OpenTofu¶
Summary
OpenTofu is the open-source (MPL-2.0) fork of Terraform. It is a Linux Foundation project and has been in the CNCF Sandbox since April 2025. It forked from Terraform 1.5.x after HashiCorp moved Terraform to BSL 1.1. It stays compatible with Terraform HCL, state and providers, and it adds features Terraform lacks: client-side state and plan encryption, early variable evaluation in backend and module-source blocks, provider for_each, -exclude, and OCI registry distribution. The current stable series is 1.12 (1.12.6, 2026-08-19). 1.13 is at release candidate with experimental Symbol Libraries.
Key Facts¶
| Attribute | Detail |
|---|---|
| Latest Version | 1.12.6 (2026-08-19). 1.13.0-rc1 in testing (2026-09). |
| Supported series | 1.12 until 2027-02-01. 1.13 until 2027-08-01. 1.11 support ended 2026-08-01. |
| Release cadence | No fixed cycle. Minor releases have come roughly every 5 to 6 months (1.9 2025-01, 1.10 2025-06, 1.11 2025-12, 1.12 2026-05). |
| License | MPL-2.0 (OSI-approved) |
| Governance | Linux Foundation project run by a Technical Steering Committee. CNCF Sandbox since 2025-04-23. |
| Language / config | Go, HCL (.tf plus OpenTofu-only .tofu files) |
| Registry | registry.opentofu.org (browse at search.opentofu.org). OCI registries since 1.10. |
| Repository | github.com/opentofu/opentofu |
| Stars | ~24k+ (recorded by 2026-08) |
| Pricing | Free. No first-party SaaS. Supported by commercial TACOS (Spacelift, env0, Scalr, Harness). |
Architecture at a Glance¶
A tofu run loads the configuration, builds a dependency graph, and drives provider plugins over gRPC. State passes through the encryption layer on its way to the backend.
graph LR
CLI["tofu CLI"] --> CFG["Config loader<br/>+ static eval"]
CFG --> DAG["Graph + evaluator"]
DAG -->|"gRPC tfplugin5/6"| PROV["Provider plugins"]
PROV --> API["Cloud APIs"]
DAG --> ENC["State/plan encryption<br/>(aes_gcm + key provider)"]
ENC --> BE["Backend<br/>(s3, gcs, azurerm, pg, local)"]
CLI -->|"init"| REG["registry.opentofu.org<br/>or OCI mirror"]
The full component, protocol and encryption diagrams are in Explanation.
Evaluation¶
| Pros | Cons |
|---|---|
| Drop-in replacement for Terraform 1.5.x. Same HCL, state format and provider binaries. | Diverges from Terraform 1.6+ in both directions, so Terraform-only features will not run |
| MPL-2.0 under neutral foundation governance. No relicensing risk. | Smaller contributor base and ecosystem mindshare than Terraform |
| Native client-side state and plan encryption (AES-GCM with KMS, OpenBao, Azure Key Vault or PBKDF2) | Encryption adds key-management duties. Losing the key means losing the state. |
Features Terraform lacks: early evaluation in backend and encryption blocks, provider for_each, -exclude, OCI distribution, .tofu overrides |
No first-party managed service like HCP Terraform. You rely on third-party TACOS. |
| Ephemeral values and write-only attributes (1.11+) keep secrets out of state | Some vendor docs, examples and tools still assume terraform |
| Community-driven roadmap and public TSC, CNCF Sandbox | Frequent security patches (six in the v1.12 series), so stay current |
When it fits¶
- Good fit: teams on Terraform 1.5 or earlier that want an OSI-licensed tool. Regulated environments that need state encrypted at rest regardless of backend. Multi-region estates that benefit from provider
for_each. Air-gapped sites that already run an OCI registry. - Weaker fit: organizations standardized on HCP Terraform or Terraform Enterprise features (Sentinel, Stacks), or configurations that already depend on Terraform-only language features added after 1.5.
