CFEngine
CFEngine automates infrastructure, security, and compliance by steering managed systems toward a state defined by users. Users express that state in CFEngine's domain-specific language, and lightweight agents work to bring each device into compliance. By default, an agent contacts the CFEngine hub every five minutes. The platform runs on embedded devices, servers, cloud systems, and mainframes, and is designed to handle tens or hundreds of thousands of nodes. Enterprise adds the Mission Portal web interface, an SQL-backed reporting hub, REST APIs, compliance reports, policy analysis, alerts, inventory and change reporting, file-integrity monitoring, and performance monitoring. Its dashboards show compliance and performance information and can be customized and shared. Secure bootstrap uses mutual authentication, key exchange, and encrypted TLS communication. Community Edition is free under GNU GPL, supports Linux, and includes community support. Enterprise is free for up to 25 hosts; other pricing is available on request. Listed operating systems include Linux distributions and Windows.
Who it is for
CFEngine suits organizations that manage infrastructure across many devices and want to define desired system states through policy. Enterprise is aimed at teams that need reporting and monitoring features.
What is good
- Agents check configuration compliance by default every five minutes.
- Designed for tens or hundreds of thousands of nodes.
- Enterprise includes compliance, inventory, and change reporting.
- Enterprise is free for up to 25 hosts.
What to know first
- Community Edition supports Linux only.
- Community Edition includes community support.
- Enterprise pricing beyond 25 hosts is available on request.
Verdict
CFEngine uses policy and agents to maintain infrastructure state, with Enterprise adding centralized reporting and monitoring. Confirm operating-system support and pricing for the size of your deployment.
CFEngine plans and pricing
All plansCompared on IT automation software
- Free plan
- Yes
- Deployment model
- self_hosted
- Agent model
- agent_based
- Drift detection
- Yes
- Patch management
- Yes
- Policy as code
- Yes
- Compliance reporting
- Yes
- Supported platforms
- Linux (RHEL, Debian, Ubuntu) and Windows





