Skip to content

Rank #2 of 4 in Infrastructure as Code

OpenTofu logo

OpenTofu

Open Source

OpenTofu (Linux Foundation)

30.2k9.8k/yr +125

Access

Install

brewbrew install opentofu

Compare head-to-head

Alternatives to OpenTofu

Showcase

OpenTofu homepage screenshot
homepage · captured Sep 2026 · view live ↗
OpenTofu docs screenshot
docs · captured Sep 2026 · view live ↗

Try itExperimental

See what an agent can do with OpenTofu before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).

$tofu versionrecorded session — replayed, not live
recorded 2026-09-04 · exit 0 · captured verbatim by our probe harness, secrets redacted

Verified integrations

Connections to other tracked products — hover a chip for the verbatim evidence quote behind it.

By theme — the product's score on each story themeBy theme

Agenticness — how well agents can access and operate the productAgenticnessevidence →

How well agents can access and operate the product

24.0/100

Automation depth — how much of the product can run unattendedAutomation depthevidence →

How much of the product can run unattended

17.0/100

Import migration — stories about import migration in this arenaImport migrationevidence →

Stories about import migration in this arena

49.6/100

Licensing governance — stories about licensing governance in this arenaLicensing governanceevidence →

Stories about licensing governance in this arena

54.0/100

Openness — open source, data portability, and self-hosting storiesOpennessevidence →

Open source, data portability, and self-hosting stories

63.5/100

Plan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan applyevidence →

The plan/apply loop — previewing infrastructure changes and applying them safely

77.1/100

Policy as code — stories about policy as code in this arenaPolicy as codeevidence →

Stories about policy as code in this arena

9.6/100

Privacy posture — data-handling and privacy storiesPrivacy postureevidence →

Data-handling and privacy stories

0.0/100

Providers modules — stories about providers modules in this arenaProviders modulesevidence →

Stories about providers modules in this arena

47.3/100

Secrets config — stories about secrets config in this arenaSecrets configevidence →

Stories about secrets config in this arena

30.0/100

State management — stories about state management in this arenaState managementevidence →

Stories about state management in this arena

45.6/100

Testing validation — stories about testing validation in this arenaTesting validationevidence →

Stories about testing validation in this arena

24.0/100

Story verdicts — every judged story with its evidenceStory verdicts

?

Sorted by importance (agentic first) (high → low) · 54/54 stories · click a row’s chevron for the rationale and evidence

Drive the product through a documented public API G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3partial5/10T

Connect an agent via an official MCP server G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3n/auntestednone yet

Delegate tasks to a built-in AI assistant inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness3n/auntestednone yet

Plug MCP servers into this product so it can use their tools G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3n/auntestednone yet

Run the product headlessly / in CI for automation G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full9/10T

Use an official CLI G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full9/10T

Set up automations that run autonomously in the background G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial4/10T

Build against official SDKs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Download a machine-readable API spec (OpenAPI or equivalent) G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Explore an interactive API reference with runnable examples G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Operate the product with natural-language commands G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Point an agent at llms.txt or agent-oriented docs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Rely on versioned APIs with a documented deprecation policy G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Get AI-generated insights and suggestions from my data inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2n/auntestednone yet

Issue scoped/least-privilege API credentials for an agent G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2n/auntestednone yet

Subscribe to events via webhooks G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2n/auntestednone yet

Test against a sandbox environment without touching production data G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness1partial5/10T

Get machine-readable plan output (JSON) that an agent can parse to reason about a proposed change C

Agent plan parsing

ai-native userPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply3full9/10T

Manage resources across all major clouds and SaaS providers through a broad provider ecosystem C

Providers

developerProviders modules — stories about providers modules in this arenaProviders modules3full9/10X

Preview exactly what will change — creates, updates, and destroys — before applying C

Plan workflow

platform-engineerPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply3full9/10T

Run plan and apply non-interactively in CI using saved plan artifacts and approval flags C

Plan workflow

devops-leadPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply3full9/10T

Detect drift between my declared configuration and the actual cloud resources C

Drift

platform-engineerState management — stories about state management in this arenaState management3full8/10T

Have an agent author an infrastructure change, run a plan headlessly, and present the diff for my approval C

Ai infra ops

ai-native userPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply3full8/10T

