DevOps
Ansible vs Terraform vs Argo CD: three tools for three different jobs
Terraform provisions infrastructure, Ansible configures machines, and Argo CD keeps Kubernetes in sync with Git. How they differ, where they overlap and when you need more than one.
By Raktim Ranjit · Published · 3 min read
Short answer: they are not competitors. Terraform creates infrastructure: servers, networks, DNS records, databases. Ansible configures what runs on a machine: packages, files, services, users. Argo CD makes a Kubernetes cluster match the manifests in a Git repository. Many setups use two of them. A single small server needs none of them.
What does Terraform do?
Terraform is declarative infrastructure as code. You describe resources in HCL, it compares that with a state file recording what exists, and it creates, changes or destroys resources to match. It talks to cloud and service APIs through providers.
resource "hcloud_server" "app" {
name = "app-1"
server_type = "cx22"
image = "debian-12"
location = "nbg1"
}
resource "cloudflare_record" "app" {
zone_id = var.zone_id
name = "app"
type = "A"
content = hcloud_server.app.ipv4_address
}Commands: terraform plan shows what would change, terraform apply does it. The state file is critical. Store it in a remote backend with locking, and treat it as sensitive since it can contain secrets. OpenTofu is an open-source fork with a compatible workflow.
What does Ansible do?
Ansible connects to machines over SSH and runs tasks from YAML playbooks. There is no agent to install. Well-written modules are idempotent: running the playbook twice produces the same result and changes nothing the second time.
- hosts: app
become: true
tasks:
- name: Install Docker
ansible.builtin.apt:
name: [docker.io, docker-compose-v2]
state: present
update_cache: true
- name: Copy compose file
ansible.builtin.copy:
src: compose.yaml
dest: /srv/app/compose.yaml
mode: "0644"
- name: Start stack
community.docker.docker_compose_v2:
project_src: /srv/app
state: presentIt suits configuring servers, deploying to hosts and one-off operational tasks.
What does Argo CD do?
Argo CD is a GitOps controller for Kubernetes. It runs in the cluster, watches a Git repository containing manifests, Helm charts or Kustomize overlays, and continuously compares the live cluster to Git. If they differ, it shows the drift and can sync automatically. Git becomes the source of truth, and a rollback is a revert commit.
How do they differ?
- Layer: Terraform builds the platform. Ansible prepares machines. Argo CD manages applications on Kubernetes.
- Model: Terraform tracks state and plans. Ansible runs ordered tasks. Argo CD reconciles continuously.
- Drift: Terraform notices on the next plan. Ansible fixes on the next run. Argo CD detects constantly.
- Needs Kubernetes: only Argo CD.
How do they combine?
A common pattern: Terraform creates the servers and a managed Kubernetes cluster; Ansible, if you have plain VMs, installs software on them; Argo CD deploys the applications onto the cluster from Git. Each tool does the part it is good at. Resist using Terraform to deploy application releases or Ansible to manage a hundred services' versions. It works until it does not.
What should a small team use?
- One server running Compose: a shell script or a short Ansible playbook, plus a CI deploy step. See how to set up CI/CD.
- A few cloud resources: Terraform, to keep DNS and servers reproducible.
- Kubernetes with several apps: Argo CD or Flux, along with Terraform for the cluster itself.
Add a tool when you feel a specific pain, such as servers you cannot recreate or manual clicking in a console, not because a job listing mentions it. Comparing the two main GitOps controllers is in Argo CD vs Flux.
References
Author
Raktim Ranjit is a software engineer and the founder of NodeDR Infotech. He builds and maintains the software described here.