The company that defined modern infrastructure automation — the HashiStack (Terraform, Vault, Consul, Nomad, Boundary) that provisions, secures, networks, orchestrates & grants access to infrastructure as code. Now an IBM company. This hub is your complete intel file.
Buy through TechBag
Same software. Better outcome — at no extra cost.
Free, vendor-neutral, 30 minutes
The company, at a glance
Quick answer
The complete HashiCorp stack — every linked card is a full intel page, from the Infrastructure-as-Code flagship to identity-based secure access.
Infrastructure as Code, the standard.
The flagship — the de-facto-standard Infrastructure as Code (IaC) tool that provisions multi-cloud & hybrid infrastructure as declarative, version-controlled code (HCL). Write, Plan, Apply — with the biggest provider registry and ecosystem in IaC. The #1 honest story lives here: the August 2023 BSL relicense (MPL → Business Source License) triggered the truly-open OpenTofu fork (Linux Foundation) — some teams now choose OpenTofu for licensing freedom. TechBag names both, honestly.
Secure every secret.
Secrets management & encryption — centralise, secure, rotate and control access to every secret (API keys, passwords, certificates, cloud credentials) with DYNAMIC (short-lived, auto-revoked) secrets as its signature, plus encryption-as-a-service, full PKI and Vault Radar secret scanning. The multi-cloud/hybrid secrets leader. Honest: powerful but operationally heavy (HA, unseal, upgrades — HCP Vault eases it), and complementary to CyberArk’s PAM (TechBag sells it).
Services find, connect & secure.
Service networking & service mesh — service discovery (find services by name, health-aware), a full mesh (automatic mTLS, intentions-based authorization, traffic management, observability) and zero-trust networking. Its distinctive edge: reach across MULTIPLE datacenters, clouds, and BOTH VMs and containers — not just Kubernetes. Honest: for PURE-Kubernetes environments, the CNCF meshes (Istio/Linkerd/Cilium) own the mindshare — Consul wins where you span beyond K8s.
The simpler K8s alternative.
Workload orchestration & scheduling — a single, lightweight BINARY that schedules, self-heals and scales containers, VMs, Java apps and raw binaries. Genuinely SIMPLER than Kubernetes, and it runs non-container (legacy) workloads too. The honest truth: Nomad is elegant, but KUBERNETES WON the orchestration war (bigger ecosystem, deeper hiring pool), and under IBM (which owns Red Hat OpenShift) Nomad’s long-term investment is a fair question. Choose it where simplicity or non-container workloads genuinely matter.
Identity-based infra access.
Identity-based secure remote access — ZTNA for infrastructure: engineers reach servers & databases without VPNs, bastions, shared keys or standing credentials, via Authenticate (IdP), Authorize (RBAC to specific targets) and Access (just-in-time, short-lived, brokered credentials from Vault, with session recording). Honest: newer/less mature than Teleport or StrongDM; strongest inside the HashiStack (Vault). It overlaps with Zscaler ZPA and CyberArk — both of which TechBag also sells and scopes honestly.
Everything HashiCorp builds shares ONE design philosophy — declarative, API-driven, multi-cloud, infrastructure-as-code — and the tools integrate: Terraform provisions, Vault secures secrets and PKI, Consul networks, Nomad orchestrates, Boundary grants access. That coherence (one operational model across provisioning, secrets, networking, orchestration and access) is the ‘HashiStack’ and a genuine reason teams standardise on it. Also in the family but folded into this hub, not their own pages: Packer (build machine images as code), HCP (the managed HashiCorp Cloud Platform — Terraform/Vault/Consul/Boundary as SaaS, easing ops), and Waypoint (an app-deployment tool, ARCHIVED in January 2024).
