Skip to content
DBDeependra Bhatta~/notes
Infrastructure as Code#installation · #opentofu · #quick-start-with-open-tofu

OpenTofu

OpenTofu is a reliable, flexible, community-driven infrastructure as code tool under the Linux Foundation’s stewardship. It serves as a drop-in replacement for Terraform, preserving your existing…

· updated · 5 min read
ON THIS PAGE

OpenTofu is a reliable, flexible, community-driven infrastructure as code tool under the Linux Foundation’s stewardship. It serves as a drop-in replacement for Terraform, preserving your existing workflows and configurations.

With a thriving ecosystem of 3,900+ providers and 23,600+ modules, you can build and manage infrastructure across every cloud platform with confidence.

What is OpenTofu?

OpenTofu is an open-source infrastructure as code tool that enables users to define, manage, and version cloud and on-premises resources using human-readable configuration files. It supports a consistent workflow to provision and manage infrastructure throughout its lifecycle, handling both low-level components (e.g., compute, storage, networking) and high-level components (e.g., DNS entries, SaaS features).

How Does OpenTofu Work?

OpenTofu interacts with cloud platforms and services via their APIs, supported by thousands of community-developed providers available on the Public OpenTofu Registry (e.g., AWS, Azure, GCP, Kubernetes). Its workflow includes three stages:

  • Write: Define resources across multiple providers in configuration files.
  • Plan: Generate an execution plan outlining infrastructure changes.
  • Apply: Execute the plan to create, update, or destroy resources in the correct order, respecting dependencies.

Why OpenTofu?

  • Manage Any Infrastructure: Supports numerous platforms via providers in the Public OpenTofu Registry or custom ones using the Terraform Plugin SDK, with an immutable infrastructure approach.
  • Track Infrastructure: Uses a state file as a source of truth to track real infrastructure and plan changes, ensuring alignment with configurations.
  • Automate Changes: Declarative configurations allow OpenTofu to handle resource creation logic and dependencies automatically, provisioning resources efficiently in parallel.
  • Standardize Configurations: Reusable modules promote best practices and save time, available publicly or customizable.
  • Collaborate: Configurations stored in version control systems, combined with cloud backends, enable team collaboration with secure state management, role-based access, and private registries.

Manifesto of OpenTofu

Background: Terraform, a popular tool for managing infrastructure, was open-source under the Mozilla Public License (MPL) since 2014, building a large community of users, contributors, and tools. In August 2023, HashiCorp, the company behind Terraform, changed its license to the Business Source License (BUSL), which is not open-source. This sudden change worried the community, as it introduced legal risks for businesses and developers using Terraform, threatening the ecosystem of tools and contributions built around it.

The Problem: The BUSL license is vague, making it unclear whether using Terraform could be seen as competing with HashiCorp’s products. This uncertainty could discourage developers and companies from using or contributing to Terraform, causing the community and ecosystem to shrink. It also raises concerns about future license changes and sets a worrying precedent for other open-source projects like Linux or Kubernetes.

The Goal: The manifesto aims to keep Terraform truly open-source under a trusted license (like MPL or Apache License 2.0) to ensure it remains reliable and free from sudden changes, protecting the community and businesses that depend on it.

Why OpenTofu Was Created: When HashiCorp didn’t respond to requests to revert to an open-source license, the community forked Terraform (created a separate version) and named it OpenTofu. This fork, maintained under the Linux Foundation, ensures the tool stays open-source and community-driven, similar to how Linux is managed.

OpenTofu’s Promises:

  • Truly Open-Source: Uses a trusted, stable license that won’t change unexpectedly.
  • Community-Driven: Governed by the community, with contributions accepted based on their value.
  • Impartial: Features and fixes are prioritized for the community’s benefit, not any single company.
  • Modular and Layered: Designed to support new tools and integrations, encouraging a thriving ecosystem.
  • Backward-Compatible: Works with existing Terraform code, ensuring long-term usability.

How to install opentofu

  1. To install opentofu you can run this command
SHBash
# Download the installer script:
curl --proto '=https' --tlsv1.2 -fsSL https://get.opentofu.org/install-opentofu.sh -o install-opentofu.sh
# Alternatively: wget --secure-protocol=TLSv1_2 --https-only https://get.opentofu.org/install-opentofu.sh -O install-opentofu.sh
 
# Grant execution permissions:
chmod +x install-opentofu.sh
 
# Please inspect the downloaded script at this point.
 
# Run the installer:
./install-opentofu.sh --install-method standalone
 
# Remove the installer:
rm -f install-opentofu.sh

NOTE: It will be better if you copy this command from official link.

StandAlone Installation

2. If you want to install step by step then you can use this command.

For debian/unix os

SHBash
sudo apt-get update
sudo apt-get install -y apt-transport-https ca-certificates curl gnupg
SHBash
sudo install -m 0755 -d /etc/apt/keyrings
curl -fsSL https://get.opentofu.org/opentofu.gpg | sudo tee /etc/apt/keyrings/opentofu.gpg >/dev/null
curl -fsSL https://packages.opentofu.org/opentofu/tofu/gpgkey | sudo gpg --no-tty --batch --dearmor -o /etc/apt/keyrings/opentofu-repo.gpg >/dev/null
sudo chmod a+r /etc/apt/keyrings/opentofu.gpg /etc/apt/keyrings/opentofu-repo.gpg
SHBash
echo \
  "deb [signed-by=/etc/apt/keyrings/opentofu.gpg,/etc/apt/keyrings/opentofu-repo.gpg] https://packages.opentofu.org/opentofu/tofu/any/ any main
deb-src [signed-by=/etc/apt/keyrings/opentofu.gpg,/etc/apt/keyrings/opentofu-repo.gpg] https://packages.opentofu.org/opentofu/tofu/any/ any main" | \
  sudo tee /etc/apt/sources.list.d/opentofu.list > /dev/null
sudo chmod a+r /etc/apt/sources.list.d/opentofu.list
SHBash
sudo apt-get update
sudo apt-get install -y tofu

Now you can verify the installation using the tofu –version command.

OpenTofu screenshot 1

All of things are same to terraform to read more about terraform you can refer to this link.

Terraform

To migrate

If you want to migrate from terraform to opentofu you can refer to this link.

migration Guide

Migration process overview

The migration process is designed to be safe and reversible:

  1. Back up your infrastructure state and code
  2. Install OpenTofu
  3. Initialize and verify your configuration
  4. Test with a small change

→ Read the complete migration guide

OpenTofu screenshot 2

  • Aws cloudformation: For aws native cloud
  • Terraform

    Overview If we need manage infrastructure code can be use in wide range like in aws, azure or in GCP. If we want to use specially in AWS. For azure Terraform is not fully open source for now…

  • Ansible playbook II

    First Read ansible playbook1 before starting this section. Ansible “file” and “template” module File ownership create directory create file permission syslinks Template To understand this let’s…

  • Ansible Playbook I

    In this blog we will explore different playbooks example in ansible. Earlier we have used Ad-hoc command to configure another machine using ansible host. But in that approach we don’t have any data…