# What is OpenTofu? The Open-Source Fork of Terraform Explained

> OpenTofu is the open-source Infrastructure as Code tool, a fork of Terraform managed by the Linux Foundation. Learn what it is, how it works and how to start.

- Source: https://www.itwonderlab.com/what-is-opentofu/
- Published: 2026-09-19
- Updated: 2026-09-19
- Author: Javier Ruiz Jiménez (https://www.javierruizjimenez.com/)
- Site: IT Wonder Lab (https://www.itwonderlab.com/)

---

## OpenTofu in a nutshell

**OpenTofu** is an open-source [Infrastructure as Code (IaC)](https://www.itwonderlab.com/iac/) tool. You describe the infrastructure you want (networks, servers, databases, DNS records) in text files written in [HCL](https://www.itwonderlab.com/hcl/), and OpenTofu compares it with what exists and creates, changes or deletes resources until both match. It works with AWS, Azure, Google Cloud, Kubernetes and thousands of other services through **providers**.

It started in 2023 as a fork of Terraform 1.5 after HashiCorp changed Terraform's license. It is governed by the Linux Foundation and is now a CNCF project, and it keeps the MPL 2.0 open-source license. For a detailed comparison read [Terraform vs OpenTofu](https://www.itwonderlab.com/terraform-vs-opentofu/).

### How it works

1. **Write** the configuration in `.tf` files.
2. **`tofu init`** downloads the providers and modules and configures the [backend](https://www.itwonderlab.com/terraform-backend/).
3. **`tofu plan`** reads the real state of the infrastructure and shows what will change.
4. **`tofu apply`** executes the changes and records the result in the [state](https://www.itwonderlab.com/terraform-state/).
5. **`tofu destroy`** removes everything that the configuration manages.

### A first example

```hcl title="main.tf"
terraform {
  required_providers {
    aws = {
      source  = "hashicorp/aws"
      version = "~> 5.0"
    }
  }
}

provider "aws" {
  region = "eu-west-1"
}

resource "aws_s3_bucket" "example" {
  bucket = "my-unique-bucket-name-12345"
}
```

```shell
$ tofu init
$ tofu plan
$ tofu apply
```

The configuration blocks are still named `terraform {}`, and the files still use the `.tf` extension, so existing code works without changes.

### Features that stand out

- **State and plan encryption** on the client ([how to encrypt the state](https://www.itwonderlab.com/terraform-state-file-encryption/)).
- **Provider iteration with `for_each`** and **early variable evaluation** for module sources and backends.
- **Built-in testing** with `tofu test` ([testing](https://www.itwonderlab.com/terraform-testing-opentofu-test/)).
- An **open registry** at registry.opentofu.org, with the same providers and modules that Terraform uses.
- A public roadmap driven by community RFCs.

### Who uses it

OpenTofu is a replacement for teams that need an open-source license, that want a tool not controlled by a single company or that need state encryption. Platforms such as Spacelift, env0, Scalr and Terragrunt support it.

### Start learning

1. [Install OpenTofu](https://www.itwonderlab.com/how-to-install-opentofu/).
2. Follow the [AWS with Terraform series](https://www.itwonderlab.com/aws-terraform-tutorial-terraform-basics/), which uses OpenTofu in every example.
3. If you already use Terraform, [migrate your infrastructure](https://www.itwonderlab.com/terraform-to-opentofu/).
4. Learn the [commands](https://www.itwonderlab.com/terraform-cheat-sheet/) and the recommended [project structure](https://www.itwonderlab.com/terraform-project-structure/).
