Files
atelier/domains/infrastructure-as-code/opentofu.md
T
Jon Chery d1aa5daf2b docs(milestone): complete v0.2 — infrastructure-as-code + kubernetes
---ci---
project: atelier
phase: 5
milestone: v0.2
status: complete
requirements:
  covered: [ATELIER-36, ATELIER-37, ATELIER-38, ATELIER-39, ATELIER-40, ATELIER-41, ATELIER-42, ATELIER-43, ATELIER-44, ATELIER-45, ATELIER-46, ATELIER-47, ATELIER-48, ATELIER-49, ATELIER-50, ATELIER-51, ATELIER-52, ATELIER-53, ATELIER-54, ATELIER-55, ATELIER-56, ATELIER-57, ATELIER-58, ATELIER-59]
  partial: []
---/ci---
2026-08-05 02:20:17 +00:00

3.7 KiB

OpenTofu — Derived Rules

Derives from domains/infrastructure-as-code/first-principles.md. OpenTofu is the open-source fork of Terraform; this doc covers fork-specific governance, license, and migration. The shared HCL/state/module model is documented in terraform.md. See also state.md and modules.md.

Fork Lineage (P5 Version Everything)

  • OpenTofu is a 2023 fork of Terraform, created when HashiCorp switched Terraform from MPL-2.0 to the Business Source License (BUSL), which is not open source.
  • OpenTofu is stewarded by the Linux Foundation under a genuinely open-source license. The fork's reason for existing is license neutrality.
  • Both tools implement the same HCL configuration language, the same provider protocol, and the same state model. Configuration written for one runs on the other at the fork point; divergence accrues slowly over time.

When to Choose OpenTofu (P7 Least Privilege Providers, supply-chain)

  • License neutrality matters: if your organization cannot accept BUSL's "competitive use" ambiguity, OpenTofu removes it.
  • Supply-chain provenance: Linux Foundation stewardship means no single vendor can relicense the tool out from under you.
  • Community governance: features and fixes are accepted on merit, not vendor strategy.
  • When NOT to switch: if you depend on HCP Terraform (HashiCorp's managed platform), BUSL-licensed providers, or provider features that have diverged since the fork, stay on Terraform. The decision is supply-chain, not syntax.

CLI Parity (P1 Declarative Intent)

  • tofu init, tofu plan, tofu apply, tofu destroy mirror terraform init/plan/apply/destroy.
  • The lock file (.terraform.lock.hcl.tofu.lock.hcl) is committed; it makes init reproducible.
  • Workspaces, state backends, and module sources behave as in Terraform — see terraform.md and state.md.

Registry Parity (P6 Modules Compose)

  • OpenTofu can consume the Terraform Registry and the OpenTofu Registry. Module version pinning works identically.
  • Some providers have BUSL licenses that OpenTofu cannot ship; verify a provider's license before adopting it. An MPL or Apache provider is portable; a BUSL provider is not.
  • See modules.md for module structure, which is unchanged from Terraform.

Migration from Terraform (P5 Version Everything, P9 Drift is Recoverable)

  • terraform state pull > state.jsontofu state push state.json carries state across. Validate with tofu plan after the push — the plan should be empty.
  • Rename the binary in CI: replace terraform with tofu in scripts. The lock file may need regeneration.
  • Migrate one workspace at a time. Do not big-bang a migration; rehearse on a non-prod workspace first (P4 Plan Before Apply applies to the migration itself).
  • Pin the OpenTofu version in CI. A migration is a versioned, reviewed change, not a quiet swap.
  • OpenTofu's governance model — impartial, community-driven, layered, modular, backwards-compatible — is itself a supply-chain principle. A tool you cannot trust to remain open is a tool you cannot build on.
  • This is the OpenTofu angle on security/supply-chain.md: license is a supply-chain property, not a legal footnote.

What Violates OpenTofu Discipline

Violation Principle
Assuming OpenTofu == latest Terraform (unverified parity) P5 Version Everything
Migrating prod state without a non-prod rehearsal P4 Plan Before Apply
Adopting a BUSL-licensed provider into OpenTofu CI P7 Least Privilege Providers, supply-chain
Quiet swap of terraform for tofu without a versioned change P5 Version Everything
Losing state during migration P3 State is Truth