HashiCorp is now ‘HashiCorp, an IBM Company’ — the IBM acquisition closed on February 27, 2025 (never say it’s pending) — within IBM Software, integrating with Red Hat Ansible and the wider portfolio. Two honest stories run through every page: (1) the AUGUST 2023 BSL RELICENSE (Terraform and other tools moved from open-source MPL to the source-available Business Source License) triggered the truly-open OpenTofu fork (Linux Foundation, MPL) — a real trust and licensing consideration; and (2) IBM ownership raises fair questions about multi-cloud NEUTRALITY, roadmap, and overlap with IBM/Red Hat products (Ansible, OpenShift). TechBag names both openly rather than pretending they don’t exist.
Clicking consoles and brittle scripts don’t scale, and infrastructure sprawls across clouds. HashiCorp bet oninfrastructure as code — declarative, multi-cloud, one coherent stack— declarative, multi-cloud infrastructure as code, from provisioning (Terraform) through secrets (Vault), networking (Consul), orchestration (Nomad) and access (Boundary) — now an IBM company (honest: the 2023 BSL relicense spawned the open OpenTofu fork) doubled down on it.
The de-facto IaC standard — provision multi-cloud/hybrid infrastructure as declarative code (Write/Plan/Apply) with the biggest provider registry. The anchor of the stack. (Honest: the 2023 BSL relicense spawned the open OpenTofu fork.)
Centralise, secure and rotate every secret — with dynamic (short-lived) secrets, encryption-as-a-service and PKI. The multi-cloud secrets leader. (Honest: operationally heavy; HCP Vault eases it; complementary to CyberArk’s PAM.)
Service discovery and a full service mesh (mTLS, intentions, zero-trust) across multi-DC, multi-cloud, VMs and containers — beyond Kubernetes. (Honest: pure-K8s shops often default to the CNCF meshes.)
A single lightweight binary that schedules, heals and scales workloads — containers, VMs, Java and raw binaries — simpler than Kubernetes. (Honest: Kubernetes won the ecosystem war; IBM owns OpenShift too.)
Boundary grants identity-based, zero-trust access to infrastructure (no VPNs/bastions; Vault-native). HCP (HashiCorp Cloud Platform) delivers the stack as managed SaaS — easing the operational burden. (Honest: Boundary is newer than Teleport/StrongDM and overlaps with Zscaler/CyberArk, which TechBag sells.) TechBag adds scoping, INR/GST and support.
Start with Terraform (Infrastructure as Code, the standard) — then add Vault (secrets), Consul (networking), Nomad (orchestration) and Boundary (access). One coherent, multi-cloud stack.
Every claim on this hub traces to one of these public signals.
Terraform — the standard
provision, secure, network, run, access
Vault — dynamic secrets
now an IBM company
Hashimoto & Dadgar
the open fork
huge community & registry
deep platform-eng community
The HashiStack, explained.
Write, Plan, Apply — the standard.
Trusted by 600,000+ organisations worldwide
Two company-level views you won’t find on any vendor site — tap any dot for the rationale. The category-level grid lives on the product page.
Each dot is a HashiStack tool: competitive position vs category momentum.
The flagship — the IaC standard.
Infrastructure-as-code & multi-cloud strength vs the field — where the HashiStack leads (and where rivals win).
The de-facto IaC standard; the HashiStack.
Positions are TechBag’s illustrative synthesis of public review-platform standings and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Zero-jargon starting points, in reading order. Each links into the deep education on the product page.
Answer three questions; we’ll point you at the right starting product. No email required — this isn’t that kind of quiz.
1. What’s your priority?
2. Which sentence sounds most like you?
3. What does success look like?
The de-facto IaC standard — provision multi-cloud infrastructure as declarative code (Write/Plan/Apply) with the biggest provider registry.
Read →Why the 2023 licence change spawned the truly-open OpenTofu fork — and how to choose Terraform vs OpenTofu honestly.
Read →How short-lived, auto-revoked (dynamic) secrets shrink the blast radius — and where Vault fits vs CyberArk’s PAM.
Read →Service discovery, mesh and zero-trust across multi-DC, VMs and containers — and when the CNCF meshes win instead.
Read →A single lightweight binary for containers, VMs and raw binaries — and the honest truth that Kubernetes won.