Key Differentiators vs Terraform¶
| Feature | OpenTofu | Terraform |
|---|---|---|
| License | MPL-2.0 | BSL 1.1 |
| State and plan encryption | Native, client-side (1.7+) | Not available. Backend or HCP at-rest encryption only. |
| Variables in backend and encryption config | Yes (1.8+) | No (Terraform 1.15+ allows variables only in module source/version) |
Provider for_each |
Yes (1.9+) | No |
| OCI registry for providers and modules | Yes (1.10+) | No |
| Ephemeral resources and write-only attributes | Yes (1.11+) | Yes |
| Governance | Linux Foundation / CNCF Sandbox | HashiCorp (IBM) |
| Provider compatibility | Same provider binaries | Same |
The version-by-version detail is in Reference: features by version.
Topic Map¶
- How-to Guides: install, migrate from Terraform, encrypt state, move S3 locking off DynamoDB, OCI mirrors, provider
for_each, ephemeral secrets, troubleshooting. - Reference: release and support matrix, features by version, OpenTofu-only CLI flags and environment variables, encryption key providers, backends, lock-file hashes, protocol RPCs, security advisories, hardening checklist.
- Explanation: origins and governance, core engine, static evaluation, plugin protocol, plan/apply lifecycle, state encryption design and threat model, ephemeral values, registry and OCI installation, the next-generation engine RFC.
Related Topics¶
- IaC Tools Comparison: Terraform vs OpenTofu vs Pulumi
- Terraform: the upstream project and its BSL-licensed line
- Pulumi: general-purpose-language IaC. It bridges Terraform/OpenTofu providers.
- HashiCorp Vault: dynamic credentials for providers. Its fork OpenBao is an OpenTofu encryption key provider.
- SOPS: file-level secret encryption, an alternative for secrets in IaC repos
- OpenTelemetry: OpenTofu 1.10+ can export traces over OTLP
- Argo CD: GitOps delivery of what OpenTofu provisions
- Multi-cloud governance and Proxmox: environments commonly managed with OpenTofu
Sources¶
- OpenTofu documentation
- OpenTofu GitHub repository and releases
- v1.12 CHANGELOG, v1.13 CHANGELOG, main CHANGELOG
- OpenTofu v1.12.0 announcement and InfoQ: OpenTofu 1.12 (2026-05)
- OpenTofu v1.11.0 announcement
- OpenTofu 1.10.0 announcement
- An Introduction to OpenTofu Symbol Libraries (2026-09-17)
- State and plan encryption
- Migration guide
- CNCF project page and The New Stack: OpenTofu joins CNCF
- Governance (opentofu/org)
- OpenTofu Registry search
Questions¶
Answered¶
- Q: Is OpenTofu a drop-in Terraform replacement? Yes, for Terraform 1.5.x and earlier: same HCL, state and providers. Run
tofu initandtofu planand expect no changes. Configurations that use Terraform-only features added after the fork need review (migration guide). - Q: Is OpenTofu in the CNCF? Yes. It was accepted at Sandbox level on 2025-04-23, with a license exception for MPL-2.0. It is also a Linux Foundation project.
- Q: What are the support end dates for 1.10 and earlier? OpenTofu never published them: the 1.6 to 1.10 branch changelogs have no support line (dated support starts with 1.11), and opentofu.org marks the 1.6 to 1.11 docs as unmaintained (checked 2026-09-27; see Reference).
- Q: Can S3 state locking work without DynamoDB? Yes, since 1.10 with
use_lockfile = true(How-to).
Open¶
- Q: What is the migration path from HCP Terraform to self-hosted OpenTofu backends? Evaluate S3, GCS or pg backends with state encryption enabled, and a third-party TACOS for remote runs and policy.
- Q: How far does the provider ecosystem diverge? The same binaries serve both tools today. Watch for providers that start requiring Terraform-only protocol features. The registry metadata repo opentofu/registry holds 4,603 provider and 25,873 module entries (counted 2026-09-27).
- Q: When will Symbol Libraries and the new plan/apply engine (RFC 2025-10) stabilize? The maintainers target Symbol Libraries for stabilization in 1.14. The engine RFC has no release target yet.