Self-host the core product G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3full8/10T

Rely on an open license and open governance so the tool cannot be relicensed out from under my company G

Licensing

devops-leadLicensing governance — stories about licensing governance in this arenaLicensing governance3full7/10X

Consume and publish reusable modules or components from a public registry C

Modules

developerProviders modules — stories about providers modules in this arenaProviders modules3partial6/10C

Export all of my data in open formats and leave G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3partial6/10T

Import existing cloud resources under management and generate matching configuration code G

Import

platform-engineerImport migration — stories about import migration in this arenaImport migration3partial6/10X

Pass secrets and sensitive configuration into deployments without exposing them in code or logs C

Secrets

developerSecrets config — stories about secrets config in this arenaSecrets config3partial5/10X

Enforce policy-as-code checks that block non-compliant infrastructure changes before apply C

Policy

devops-leadPolicy as code — stories about policy as code in this arenaPolicy as code3none0/10

Store state in a remote backend with locking so concurrent runs cannot corrupt it C

State backends

platform-engineerState management — stories about state management in this arenaState management3none0/10

Define rules that trigger actions automatically on events G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth3noneuntestednone yet

Prevent my data from being used to train AI models G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture3n/auntestednone yet

Encrypt state at rest so credentials and sensitive values are not readable in plaintext state files C

State backends

devops-leadState management — stories about state management in this arenaState management2full9/10X

Tear down an entire environment cleanly with a destroy operation C

Plan workflow

developerPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply2full9/10T

Read the product's source under an open license G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2full8/10X

Migrate an existing Terraform-format codebase and its state into this tool C

Migration

platform-engineerImport migration — stories about import migration in this arenaImport migration2full7/10T

Perform bulk operations across many items at once G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2partial6/10C

Write automated tests for my infrastructure code and run them without touching production C

Testing

developerTesting validation — stories about testing validation in this arenaTesting validation2partial6/10C

Manage per-environment configuration (dev, staging, prod) as separate stacks or workspaces C

Config stacks

developerSecrets config — stories about secrets config in this arenaSecrets config2partial5/10C

Rely on documented compatibility promises and upgrade guides between releases C

Stability

developerLicensing governance — stories about licensing governance in this arenaLicensing governance2partial5/10X

Let an agent plan and apply with least-privilege credentials and review gates so it cannot make unapproved changes C

Ai infra ops

ai-native userPolicy as code — stories about policy as code in this arenaPolicy as code2partial4/10T

Safely inspect and modify state — moving, removing, or renaming resources — when refactoring C

State backends

platform-engineerState management — stories about state management in this arenaState management2partial3/10C

Do everything through the API that I can do in the UI G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2n/a0/10

Drive deployments programmatically from my own application code rather than only through the CLI G

Automation api

developerPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply2none0/10

Choose where my data is stored (region/residency) G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

Control data retention and deletion G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2n/auntestednone yet

Define infrastructure in a general-purpose programming language with types, loops, and IDE support C

Languages

developerProviders modules — stories about providers modules in this arenaProviders modules2noneuntestednone yet

Generate infrastructure code from natural language using AI assistance built into the toolchain C

Ai authoring

ai-native userProviders modules — stories about providers modules in this arenaProviders modules2n/auntestednone yet

Opt out of telemetry and usage tracking G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

Schedule recurring jobs or workflows G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2n/auntestednone yet

Target or exclude specific resources in a plan or apply C

Plan workflow

platform-engineerPlan apply — the plan/apply loop — previewing infrastructure changes and applying them safelyPlan apply1full8/10T

Version, review, and roll back my automations G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth1partial5/10T

Validate and auto-format my configuration before planning C

Testing

developerTesting validation — stories about testing validation in this arenaTesting validation1noneuntestednone yet

Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 28 stories with headroom

What would move OpenTofu’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.

  1. Automation depth — how much of the product can run unattendedDefine rules that trigger actions automatically on events

    nonemoves PA Scoreimpact 30

    OpenTofu's evidence pack covers CLI plan/apply/test/import workflows but shows no rule-based or event-triggered automation engine (e.g., webhooks, event listeners, policy-triggered actions) built into the tool itself.