Read →Identity-based access to servers/DBs without VPNs or bastions — and the honest overlap with Zscaler and CyberArk.
Read →The procurement playbook TechBag runs with IT buyers — steps, licensing cheat-sheet, and the pitfalls that cost quarters.
Which layers you need — provision (Terraform), secrets (Vault), network (Consul), orchestrate (Nomad), access (Boundary) — and your clouds, team and governance. TechBag scopes it honestly, including the OpenTofu licensing question, self-hosted vs HCP, and where TechBag-sold rivals (CyberArk, Zscaler) fit.
Codify your infrastructure as declarative Terraform (or the open OpenTofu fork) — Write/Plan/Apply across your clouds, with modules and policy-as-code. The provisioning core the rest builds on.
Centralise secrets in Vault (dynamic, short-lived) and network services with Consul (discovery, mesh, zero-trust) — securing and connecting what Terraform provisioned. Honest: both are operationally heavy — HCP eases it.
Add Nomad (orchestration — where simplicity/non-container workloads matter) and Boundary (identity-based, just-in-time infra access). One integrated stack. Honest: weigh Nomad vs Kubernetes, and Boundary vs Teleport/StrongDM/Zscaler/CyberArk.
Open-source vs OpenTofu (licensing)? Vault vs cloud-native manager (single-cloud)? Consul vs CNCF meshes (pure-K8s)? Nomad vs Kubernetes/OpenShift? Boundary vs Zscaler/CyberArk (TechBag sells both)? TechBag advises candidly — including the IBM-ownership context.
HashiCorp is open-core with quote-priced HCP / Enterprise tiers — TechBag adds scoping, INR/GST invoicing (18%), DPDPA-residency help, IBM-channel options and local support.
| Product | Licensing model | How you enter | Best for |
|---|---|---|---|
| Terraform | Open-core / HCP / Enterprise — by quote | IaC: Write/Plan/Apply, providers, modules, policy | Multi-cloud IaC (or the open OpenTofu fork) |
| Vault | Open-core / HCP / Enterprise — by quote | Secrets, dynamic secrets, encryption, PKI, Radar | Multi-cloud secrets & encryption |
| Consul | Open-core / HCP / Enterprise — by quote | Discovery, service mesh (mTLS/intentions), zero-trust | Multi-DC/hybrid networking (beyond K8s) |
| Nomad | Open-core / Enterprise — by quote | Scheduling, self-healing, safe deploys, autoscaling | Simple / non-container orchestration |
| Boundary | Open-core / HCP / Enterprise — by quote | Identity-based access, JIT creds, session recording | Zero-trust infra access (HashiStack-native) |
Per-user/device plus appliances and MDR service — TechBag models the mix (managed vs self-managed) for your size.
In August 2023 HashiCorp relicensed Terraform (and other tools) from open-source MPL to the source-available Business Source License — which triggered the truly-open OpenTofu fork (Linux Foundation, MPL, community-governed). For most users, Terraform under the BSL is perfectly usable and retains the biggest ecosystem — but if open-source licensing/governance is a hard requirement, OpenTofu is a credible, drop-in alternative. Don’t make the decision without knowing both exist. TechBag names OpenTofu openly and scopes your licensing constraints.
Vault and Consul are powerful — but running them WELL (Vault’s HA/unseal/upgrades; any service mesh’s complexity) is real operational work. A single-cloud shop may find a cloud-native secrets manager simpler than Vault; a pure-Kubernetes shop may default to the CNCF meshes over Consul. The managed HCP options meaningfully ease this burden and are often the right answer. Don’t adopt the heavyweight self-hosted path without weighing HCP and the simpler alternatives. TechBag scopes self-hosted vs HCP honestly.
HashiCorp is now ‘HashiCorp, an IBM Company’ (the acquisition CLOSED February 27, 2025 — it is NOT pending). This brings stability and IBM/Red Hat integration — but raises fair questions: multi-cloud NEUTRALITY (does an IBM-owned Terraform stay cloud-agnostic?), ROADMAP, and OVERLAP with IBM/Red Hat products (Red Hat Ansible for config management; Red Hat OpenShift for Kubernetes, which overlaps Nomad). These are legitimate diligence questions, not deal-breakers. TechBag surfaces the honest context so you decide with eyes open.
