Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Opentofu

ASecurity

Covers OpenTofu, the open-source Terraform fork: HCL, providers, state management, modules, migration from Terraform, feature parity, divergences, and community ecosystem. WHEN: \"OpenTofu\", \"tofu plan\", \"tofu apply\", \"Terraform fork\", \"OpenTofu migration\", \"tofu state\", \"MPL license Terraform\". Do NOT use for Terraform-proper questions with no OpenTofu angle — use the `terraform` skill.

4 stars
0 votes
0 copies
0 views
Added 9/24/2026
devopsgobashawsgcpazureterraformbackendci/cd

Works with

cli

Security Analysis

A100/100

Pro scans all 4 files and shows the line behind each finding

Scanned 9/24/2026

$npx -y skills add chrishuffman5/domain-expert --skill opentofu --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Opentofu?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Opentofu
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-opentofu/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-opentofu)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: opentofu
description: "Covers OpenTofu, the open-source Terraform fork: HCL, providers, state management, modules, migration from Terraform, feature parity, divergences, and community ecosystem. WHEN: \"OpenTofu\", \"tofu plan\", \"tofu apply\", \"Terraform fork\", \"OpenTofu migration\", \"tofu state\", \"MPL license Terraform\". Do NOT use for Terraform-proper questions with no OpenTofu angle — use the `terraform` skill."
license: MIT
---

# OpenTofu Technology Expert

This skill covers OpenTofu, the open-source fork of Terraform maintained by the Linux Foundation. OpenTofu was created in response to HashiCorp's license change from MPL 2.0 to BSL 1.1 in August 2023. Current version is 1.x.

OpenTofu maintains broad compatibility with Terraform but diverges on newer features. For foundational IaC concepts (state, drift, idempotency), refer to the parent IaC agent.

## How to Approach Tasks

1. **Classify** the request:
   - **Troubleshooting** -- Load `references/diagnostics.md`
   - **Architecture / internals** -- Load `references/architecture.md`
   - **Best practices** -- Load `references/best-practices.md`
   - **Migration from Terraform** -- Cover compatibility, state migration, provider reuse

2. **Identify context** -- Is the user migrating from Terraform, starting fresh, or maintaining an existing OpenTofu setup?

3. **Note divergences** -- OpenTofu and Terraform share a common heritage but diverge on features after the fork point. Always clarify which features are OpenTofu-specific vs shared.

## Core Architecture

OpenTofu shares the same fundamental architecture as Terraform:

- **HCL configuration** -- Same HCL syntax, same `.tf` file format
- **Provider plugin protocol** -- Uses the same gRPC provider protocol (versions 5 and 6). Most Terraform providers work with OpenTofu.
- **State file** -- Same format (version 4). State files are interchangeable between Terraform and OpenTofu.
- **Module system** -- Same module structure, same registry protocol
- **CLI workflow** -- `tofu init`, `tofu plan`, `tofu apply` (drop-in replacement for `terraform` commands)

### Key Differences from Terraform

| Feature | OpenTofu | Terraform |
|---|---|---|
| **License** | MPL 2.0 (open source) | BSL 1.1 (source-available) |
| **Governance** | Linux Foundation, community-driven | HashiCorp (Broadcom) |
| **Registry** | OpenTofu Registry (mirrors + community) | Terraform Registry |
| **State encryption** | Native state encryption (client-side) | No native encryption (rely on backend) |
| **Early variable/locals evaluation** | Supported | Not supported |
| **Provider-defined functions** | Supported (own implementation) | Supported (different implementation) |
| **Removed blocks** | `removed` block for safe resource removal | `removed` block (different syntax) |
| **Stacks** | Not supported | Terraform Cloud/Enterprise only |
| **Cloud integration** | No proprietary cloud service | Terraform Cloud/Enterprise |

### State Encryption

OpenTofu's standout feature — client-side state encryption:

```hcl
terraform {
  encryption {
    key_provider "pbkdf2" "my_passphrase" {
      passphrase = var.state_passphrase
    }

    method "aes_gcm" "my_method" {
      keys = key_provider.pbkdf2.my_passphrase
    }

    state {
      method = method.aes_gcm.my_method
    }

    plan {
      method = method.aes_gcm.my_method
    }
  }
}
```

Key providers: `pbkdf2`, `aws_kms`, `gcp_kms`, `openbao` (Vault fork).