  2. Policy as code — stories about policy as code in this arenaEnforce policy-as-code checks that block non-compliant infrastructure changes before apply

    nonemoves PA Scoreimpact 30

    Missing: any policy-as-code engine or gating mechanism, documentation of policy enforcement in CI/CD, and evidence that non-compliant plans are actually blocked before apply.

  3. State management — stories about state management in this arenaStore state in a remote backend with locking so concurrent runs cannot corrupt it

    nonemoves PA Scoreimpact 30

    Missing: any documentation or probe evidence of remote backend configuration (e.g., S3/consul/etc.), locking mechanism, or verification that concurrent runs are prevented from corrupting state.

  4. Agenticness — how well agents can access and operate the productPoint an agent at llms.txt or agent-oriented docs

    nonemoves agent-readyimpact 30

    A direct probe of https://opentofu.org/llms.txt returned HTTP 404, and no other evidence pack items reference an llms.txt file or agent-oriented documentation format; the docs are standard human-facing pages only.

  5. Agenticness — how well agents can access and operate the productOperate the product with natural-language commands

    nonemoves Built-in AIimpact 30

    OpenTofu's interface is HCL configuration plus a fixed CLI command set (plan, apply, test, import, etc.); nothing in the evidence pack shows any natural-language command interface, NL parsing, or AI-native control surface — llms.txt and other AI-discovery probes even returned 404s.

  6. Agenticness — how well agents can access and operate the productBuild against official SDKs

    nonemoves agent-readyimpact 30

    Missing: any documented official SDK, API/OpenAPI spec, or programmatic library for AI agents to integrate with OpenTofu beyond the CLI.

  7. Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples

    nonemoves API qualityimpact 30

    OpenTofu's docs are static CLI command references (plan/apply/test/import) with no interactive API explorer or runnable-example sandbox; explicit probes confirm no OpenAPI/swagger spec and no llms.txt discoverability aid.

  8. Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent)

    nonemoves API qualityimpact 30

    Explicit probes confirm no OpenAPI/Swagger spec or llms.txt is available (404s at all candidate paths), and no evidence of any machine-readable API spec being offered.

Showing the top 8 of 28 — every none/partial verdict in the story verdicts table is headroom.

Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.

Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map7 surfaces · 29 covered stories

Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.

docs22 stories

Probe proofs — replayable recordings from the probe harnessProbe proofs

Replayable recordings from our probe harness — see the Prove-It protocol to submit one.

$tofu versionreproduced
$ tofu version
OpenTofu v1.12.6
on darwin_arm64
proves: Use an official CLIrecorded 2026-09-04
$tofu plan -helpreproduced
$ tofu plan -help
Usage: tofu [global options] plan [options]

  Generates a speculative execution plan, showing what actions OpenTofu would
  take to apply the current configuration. This command will not actually
  perform the planned actions.

  You can optionally save the plan to a file, which you can then pass to the
  "apply" command to perform exactly the actions described in the plan.

Plan Customization Options:

  The following options customize how OpenTofu will produce its plan. You can
  also use these options when you run "tofu apply" without passing it a saved
  plan, in order to plan and apply in a single command.

  -destroy                Select the "destroy" planning mode, which creates a
                          plan to destroy all objects currently managed by this
                          OpenTofu configuration instead of the usual behavior.

  -refresh-only           Select the "refresh only" planning mode, which checks
                          whether remote objects still match the outcome of the
                          most recent OpenTofu apply but does not propose any
                          actions to undo any changes made outside of OpenTofu.

  -refresh=false          Skip checking for external changes to remote objects
                          while creating the plan. This can potentially make
                          planning faster, but at the expense of possibly
                          planning against a stale record of the remote system
                          state.

  -replace=resource       Force replacement of a particular resource instance
                          using its resource address. If the plan would've
                          otherwise produced an update or no-op action for this
                          instance, OpenTofu will plan to replace it instead.
                          You can use this option multiple times to replace
                          more than one object.

  -target=resource        Limit the planning operation to only the given
                          module, resource, or resource instance and all of its
                          dependencies. You can use this option multiple times
                          to include more than one object. This is for
                          exceptional use only. Cannot be used alongside the
                          -exclude option.

  -target-file=filename   Similar to -target, but specifies zero or more
                          resource addresses from a file.