Nomad is elegant, simpler than Kubernetes, and runs non-container workloads — real strengths. But the honest truth is that KUBERNETES WON the orchestration war: bigger ecosystem, deeper hiring pool, default status. Nomad’s community and ecosystem are much smaller, and under IBM (which owns OpenShift) its long-term investment is a fair question. Choose Nomad where its simplicity or non-container support GENUINELY matters — but for most, Kubernetes (or OpenShift/managed K8s) is the safer long-term bet. TechBag scopes Nomad vs Kubernetes candidly.
Two HashiCorp products overlap with TechBag-sold security tools, and it’s worth scoping honestly. VAULT (application/machine secrets) overlaps with CyberArk (privileged human access / PAM) — largely complementary; many run both. BOUNDARY (identity-based infra access) overlaps with both Zscaler ZPA (broad user-to-app ZTNA) and CyberArk (PAM). TechBag sells CyberArk and Zscaler too, so it can scope where each fits (rather than pretending one replaces the others) — the right mix depends on your primary need and existing stack.
The flagship intel page carries an 8-question vendor checklist and an automation-savings calculator:
Bring your device counts and current tool bills — a TechBag advisor models the whole decision for you.
Book a discovery call →Six trends with momentum scores (TechBag’s read of analyst and market signals) — and what each means for your next decision.
*Directionally consistent with public analyst forecasts; verify exact figures before quoting. The takeaway: Infrastructure as Code and zero-trust security compound fastest — exactly where the HashiStack (Terraform, Vault, Consul, Boundary) is placed.
Provisioning infrastructure as declarative, version-controlled code — rather than clicking consoles — is now the default for cloud-native and multi-cloud teams.
What it means for you
Terraform is the de-facto IaC standard with the biggest provider registry; TechBag scopes it (and names the open OpenTofu fork born of the 2023 BSL relicense honestly).
Getting secrets out of code/config, and moving from static shared credentials to short-lived, auto-revoked dynamic secrets, is a top security priority.
What it means for you
Vault is the multi-cloud secrets leader — dynamic secrets shrink the blast radius — with encryption-as-a-service and PKI. (Complementary to CyberArk PAM.)
Security is shifting from network-location trust (IPs, VPNs, firewalls) to identity-based, least-privilege, default-deny access — zero trust.
What it means for you
Consul brings zero-trust to service networking (mTLS, intentions), and Boundary brings identity-based zero-trust access to infrastructure (no VPNs/bastions).
Vendors relicensing formerly-open tools to source-available licences (BSL and similar) is driving community forks (OpenTofu, others) and licensing scrutiny.
What it means for you
HashiCorp’s 2023 BSL relicense of Terraform triggered the truly-open OpenTofu fork — the #1 honest story; TechBag scopes Terraform vs OpenTofu candidly.
Major consolidation is reshaping the infrastructure-automation market — IBM acquiring HashiCorp brings it alongside Red Hat Ansible and OpenShift.
What it means for you
HashiCorp is now an IBM company (deal closed Feb 2025) integrating with Red Hat — raising honest neutrality/roadmap/overlap questions TechBag surfaces.
India’s vast IT/ITES and GCC ecosystem is booming in platform engineering and DevOps — with deep Terraform/HashiStack skills and hiring depth.
What it means for you
The HashiStack suits India’s multi-cloud, platform-engineering reality; HashiCorp has Bengaluru R&D, and TechBag adds scoping, INR/GST (18%) and local support.
Open any of the twelve intel pages for the deep dive, or let a TechBag advisor build the case with you — MDR-vs-self-managed scoping, quotes, trials, GST invoicing and lifecycle support included.
Stats, positions and figures are illustrative syntheses of public materials; verify before purchase.