What is OpenTofu? The Open-Source Fork of Terraform Explained
OpenTofu in a nutshell #
OpenTofu is an open-source Infrastructure as Code (IaC) tool. You describe the infrastructure you want (networks, servers, databases, DNS records) in text files written in HCL, and OpenTofu compares it with what exists and creates, changes or deletes resources until both match. It works with AWS, Azure, Google Cloud, Kubernetes and thousands of other services through providers.
It started in 2023 as a fork of Terraform 1.5 after HashiCorp changed Terraform's license. It is governed by the Linux Foundation and is now a CNCF project, and it keeps the MPL 2.0 open-source license. For a detailed comparison read Terraform vs OpenTofu.
How it works #
- Write the configuration in
.tffiles. tofu initdownloads the providers and modules and configures the backend.tofu planreads the real state of the infrastructure and shows what will change.tofu applyexecutes the changes and records the result in the state.tofu destroyremoves everything that the configuration manages.
A first example #
terraform {
required_providers {
aws = {
source = "hashicorp/aws"
version = "~> 5.0"
}
}
}
provider "aws" {
region = "eu-west-1"
}
resource "aws_s3_bucket" "example" {
bucket = "my-unique-bucket-name-12345"
}$ tofu init
$ tofu plan
$ tofu apply
The configuration blocks are still named terraform {}, and the files still use the .tf extension, so existing code works without changes.
Features that stand out #
- State and plan encryption on the client (how to encrypt the state).
- Provider iteration with
for_eachand early variable evaluation for module sources and backends. - Built-in testing with
tofu test(testing). - An open registry at registry.opentofu.org, with the same providers and modules that Terraform uses.
- A public roadmap driven by community RFCs.
Who uses it #
OpenTofu is a replacement for teams that need an open-source license, that want a tool not controlled by a single company or that need state encryption. Platforms such as Spacelift, env0, Scalr and Terragrunt support it.
Start learning #
- Install OpenTofu.
- Follow the AWS with Terraform series, which uses OpenTofu in every example.
- If you already use Terraform, migrate your infrastructure.
- Learn the commands and the recommended project structure.