opentofu

    opentofu/opentofu

    #59 this week

    OpenTofu lets you declaratively manage your cloud infrastructure.

    backend
    Go
    MPL-2.0
    30.1K stars
    1.3K forks
    30.1K GitHub watchers
    Updated 9/5/2026
    View on GitHub

    Build with Backblaze B2

    SDKs, agent skills, IDE extensions, and reference pipelines from Backblaze Labs. All open source.

    Explore Backblaze Labs

    Loading star history...

    Use Cases & Benefits

    • OpenTofu is an open-source tool for declaratively managing cloud infrastructure using Infrastructure as Code principles.
    • Key features include execution plans, resource graph for dependency management, and change automation for safe infrastructure updates.
    • Written in Go, it supports popular service providers and custom solutions, licensed under MPL-2.0 with a strong community and 26k+ stars.
    • Organizations can use OpenTofu to version, plan, and automate infrastructure changes, reducing human error and improving deployment efficiency.
    • Ideal for teams needing scalable, efficient, and safe cloud infrastructure management with clear change visibility and automation capabilities.

    About opentofu

    OpenTofu

    OpenSSF Best Practices

    OpenTofu is an OSS tool for building, changing, and versioning infrastructure safely and efficiently. OpenTofu can manage existing and popular service providers as well as custom in-house solutions.

    The key features of OpenTofu are:

    • Infrastructure as Code: Infrastructure is described using a high-level configuration syntax. This allows a blueprint of your datacenter to be versioned and treated as you would any other code. Additionally, infrastructure can be shared and re-used.

    • Execution Plans: OpenTofu has a "planning" step where it generates an execution plan. The execution plan shows what OpenTofu will do when you call apply. This lets you avoid any surprises when OpenTofu manipulates infrastructure.

    • Resource Graph: OpenTofu builds a graph of all your resources, and parallelizes the creation and modification of any non-dependent resources. Because of this, OpenTofu builds infrastructure as efficiently as possible, and operators get insight into dependencies in their infrastructure.

    • Change Automation: Complex changesets can be applied to your infrastructure with minimal human interaction. With the previously mentioned execution plan and resource graph, you know exactly what OpenTofu will change and in what order, avoiding many possible human errors.

    Getting help and contributing

    [!TIP] For more OpenTofu events, subscribe to the OpenTofu Events Calendar!

    Reporting security vulnerabilities

    If you've found a vulnerability or a potential vulnerability in OpenTofu please follow Security Policy. We'll send a confirmation email to acknowledge your report, and we'll send an additional email when we've identified the issue positively or negatively.

    If you believe you have found any possible copyright or intellectual property issues, please contact [email protected]. We'll send a confirmation email to acknowledge your report.

    Registry Access

    In an effort to comply with applicable sanctions, we block access from specific countries of origin.

    License

    Mozilla Public License v2.0

    Discover Repositories

    Search across tracked repositories by name or description