  -exclude=resource       Limit the planning operation to not operate on the
                          given module, resource, or resource instance and all
                          of the resources and modules that depend on it. You
                          can use this option multiple times to exclude more
                          than one object. This is for exceptional use only.
                          Cannot be used together with the -target option.

  -exclude-file=filename  Similar to -exclude, but specifies zero or more
                          resource addresses from a file.

  -var 'foo=bar'          Set a value for one of the input variables in the
                          root module of the configuration. Use this option
                          more than once to set more than one variable.

  -var-file=filename      Load variable values from the given file, in addition
                          to the default files terraform.tfvars and
                          *.auto.tfvars. Use this option more than once to
                          include more than one variables file.

Other Options:

  -compact-warnings            If OpenTofu produces any warnings that are not
                               accompanied by errors, shows them in a more
                               compact form that includes only the summary
                               messages.

  -consolidate-warnings=false  If OpenTofu produces any warnings, do not
                               attempt to consolidate similar messages. All
                               locations for all warnings will be listed.

  -consolidate-errors          If OpenTofu produces any errors, attempt to
                               consolidate similar messages into a single item.

  -detailed-exitcode           Return detailed exit codes when the command
                               exits. The detailed exit codes are:
                                 0 - Succeeded but no changes proposed
                                 1 - Planning failed with an error
                                 2 - Succeeded and changes are proposed

  -generate-config-out=path    (Experimental) If import blocks are present in
                               configuration, instructs OpenTofu to generate
                               HCL for any imported resources not already
                               present. The configuration is written to a new
                               file at PATH, which must not already exist.
                               OpenTofu may still attempt to write
                               configuration if planning fails with an error.

  -input=false                 Disable prompting for required input variables
                               that are not set some other way.

  -lock=false                  Don't hold a state lock during the operation.
                               This is dangerous if others might concurrently
                               run commands against the same workspace.

  -lock-timeout=duration       Duration to retry a state lock, such as "5s"
                               to represent five seconds.

  -no-color                    Disable virtual terminal escape sequences.

  -concise                     Disable progress-related messages.

  -out=path                    Write a plan file to the given path. This can be
                               used as input to the "apply" command.

  -parallelism=n               Limit the number of concurrent operations.
                               Defaults to 10.

  -state=statefile             A legacy option used for the local backend only.
                               Refer to the local backend's documentation for
                               more information.

  -show-sensitive              If specified, sensitive values will not be
                               redacted in te UI output.

  -json                        Produce output in a machine-readable JSON
                               format, suitable for use in text editor
                               integrations and other automated systems.

  -json-into=out.json          Produce the same output as -json, but sent directly
                               to the given file. This allows automation to preserve
                               the original human-readable output streams, while
                               capturing more detailed logs for machine analysis.

  -deprecation=module:m        Specify what type of warnings are shown.
                               Accepted values for "m": all, local, none.
                               Default: all. When "all" is selected, OpenTofu
                               will show the deprecation warnings for all
                               modules. When "local" is selected, the warns
                               will be shown only for the modules that are
                               imported with a relative path. When "none" is
                               selected, all the deprecation warnings will be
                               dropped.

Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence

11 of 14 testable claims verified · 0 contradictedintegrity 79/100

18 distinct capability claims found in OpenTofu’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.

11

Verified

3

Unverified

0

Contradicted

15

Undersold

Verified (13)
Unverified (3)
Undersold (15)
Claims outside our story set (2)

Real capability claims found in OpenTofu’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.

  • Speculative plans let developers verify change effects before submitting for code review

    source ↗
  • Builds a dependency graph and parallelizes creation/modification of non-dependent resources

    source ↗
Suggest a story for these →

Business model

open-source

MPL-2.0 open-source fork of Terraform under the Linux Foundation; no paid product — development is funded by supporting companies pledging engineering time.

pricing ↗

Score trend

How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.

PA Score25 (Sep 4 '26)30 (Sep 4 '26)
Agent-ready21 (Sep 4 '26)41 (Sep 4 '26)

Try Experimental

Run it in the microterminal →

Recorded agent sessions — and a live MCP handshake where the vendor ships one.

Flag

⚑ Flag a verdict

Think a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.

Badge

Embed this product's score badge →

Hotlinked SVG — always shows the live current score.

For agents

Data