-service and PKI. (Complementary to CyberArk PAM.)
Security is shifting from network-location trust (IPs, VPNs, firewalls) to identity-based, least-privilege, default-deny access — zero trust.
What it means for you
Consul brings zero-trust to service networking (mTLS, intentions), and Boundary brings identity-based zero-trust access to infrastructure (no VPNs/bastions).
Vendors relicensing formerly-open tools to source-available licences (BSL and similar) is driving community forks (OpenTofu, others) and licensing scrutiny.
What it means for you
HashiCorp’s 2023 BSL relicense of Terraform triggered the truly-open OpenTofu fork — the #1 honest story; TechBag scopes Terraform vs OpenTofu candidly.
Major consolidation is reshaping the infrastructure-automation market — IBM acquiring HashiCorp brings it alongside Red Hat Ansible and OpenShift.
What it means for you
HashiCorp is now an IBM company (deal closed Feb 2025) integrating with Red Hat — raising honest neutrality/roadmap/overlap questions TechBag surfaces.
India’s vast IT/ITES and GCC ecosystem is booming in platform engineering and DevOps — with deep Terraform/HashiStack skills and hiring depth.
What it means for you
The HashiStack suits India’s multi-cloud, platform-engineering reality; HashiCorp has Bengaluru R&D, and TechBag adds scoping, INR/GST (18%) and local support.
Open any of the twelve intel pages for the deep dive, or let a TechBag advisor build the case with you — MDR-vs-self-managed scoping, quotes, trials, GST invoicing and lifecycle support included.
Stats, positions and figures are illustrative syntheses of public materials; verify before purchase.