The HashiCorp Licence Change: A Historic Turning Point
In August 2023, HashiCorp announced the transition of Terraform (and several other products) from the MPL 2.0 (Mozilla Public License) to the BSL 1.1 (Business Source License). This new licence forbids the commercial use of Terraform for products that compete with HashiCorp — in particular, managed Terraform offerings from third parties such as Spacelift, Env0, and Scalr.
The community reaction was immediate and massive. Within weeks, several major companies and open-source players created the OpenTofu Initiative, quickly joined by Gruntwork, Spacelift, Env0, Scalr, Harness, and others. The project was placed under the governance of the Linux Foundation and submitted as a sandbox project to the CNCF.
The Birth of OpenTofu
OpenTofu is a fork of Terraform 1.5.x, created from the last commit under the MPL 2.0 licence. The project maintains full compatibility with Terraform 1.x while adding independent new features. In 2024, OpenTofu reached feature parity with Terraform 1.8 and began innovating independently.
- Licence: MPL 2.0 — truly open-source, forever
- Governance: Linux Foundation Technical Advisory Council, contributor voting
- Registry: OpenTofu maintains its own provider and module registry, compatible with the Terraform registry
- CLI:
tofucommand replacingterraform
Feature Parity with Terraform 1.8+
OpenTofu supports all Terraform features up to version 1.8:
- Backends: S3, GCS, Azure Blob, Consul, HTTP
- Workspaces, modules, remote state
- Import of existing resources (
importblock) - Test framework (
tofu test) - Check blocks for post-apply assertions
- Moved blocks for refactoring
OpenTofu-Exclusive Features
OpenTofu innovates beyond Terraform with features that do not exist in the HashiCorp version:
Provider-Defined Functions
Providers can now expose functions callable from HCL code, without needing data resources. For example, an AWS provider can expose a function to dynamically calculate ARNs:
output "bucket_arn" {
value = provider::aws::arn(
partition = "aws",
service = "s3",
region = "",
account = "",
resource = var.bucket_name
)
}
Early Variable Evaluation
OpenTofu allows the use of variables in backend and provider blocks, which was impossible with Terraform. This greatly simplifies dynamic backend configuration:
variable "environment" {
type = string
}
terraform {
backend "s3" {
bucket = "tfstate-${var.environment}" # Now possible with OpenTofu
key = "terraform.tfstate"
region = "eu-west-1"
}
}
State Encryption
OpenTofu supports native client-side encryption of state files, with support for AWS KMS, GCP KMS, Azure Key Vault, or a local passphrase. Encrypted state files are unreadable without the key, even with direct access to the S3 bucket.
Migration Guide from Terraform
Migrating from Terraform to OpenTofu is designed to be non-destructive and reversible. State files are 100 % compatible.
Step 1: Install OpenTofu
# macOS via Homebrew
brew install opentofu
# Linux
curl --proto '=https' --tlsv1.2 -fsSL https://get.opentofu.org/install-opentofu.sh | sh
# Verify the installation
tofu version
Step 2: Rename terraform blocks
The only mandatory syntactic change is renaming terraform {} blocks — in practice, OpenTofu accepts both. The required_providers block works identically.
# Before (Terraform)
terraform {
required_version = ">= 1.5"
required_providers {
aws = {
source = "hashicorp/aws"
version = "~> 5.0"
}
}
}
# After (OpenTofu) — identical, no change required
Step 3: Update CI/CD Pipelines
# GitHub Actions — before
- name: Terraform Apply
run: terraform apply -auto-approve
# After
- name: OpenTofu Apply
run: tofu apply -auto-approve
# Alternative: use the official OpenTofu action
- uses: opentofu/setup-opentofu@v1
with:
tofu_version: "1.8.0"
Provider and State Compatibility
Providers from the Terraform registry (registry.terraform.io) are directly compatible with OpenTofu via the opentofu.org registry. JSON state files are identical. You can alternate between terraform and tofu on the same state without any conversion.
When to Migrate Now vs Wait
Migrate now if you use Terraform in a commercial product that competes with HashiCorp (legal requirement), if you want the exclusive features (state encryption, provider functions), or if your organisation has a strict open-source policy.
You can wait if you are under a Terraform Cloud/Enterprise contract (respect the contract terms), if your use is internal and non-commercial, or if your organisation has not yet decided on its IaC strategy.
Conclusion
OpenTofu is today a mature, feature-complete alternative to Terraform. Migration is trivial for the vast majority of projects. The choice between OpenTofu and Terraform comes down to governance and trust: do you want to depend on a company whose monetisation strategy can change, or on a project under the neutral governance of the Linux Foundation?