### Early Variable/Locals Evaluation

OpenTofu allows variables and locals in `backend` and `module.source` blocks:

```hcl
# OpenTofu only — not valid in Terraform
variable "environment" {
  type = string
}

terraform {
  backend "s3" {
    bucket = "mycompany-${var.environment}-state"
    key    = "terraform.tfstate"
    region = "us-east-1"
  }
}
```

## Migration from Terraform

### Compatibility Assessment

1. **CLI**: Replace `terraform` with `tofu` — most commands are identical
2. **State**: State files are compatible. No conversion needed.
3. **Providers**: Most providers work. Check the OpenTofu Registry for availability.
4. **Modules**: Terraform Registry modules work if they don't use BSL-only features.
5. **Backend**: Same backend types supported (S3, GCS, Azure Blob, Consul, pg).

### Migration Steps

```bash
# 1. Install OpenTofu
brew install opentofu    # macOS
# or download from https://opentofu.org/docs/intro/install/

# 2. Verify version
tofu version

# 3. Initialize (downloads providers from OpenTofu Registry)
tofu init

# 4. Validate
tofu validate

# 5. Plan (compare against existing state)
tofu plan

# 6. If plan matches expectations, you're migrated
# State file remains in the same backend — no migration needed
```

### Breaking Points

- **Terraform Cloud/Enterprise features**: Remote execution, Sentinel policies, private registry — no OpenTofu equivalent
- **BSL-only features**: Features added to Terraform after 1.5.x may not be in OpenTofu (or may be implemented differently)
- **Provider mirroring**: Some providers may lag in the OpenTofu Registry. Use `provider_installation` block to configure mirrors.

```hcl
# Use Terraform Registry as fallback
provider_installation {
  direct {
    exclude = []
  }
}
```

## CLI Reference

```bash
# Core workflow (identical to Terraform)
tofu init              # Initialize, download providers
tofu plan              # Preview changes
tofu apply             # Apply changes
tofu destroy           # Destroy all resources

# State management
tofu state list
tofu state show <resource>
tofu state mv <source> <dest>
tofu state rm <resource>
tofu import <resource> <id>

# Validation and formatting
tofu validate
tofu fmt -check -recursive
tofu test              # Run tests

# State encryption
tofu init -migrate-state    # Enable encryption on existing state
```

## Reference Files

- `references/architecture.md` — OpenTofu internals, registry architecture, provider compatibility layer, state encryption deep dive, fork divergence tracking
- `references/best-practices.md` — Migration strategies, provider pinning, state encryption configuration, CI/CD integration, community module usage
- `references/diagnostics.md` — Provider compatibility issues, state migration errors, encryption key management, registry resolution failures

Attribution

chrishuffman5chrishuffman5
View sourceSee grades on GitHubMore from chrishuffman5 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Terraform Module Library

Build reusable Terraform modules for AWS, Azure, and GCP infrastructure following infrastructure-as-code best practices. Use when creating infrastructure modules, standardizing cloud provisioning, or implementing reusable IaC components.

401991 votes

sematext-otel

Wire a service's OpenTelemetry output to Sematext Cloud. Walks through region, App-type, instrumentation flow (managed OTLP endpoint vs Sematext Agent), and signal selection (traces/metrics/logs), then produces the exact env-var block and points at a runnable reference example in this repo. Invoke when instrumenting a new app for Sematext.

01 votes

Deployment Patterns

Deployment workflows, CI/CD pipeline patterns, Docker containerization, health checks, rollback strategies, and production readiness checklists for web applications. Use when setting up deployment infrastructure or planning releases.

2699140 votes

Babysit

Watch a pull request or review cycle until it is ready to merge. Use when asked to babysit, monitor, or keep checking PR comments, reviews, and CI until all actionable issues are resolved.

971540 votes

V7 Roster

Interact with the Paperclip control plane API for task coordination and governance. Use when checking assignments, updating issue status, posting comments, delegating work, managing routines, or calling Paperclip API endpoints.

953190 votes
View all in devops →