Article · part of a guide
Scalr Offers Free Terraform Agents
Learn about agents and why they're included on every plan

Key takeaways
- Scalr charges no extra fee for self-hosted agents on any plan, including the free version, whereas Terraform Cloud limits you to one agent unless you pay for a higher tier or buy more.
- Scalr offers two agent types: self-hosted run agents that execute Terraform runs on your own infrastructure, and VCS agents that pull configuration from internal version control without exposing it to the internet.
- Self-hosted agents improve security, allow custom execution environments with pre-built dependencies, and give control over hardware and performance.
- Scalr does not charge for agents because it only bills for Terraform runs, not for following security best practices or hosting your own agent pools.
If you're comparing hosted options for running Terraform or OpenTofu, like Scalr or Terraform Cloud, self-hosted agents are worth a close look. In Terraform Cloud you're limited to one "Terraform Cloud Agent'' unless you move to a more expensive tier or buy more. In Scalr, extra agents are free no matter what plan you're on, even the free version. That gap matters more now that HCP Terraform's free tier is being discontinued.
There are two types of self-hosted agents:
- Self-Hosted Run Agents: Execute Terraform runs on your own cloud infrastructure, whether on public cloud resources or in on-premise infrastructure, giving you more control over the execution environment.
- Self-Hosted VCS Agents: Pull Terraform configuration files and modules from a VCS provider that isn't accessible from the internet.
Running self-hosted agents for Terraform runs gets you a few things.
On security, you can configure the agents to comply with specific security and compliance standards. That matters for organizations with strict regulatory requirements, or for anyone wanting to limit the exposure of sensitive information. On AWS, for example, the agent pool can be assigned an instance profile and runs can inherit its credentials, so you don't have to put any access tokens or secrets in Scalr itself.
You also get to run Terraform operations in an environment you control. You can customize the operating system, install specific software dependencies, and configure network settings. Dependencies can be built into the agent instead of being installed before every Terraform plan and apply.
And because the agents run on your own cloud infrastructure, you have more control over the hardware specifications and resource allocation. That lets you tune performance to what your Terraform plans and applies need.
How to Use Run Agents in Scalr?
In Scalr, agents are deployed as an agent pool, which can run on virtual machines, Docker, or Kubernetes. When a Terraform run is triggered from scalr.io, Scalr hands off the run operations through an HTTP relay to the Terraform agent, passing along Terraform configuration files, secrets, environment variables, custom hooks, and more. The agent spins up a container, executes the Terraform plan and apply in it, and relays all of the output back to scalr.io for developers to view. Once the Terraform run has finished, the agent goes back to idle until the next run.
How to Use VCS Agents in Scalr?
An organization that runs its VCS provider internally or behind a firewall is very unlikely to open it to the internet, since sensitive information or code could leak. In most cases, Terraform configuration files and modules all come from VCS providers, which is why VCS agents can be a critical part of the setup. VCS agents let developers connect their VCS providers to Scalr without opening the VCS provider to the internet. They also use a secure HTTP relay to pass the configuration files to Scalr.
Why Doesn't Scalr Charge for Agents?
Scalr only charges for a Terraform run, nothing else. We don't think you should be penalized for following best practices and making your environment more secure. We also don't think we should charge you more for hosting the agent pool on your own virtual machine or Kubernetes cluster. The value of Scalr is the Terraform run and the tooling we supply around it for automation, collaboration, visibility, and more.
Should you use self-hosted agents?
A self-hosted agent pool gives you more control over your Terraform operations when you run a product like Scalr or Terraform Cloud. You keep ownership of the execution environment while a SaaS platform still handles the scaling and management around your deployments. In highly secure environments, agents are considered a best practice for meeting security and compliance requirements.
Frequently asked questions
Does Scalr charge for self-hosted Terraform agents?
No. Extra agents are free on every Scalr plan, including the free version, because Scalr only charges for Terraform runs. Terraform Cloud, by comparison, limits you to one agent unless you move to a more expensive tier or buy more.
What types of self-hosted agents does Scalr offer?
Scalr has two agent types. Self-hosted run agents execute Terraform runs on your own infrastructure, whether public cloud or on-premise, giving you control over the execution environment. Self-hosted VCS agents pull Terraform configuration files and modules from a version control provider that isn't accessible from the internet, using a secure HTTP relay.
Why would you use self-hosted Terraform agents?
Security is the main reason: you can configure agents to meet specific compliance standards, and an agent pool can inherit credentials from something like an AWS instance profile so no secrets need to live in the platform. You also control the execution environment, so dependencies can be baked into the agent instead of installed before every run. And since agents run on your hardware, you can size resources to fit your Terraform workloads.
How do Scalr run agents work?
Agents are deployed as an agent pool on virtual machines, Docker, or Kubernetes. When a run is triggered, Scalr hands off the operation through an HTTP relay to the agent, passing along configuration files, secrets, environment variables, and custom hooks. The agent runs the plan and apply in a container, relays the output back to scalr.io, then returns to idle until the next run.
About the author

director of platform engineering at Scalr
Ryan Fee is the director of platform engineering at Scalr, with over 15 years of experience improving infrastructure experiences at companies large and small.
Part of this guide
3 sheets