Previously we evaluated prevent_destroy expressions immediately inside the config loader, thereby forcing it to always be a constant expression producing a bool value. Now the config loader just saves whatever expression it was given and we let the language runtime deal with it instead, which means we can allow references to dynamically-chosen values from elsewhere in the same module. The language runtime's "validate" phase still performs a type check for bool that's equivalent to what we used to do during config loading to make sure that the "tofu validate" command can catch a similar subset of problems as it used to be able to catch, but we have more information available during the plan phase that allows us to produce more complete and relevant error messages, so for any expression that we can't evaluate with a nil evaluation context we'll now let the plan phase deal with the checks instead. The policy for handling annoying cases such as unknown values, ephemeral values, sensitive values, and references to local symbols like count.index is intentionally the most conservative choice to start, because future versions of OpenTofu can allow more once we've got more experience but cannot permit less if we find that we've made a mistake. Future changes could potentially make these rules a little more liberal, once we have learned from feedback on this initial functionality. Signed-off-by: Martin Atkins <mart@degeneration.co.uk>
OpenTofu
OpenTofu is an OSS tool for building, changing, and versioning infrastructure safely and efficiently. OpenTofu can manage existing and popular service providers as well as custom in-house solutions.
The key features of OpenTofu are:
-
Infrastructure as Code: Infrastructure is described using a high-level configuration syntax. This allows a blueprint of your datacenter to be versioned and treated as you would any other code. Additionally, infrastructure can be shared and re-used.
-
Execution Plans: OpenTofu has a "planning" step where it generates an execution plan. The execution plan shows what OpenTofu will do when you call apply. This lets you avoid any surprises when OpenTofu manipulates infrastructure.
-
Resource Graph: OpenTofu builds a graph of all your resources, and parallelizes the creation and modification of any non-dependent resources. Because of this, OpenTofu builds infrastructure as efficiently as possible, and operators get insight into dependencies in their infrastructure.
-
Change Automation: Complex changesets can be applied to your infrastructure with minimal human interaction. With the previously mentioned execution plan and resource graph, you know exactly what OpenTofu will change and in what order, avoiding many possible human errors.
Getting help and contributing
- Have a question?
- Post it in GitHub Discussions
- Open a GitHub issue
- Join the OpenTofu Slack!
- Want to contribute?
- Please read the Contribution Guide.
- Recurring Events
- Community Meetings on Wednesdays at 12:30 UTC at this link: https://meet.google.com/xfm-cgms-has (📅 calendar link)
- Technical Steering Committee Meetings every other Tuesday at 4pm UTC at this link: https://meet.google.com/cry-houa-qbk (📅 calendar link)
Tip
For more OpenTofu events, subscribe to the OpenTofu Events Calendar!
Reporting security vulnerabilities
If you've found a vulnerability or a potential vulnerability in OpenTofu please follow Security Policy. We'll send a confirmation email to acknowledge your report, and we'll send an additional email when we've identified the issue positively or negatively.
Reporting possible copyright issues
If you believe you have found any possible copyright or intellectual property issues, please contact liaison@opentofu.org. We'll send a confirmation email to acknowledge your report.
Registry Access
In an effort to comply with applicable sanctions, we block access from specific countries of origin.