d1aa5daf2b
---ci--- project: atelier phase: 5 milestone: v0.2 status: complete requirements: covered: [ATELIER-36, ATELIER-37, ATELIER-38, ATELIER-39, ATELIER-40, ATELIER-41, ATELIER-42, ATELIER-43, ATELIER-44, ATELIER-45, ATELIER-46, ATELIER-47, ATELIER-48, ATELIER-49, ATELIER-50, ATELIER-51, ATELIER-52, ATELIER-53, ATELIER-54, ATELIER-55, ATELIER-56, ATELIER-57, ATELIER-58, ATELIER-59] partial: [] ---/ci---
3.7 KiB
3.7 KiB
OpenTofu — Derived Rules
Derives from
domains/infrastructure-as-code/first-principles.md. OpenTofu is the open-source fork of Terraform; this doc covers fork-specific governance, license, and migration. The shared HCL/state/module model is documented interraform.md. See alsostate.mdandmodules.md.
Fork Lineage (P5 Version Everything)
- OpenTofu is a 2023 fork of Terraform, created when HashiCorp switched Terraform from MPL-2.0 to the Business Source License (BUSL), which is not open source.
- OpenTofu is stewarded by the Linux Foundation under a genuinely open-source license. The fork's reason for existing is license neutrality.
- Both tools implement the same HCL configuration language, the same provider protocol, and the same state model. Configuration written for one runs on the other at the fork point; divergence accrues slowly over time.
When to Choose OpenTofu (P7 Least Privilege Providers, supply-chain)
- License neutrality matters: if your organization cannot accept BUSL's "competitive use" ambiguity, OpenTofu removes it.
- Supply-chain provenance: Linux Foundation stewardship means no single vendor can relicense the tool out from under you.
- Community governance: features and fixes are accepted on merit, not vendor strategy.
- When NOT to switch: if you depend on HCP Terraform (HashiCorp's managed platform), BUSL-licensed providers, or provider features that have diverged since the fork, stay on Terraform. The decision is supply-chain, not syntax.
CLI Parity (P1 Declarative Intent)
tofu init,tofu plan,tofu apply,tofu destroymirrorterraform init/plan/apply/destroy.- The lock file (
.terraform.lock.hcl→.tofu.lock.hcl) is committed; it makesinitreproducible. - Workspaces, state backends, and module sources behave as in Terraform — see
terraform.mdandstate.md.
Registry Parity (P6 Modules Compose)
- OpenTofu can consume the Terraform Registry and the OpenTofu Registry. Module version pinning works identically.
- Some providers have BUSL licenses that OpenTofu cannot ship; verify a provider's license before adopting it. An MPL or Apache provider is portable; a BUSL provider is not.
- See
modules.mdfor module structure, which is unchanged from Terraform.
Migration from Terraform (P5 Version Everything, P9 Drift is Recoverable)
terraform state pull > state.json→tofu state push state.jsoncarries state across. Validate withtofu planafter the push — the plan should be empty.- Rename the binary in CI: replace
terraformwithtofuin scripts. The lock file may need regeneration. - Migrate one workspace at a time. Do not big-bang a migration; rehearse on a non-prod workspace first (P4 Plan Before Apply applies to the migration itself).
- Pin the OpenTofu version in CI. A migration is a versioned, reviewed change, not a quiet swap.
Governance and Community (cross-link domains/security/supply-chain.md)
- OpenTofu's governance model — impartial, community-driven, layered, modular, backwards-compatible — is itself a supply-chain principle. A tool you cannot trust to remain open is a tool you cannot build on.
- This is the OpenTofu angle on
security/supply-chain.md: license is a supply-chain property, not a legal footnote.
What Violates OpenTofu Discipline
| Violation | Principle |
|---|---|
| Assuming OpenTofu == latest Terraform (unverified parity) | P5 Version Everything |
| Migrating prod state without a non-prod rehearsal | P4 Plan Before Apply |
| Adopting a BUSL-licensed provider into OpenTofu CI | P7 Least Privilege Providers, supply-chain |
Quiet swap of terraform for tofu without a versioned change |
P5 Version Everything |
| Losing state during migration | P3 State is Truth |