# Keel vs Terraform & OpenTofu

Keel generates and runs OpenTofu for a defined set of application infrastructure. State stays in your AWS account, and the generated configuration remains readable. OpenTofu is more flexible; Keel reduces the amount you have to design and maintain for supported workloads.

## What you'd be writing by hand

A production web app on AWS may need a VPC, subnets, routes, NAT, security groups, ECS resources, a load balancer, certificates, DNS, a container registry, a build pipeline, IAM roles, secrets, logs, autoscaling, and a firewall.

Keel generates these resources from `keel.yml`, including the relationships and IAM policies between them.

## Deploying, logs, and rollbacks included

OpenTofu manages infrastructure state but does not define an application deployment workflow. Keel adds commands for builds, logs, one-off tasks, scaling, and rollbacks:

```bash
keel deploy            # build, migrate, promote
keel logs -f
keel exec
keel scale web 6
keel rollback
```

## What Keel adds

**Know the bill before you build.** `keel cost` prices your app straight from your config — before anything exists. [More →](../guide/cost)

**A built-in access model.** Least-privilege roles, MFA, short-lived sessions, and staged team onboarding. [More →](../guide/auth)

**A dashboard over live state.** What's running, what deployed, what it's costing you. [More →](../guide/dashboard)

## You keep the parts you trust

A plan to review before anything changes. State in your own bucket, locked so two people can't collide. Whatever you already manage, linked in rather than rebuilt.

[Get started →](../guide/getting-started) · [Back to comparisons](./)
