Terraform vs OpenTofu: Differences, License and Which One to Choose
Why there are two tools #
In August 2023 HashiCorp changed the license of Terraform from the open-source MPL 2.0 to the Business Source License (BSL 1.1). The community answered with a fork, first called OpenTF and now OpenTofu, which became a project of the Linux Foundation and was later accepted into the CNCF. OpenTofu keeps the MPL 2.0 license. HashiCorp was later acquired by IBM, but the Terraform license did not return to open source.
Both tools read the same HCL language and use the same providers and modules, so for most people the day-to-day commands are identical: tofu init, tofu plan and tofu apply.
Comparison #
| Terraform | OpenTofu | |
|---|---|---|
| License | BSL 1.1 (source available) | MPL 2.0 (open source) |
| Governance | IBM / HashiCorp | Linux Foundation, community |
| Command | terraform |
tofu |
| Registry | registry.terraform.io | registry.opentofu.org |
| Providers and modules | Yes | Yes (same ones) |
| State and backends | Yes | Yes, compatible |
| Client-side state encryption | No | Yes (state encryption) |
Provider for_each |
No | Yes (1.9 and later) |
| Native tests | Yes | Yes |
| Managed platform | HCP Terraform | Third parties: Spacelift, env0, Scalr and others |
Features change in every release, so check the current release notes of both projects before deciding.
What the BSL license means for you #
The BSL does not prevent you from using Terraform to manage your own or your customers' infrastructure. It restricts using it to build a product that competes with HashiCorp's commercial offerings. If you are a company that only deploys infrastructure, you are probably not affected, but legal teams of some companies prefer an open-source license, and some Linux distributions and cloud vendors cannot redistribute BSL software.
Differences in practice #
- State encryption in OpenTofu protects the state and plan files without depending on the backend. This is a significant advantage when state contains secrets (secrets management).
- Early variable evaluation (1.8) allows variables and locals in module sources and backend configuration, something Terraform does not support.
- Provider
for_each(1.9) lets you create one provider configuration per region or account in a loop. - Terraform-only features: HCP Terraform integration, ephemeral resources and write-only arguments appeared first in Terraform (OpenTofu has since added support for ephemeral resources, check your version), and Terraform Stacks.
Compatibility and migration #
OpenTofu 1.6 was compatible with Terraform 1.5 and the 1.6 series. Since then both evolve independently, so the compatibility with the latest Terraform versions can not be assumed. Migration is simple for most projects and reversible while you stay inside the common feature set. See the migration tutorial and the installation guide.
Which one should you choose? #
- OpenTofu if you want an open-source license, state encryption, or you are starting a new project and have no HCP Terraform dependency.
- Terraform if you use HCP Terraform, Sentinel or Stacks, or your company has a support contract with HashiCorp.
- Either one if the team is small and nothing above matters. You can write code that works with both by avoiding exclusive features.
All the tutorials in this site run on both. See the AWS with Terraform series for a complete example.