Back to articles
Technology Insight

Building a Robust GitOps Infrastructure Deployment Control System with Atlantis and OpenTofu on VPS

June 3, 2026

Introduction to GitOps for Infrastructure Management

In the modern DevOps landscape, managing infrastructure as code (IaC) has transitioned from a luxury to an absolute necessity. However, simply writing code is not enough. As engineering teams scale, the traditional method of running deployment commands from local machines introduces severe risks, including configurations drift, credential leakage, and a total lack of audit trails. This is where GitOps steps in.

GitOps shifts the source of truth for your infrastructure entirely to your Version Control System (VCS), such as GitHub or GitLab. By leveraging Git repositories as the definitive state of your infrastructure, every change must pass through a structured peer-review process. In this comprehensive guide, we will explore how to construct a secure, self-hosted GitOps control system using OpenTofu (the open-source evolution of Terraform) and Atlantis (the premier pull-request automation tool for IaC) hosted on a Virtual Private Server (VPS).

The Core Architectural Components

Before diving into the implementation details, it is crucial to understand the distinct roles each component plays within this ecosystem:

  • OpenTofu: An open-source, community-driven tool that defines, provisions, and configures infrastructure using a declarative configuration language. It functions as the execution engine for your infrastructure blueprints.
  • Atlantis: A self-hosted application that listens for webhooks from your Git provider. It executes OpenTofu commands directly within the context of a pull request (PR) or merge request (MR), commenting back the execution plans and applying changes only after formal approval.
  • VPS (Virtual Private Server): The hosting environment providing a dedicated, isolated space to run the Atlantis server safely, ensuring your cloud credentials remain secure and central.

Why Choose Atlantis and OpenTofu?

Combining Atlantis and OpenTofu creates a powerful synergy for modern engineering teams. First and foremost, collaboration is democratized. Developers and operations engineers do not need direct access to cloud providers or local installations of OpenTofu. They simply review code within GitHub or GitLab. When a PR is opened, Atlantis automatically executes an opentofu plan and posts the output as a comment on the PR. Team members can easily review exactly what resources will be created, modified, or destroyed.

"By moving the execution phase to Git pull requests, infrastructure changes shift from isolated black-box operations into transparent, team-approved evolutions."

Furthermore, this setup ensures strict compliance and safety. You can enforce branch protection rules requiring at least one peer approval before Atlantis allows an atlantis apply command to execute. This completely mitigates the risk of accidental production deletions or unvetted configuration changes.

Step-by-Step Implementation Guide on a VPS

1. Preparing the VPS Environment

To begin, log into your Ubuntu-based VPS via SSH and update the system packages. Next, install OpenTofu by adding its official repository to your package manager. Ensure that you also install standard utility tools such as curl, unzip, and git.

Once OpenTofu is installed, download the latest binary for Atlantis. Extract the binary and move it to a global execution directory like /usr/local/bin/. Verify both installations by checking their versions via the terminal command line.

2. Configuring Webhooks and Git Provider Access

For Atlantis to communicate effectively with your Git repository, you must generate a Personal Access Token (PAT) with repository scopes. Additionally, you will need to configure a unique Webhook Secret. On your Git repository settings page, point the webhook URL to your VPS public IP address or domain name on port 4141 (e.g., http://vps-ip:4141/events) and select pull request events as the trigger.

3. Setting Up the Atlantis Server Configurations

To ensure security and persistence, do not run Atlantis as the root user. Create a dedicated system user named atlantis. Next, construct a configuration file (typically named repos.yaml) to enforce strict server-side workflows. This file specifies which repositories Atlantis is allowed to run against and whether pre-workflow approvals are mandatory.

To manage the background process smoothly, configure a systemd service file (/etc/systemd/system/atlantis.service). This guarantees that Atlantis restarts automatically if the VPS reboots or experiences an unexpected failure.

The GitOps Lifecycle in Action

Once the system is successfully deployed, your daily deployment workflow transforms completely. Let us walk through the new lifecycle of an infrastructure change:

  1. Branch Creation: An engineer creates a new feature branch and modifies an OpenTofu configuration file (e.g., adding a new storage bucket or compute instance).
  2. Opening a Pull Request: The engineer pushes the branch and opens a PR. The Git provider instantly sends a webhook to the Atlantis server on your VPS.
  3. Automated Plan: Atlantis detects the changes, executes an internal tofu plan, and posts the detailed architectural output directly onto the PR comment thread.
  4. Peer Review & Approval: Senior team members analyze the plan output. If everything looks correct, they approve the PR.
  5. Execution via Comment: The author or reviewer comments atlantis apply directly on the PR page. Atlantis executes the deployment on the cloud provider and locks the state file to prevent race conditions.
  6. Merge: Once successful, the PR is merged into the main branch, ensuring the code matches live reality.

Security Best Practices for Production Deployments

Hosting your own deployment pipeline on a VPS requires careful attention to security. Consider implementing the following safeguards immediately:

  • Implement TLS/SSL: Do not expose the Atlantis port via plain HTTP. Use a reverse proxy like Nginx combined with Let's Encrypt to wrap all webhook traffic in secure HTTPS encryption.
  • Principle of Least Privilege: The cloud credentials stored on the VPS should only possess the exact permissions required to manage the targeted infrastructure resources, never full global administrative rights.
  • IP Whitelisting: Configure your VPS firewall (UFW) to only accept incoming traffic on port 4141 originating from your Git provider's verified IP ranges.

Conclusion

Building an infrastructure deployment control system with Atlantis and OpenTofu on a VPS bridges the gap between software engineering best practices and cloud operations. It replaces chaotic, localized deployments with a transparent, peer-reviewed, and completely auditable GitOps pipeline. By taking control of this stack on your own server, you maximize financial efficiency while retaining full ownership over your automation pipelines and sensitive cloud credentials. Start small, enforce branch approvals, and watch your team's deployment velocity and stability soar.

Building a Robust GitOps Infrastructure Deployment Control System with Atlantis and OpenTofu on VPS | DPTCloud