# OpenTofu — Derived Rules > Derives from `domains/infrastructure-as-code/first-principles.md`. OpenTofu is the open-source fork of Terraform; this doc covers fork-specific governance, license, and migration. The shared HCL/state/module model is documented in `terraform.md`. See also `state.md` and `modules.md`. ## Fork Lineage (P5 Version Everything) - OpenTofu is a 2023 fork of Terraform, created when HashiCorp switched Terraform from MPL-2.0 to the Business Source License (BUSL), which is not open source. - OpenTofu is stewarded by the Linux Foundation under a genuinely open-source license. The fork's reason for existing is license neutrality. - Both tools implement the same HCL configuration language, the same provider protocol, and the same state model. Configuration written for one runs on the other at the fork point; divergence accrues slowly over time. ## When to Choose OpenTofu (P7 Least Privilege Providers, supply-chain) - **License neutrality matters:** if your organization cannot accept BUSL's "competitive use" ambiguity, OpenTofu removes it. - **Supply-chain provenance:** Linux Foundation stewardship means no single vendor can relicense the tool out from under you. - **Community governance:** features and fixes are accepted on merit, not vendor strategy. - **When NOT to switch:** if you depend on HCP Terraform (HashiCorp's managed platform), BUSL-licensed providers, or provider features that have diverged since the fork, stay on Terraform. The decision is supply-chain, not syntax. ## CLI Parity (P1 Declarative Intent) - `tofu init`, `tofu plan`, `tofu apply`, `tofu destroy` mirror `terraform init/plan/apply/destroy`. - The lock file (`.terraform.lock.hcl` → `.tofu.lock.hcl`) is committed; it makes `init` reproducible. - Workspaces, state backends, and module sources behave as in Terraform — see `terraform.md` and `state.md`. ## Registry Parity (P6 Modules Compose) - OpenTofu can consume the Terraform Registry and the OpenTofu Registry. Module version pinning works identically. - Some providers have BUSL licenses that OpenTofu cannot ship; verify a provider's license before adopting it. An MPL or Apache provider is portable; a BUSL provider is not. - See `modules.md` for module structure, which is unchanged from Terraform. ## Migration from Terraform (P5 Version Everything, P9 Drift is Recoverable) - `terraform state pull > state.json` → `tofu state push state.json` carries state across. Validate with `tofu plan` after the push — the plan should be empty. - Rename the binary in CI: replace `terraform` with `tofu` in scripts. The lock file may need regeneration. - Migrate one workspace at a time. Do not big-bang a migration; rehearse on a non-prod workspace first (P4 Plan Before Apply applies to the migration itself). - Pin the OpenTofu version in CI. A migration is a versioned, reviewed change, not a quiet swap. ## Governance and Community (cross-link `domains/security/supply-chain.md`) - OpenTofu's governance model — impartial, community-driven, layered, modular, backwards-compatible — is itself a supply-chain principle. A tool you cannot trust to remain open is a tool you cannot build on. - This is the OpenTofu angle on `security/supply-chain.md`: license is a supply-chain property, not a legal footnote. ## What Violates OpenTofu Discipline | Violation | Principle | |-----------|-----------| | Assuming OpenTofu == latest Terraform (unverified parity) | P5 Version Everything | | Migrating prod state without a non-prod rehearsal | P4 Plan Before Apply | | Adopting a BUSL-licensed provider into OpenTofu CI | P7 Least Privilege Providers, supply-chain | | Quiet swap of `terraform` for `tofu` without a versioned change | P5 Version Everything | | Losing state during migration | P3 State is Truth |