Q: How do you compare Crossplane Compositions with Terraform / OpenTofu modules when building an internal platform, and how do you choose between continuous state reconciliation vs push-based plan/apply workflows?
Deep architectural analysis comparing Crossplane's continuous reconciliation control plane model against Terraform's static plan/apply execution model in platform engineering.
Want to master this scenario in a live sandbox? KodeKloud's CKA & CKAD Hands-On Certification Track covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Compare Execution Models: Push vs Continuous Reconciliation
Terraform executes imperatively during CI pipeline runs: if out-of-band drift occurs between runs, it remains uncorrected until the next plan/apply. Crossplane runs a continuous reconciliation loop inside the Kubernetes control plane, automatically healing drift within seconds.
# Crossplane reconciles every 1m by default: detects drift on AWS RDS instance and enforces declared configuration automatically
Evaluate Self-Service Abstractions and API Native Integration
Terraform requires wrapper tooling (Atlantis, Spacelift, Terraform Cloud) or custom pull request automations to offer self-service to developers. Crossplane exposes native Kubernetes CRDs (XRDs), allowing developers to request databases using standard kubectl, Helm, or Backstage with native RBAC and admission policies.
# Developers define pure k8s claims:
apiVersion: platform.acme.com/v1alpha1
kind: PostgreSQLInstance
metadata:
name: orders-db
spec:
storageGB: 50
engineVersion: '16.1'
Hybrid Adoption Strategy: Crossplane for Dynamic, Terraform for Static Core
Implement a pragmatically tiered architecture: use Terraform for low-churn foundational networking (VPCs, Transit Gateways, DirectConnect) where state locking and rigorous human plan approvals are preferred, and use Crossplane for high-velocity tenant resources (RDS databases, S3 buckets, IAM roles, preview environments).
# Tier 1: Terraform manages AWS Organization, Accounts, VPCs, and EKS Clusters
# Tier 2: Crossplane runs inside EKS, vending S3, RDS, and IAM roles directly to dev teams
- Terraform is an execution pipeline that applies changes when triggered by CI; Crossplane is an active control plane that reconciles state continuously.
- We keep Terraform for foundational, low-churn networking where human plan-approval gates make sense.
- For developer resources like databases and queues, Crossplane vends Kubernetes CRDs with instant self-service and automated drift healing.