Skip to content

OpenTofu

Summary

OpenTofu is the open-source (MPL-2.0) fork of Terraform. It is a Linux Foundation project and has been in the CNCF Sandbox since April 2025. It forked from Terraform 1.5.x after HashiCorp moved Terraform to BSL 1.1. It stays compatible with Terraform HCL, state and providers, and it adds features Terraform lacks: client-side state and plan encryption, early variable evaluation in backend and module-source blocks, provider for_each, -exclude, and OCI registry distribution. The current stable series is 1.12 (1.12.6, 2026-08-19). 1.13 is at release candidate with experimental Symbol Libraries.

Key Facts

Attribute Detail
Latest Version 1.12.6 (2026-08-19). 1.13.0-rc1 in testing (2026-09).
Supported series 1.12 until 2027-02-01. 1.13 until 2027-08-01. 1.11 support ended 2026-08-01.
Release cadence No fixed cycle. Minor releases have come roughly every 5 to 6 months (1.9 2025-01, 1.10 2025-06, 1.11 2025-12, 1.12 2026-05).
License MPL-2.0 (OSI-approved)
Governance Linux Foundation project run by a Technical Steering Committee. CNCF Sandbox since 2025-04-23.
Language / config Go, HCL (.tf plus OpenTofu-only .tofu files)
Registry registry.opentofu.org (browse at search.opentofu.org). OCI registries since 1.10.
Repository github.com/opentofu/opentofu
Stars ~24k+ (recorded by 2026-08)
Pricing Free. No first-party SaaS. Supported by commercial TACOS (Spacelift, env0, Scalr, Harness).

Architecture at a Glance

A tofu run loads the configuration, builds a dependency graph, and drives provider plugins over gRPC. State passes through the encryption layer on its way to the backend.

graph LR
    CLI["tofu CLI"] --> CFG["Config loader<br/>+ static eval"]
    CFG --> DAG["Graph + evaluator"]
    DAG -->|"gRPC tfplugin5/6"| PROV["Provider plugins"]
    PROV --> API["Cloud APIs"]
    DAG --> ENC["State/plan encryption<br/>(aes_gcm + key provider)"]
    ENC --> BE["Backend<br/>(s3, gcs, azurerm, pg, local)"]
    CLI -->|"init"| REG["registry.opentofu.org<br/>or OCI mirror"]

The full component, protocol and encryption diagrams are in Explanation.

Evaluation

Pros Cons
Drop-in replacement for Terraform 1.5.x. Same HCL, state format and provider binaries. Diverges from Terraform 1.6+ in both directions, so Terraform-only features will not run
MPL-2.0 under neutral foundation governance. No relicensing risk. Smaller contributor base and ecosystem mindshare than Terraform
Native client-side state and plan encryption (AES-GCM with KMS, OpenBao, Azure Key Vault or PBKDF2) Encryption adds key-management duties. Losing the key means losing the state.
Features Terraform lacks: early evaluation in backend and encryption blocks, provider for_each, -exclude, OCI distribution, .tofu overrides No first-party managed service like HCP Terraform. You rely on third-party TACOS.
Ephemeral values and write-only attributes (1.11+) keep secrets out of state Some vendor docs, examples and tools still assume terraform
Community-driven roadmap and public TSC, CNCF Sandbox Frequent security patches (six in the v1.12 series), so stay current

When it fits

  • Good fit: teams on Terraform 1.5 or earlier that want an OSI-licensed tool. Regulated environments that need state encrypted at rest regardless of backend. Multi-region estates that benefit from provider for_each. Air-gapped sites that already run an OCI registry.
  • Weaker fit: organizations standardized on HCP Terraform or Terraform Enterprise features (Sentinel, Stacks), or configurations that already depend on Terraform-only language features added after 1.5.

Key Differentiators vs Terraform

Feature OpenTofu Terraform
License MPL-2.0 BSL 1.1
State and plan encryption Native, client-side (1.7+) Not available. Backend or HCP at-rest encryption only.
Variables in backend and encryption config Yes (1.8+) No (Terraform 1.15+ allows variables only in module source/version)
Provider for_each Yes (1.9+) No
OCI registry for providers and modules Yes (1.10+) No
Ephemeral resources and write-only attributes Yes (1.11+) Yes
Governance Linux Foundation / CNCF Sandbox HashiCorp (IBM)
Provider compatibility Same provider binaries Same

The version-by-version detail is in Reference: features by version.

Topic Map

  • How-to Guides: install, migrate from Terraform, encrypt state, move S3 locking off DynamoDB, OCI mirrors, provider for_each, ephemeral secrets, troubleshooting.
  • Reference: release and support matrix, features by version, OpenTofu-only CLI flags and environment variables, encryption key providers, backends, lock-file hashes, protocol RPCs, security advisories, hardening checklist.
  • Explanation: origins and governance, core engine, static evaluation, plugin protocol, plan/apply lifecycle, state encryption design and threat model, ephemeral values, registry and OCI installation, the next-generation engine RFC.

Sources

Questions

Answered

  • Q: Is OpenTofu a drop-in Terraform replacement? Yes, for Terraform 1.5.x and earlier: same HCL, state and providers. Run tofu init and tofu plan and expect no changes. Configurations that use Terraform-only features added after the fork need review (migration guide).
  • Q: Is OpenTofu in the CNCF? Yes. It was accepted at Sandbox level on 2025-04-23, with a license exception for MPL-2.0. It is also a Linux Foundation project.
  • Q: What are the support end dates for 1.10 and earlier? OpenTofu never published them: the 1.6 to 1.10 branch changelogs have no support line (dated support starts with 1.11), and opentofu.org marks the 1.6 to 1.11 docs as unmaintained (checked 2026-09-27; see Reference).
  • Q: Can S3 state locking work without DynamoDB? Yes, since 1.10 with use_lockfile = true (How-to).

Open

  • Q: What is the migration path from HCP Terraform to self-hosted OpenTofu backends? Evaluate S3, GCS or pg backends with state encryption enabled, and a third-party TACOS for remote runs and policy.
  • Q: How far does the provider ecosystem diverge? The same binaries serve both tools today. Watch for providers that start requiring Terraform-only protocol features. The registry metadata repo opentofu/registry holds 4,603 provider and 25,873 module entries (counted 2026-09-27).
  • Q: When will Symbol Libraries and the new plan/apply engine (RFC 2025-10) stabilize? The maintainers target Symbol Libraries for stabilization in 1.14. The engine RFC has no release target yet.