Why we run OpenTofu and not Terraform
Terraform 1.6, released in August 2023, changed licence from the MPL to the Business Source Licence. The BUSL is not an open-source licence and does not pretend to be: it grants you broad use of the software with one carve-out, written into an Additional Use Grant, and HashiCorp’s carve-out excludes offering the software on a hosted or embedded basis competitively.
That sentence is the whole reason this platform executes tofu rather than terraform. It is worth being precise about what it restricts, because the common readings are both wrong in opposite directions.
What the grant restricts, and what it does not
It restricts what we may do with their software. It says nothing about the configuration language, nothing about the file format, and nothing about the API. A remote-execution platform has two entirely separate relationships with the word “Terraform”: it is a client of an API, and it is an executor of a binary. Only the second one is constrained.
So we implement the Terraform Cloud API — the same JSON:API that go-tfe and the CLI already speak — and we execute your configuration with OpenTofu, which is MPL-2.0 and carries no such grant. Your existing tooling does not know the difference, because at the API boundary there is not one — with one deliberate exception: terraform login is not supported. The engine’s browser sign-in is turned off at our edge, so you set TF_TOKEN_tf_runners_io from a token in your dashboard instead.
Where there is a real difference: the lock file
The honest gap is not the language, it is .terraform.lock.hcl. tofu init rewrites registry.terraform.io entries to registry.opentofu.org and drops the hashes, because OpenTofu rebuilds providers from source rather than redistributing HashiCorp’s signed builds. A rewritten lock file committed back to your repository would be a real and unwelcome change to your supply chain.
Two things follow from that, and both are deliberate. We never write the lock file back to your repository — the run happens on an ephemeral copy of the uploaded configuration, which is discarded. And we serve HashiCorp’s own provider builds from our mirror, so the artefact that runs is the one you pinned, not a rebuild of it.
The language gap is smaller than the argument about it
Terraform and OpenTofu are converging, not diverging. Terraform 1.15’s own release headline was closing gaps to OpenTofu. What genuinely has no tofu equivalent yet is a short list: action blocks and terraform query from 1.14, and convert() from 1.15. The gap runs one to two release cycles and it closes in both directions.
Sentinel is the one that does not close. It is HashiCorp proprietary and will never run here; the plan is OPA and Rego instead. If Sentinel policies are load-bearing for your organisation, this is the wrong platform, and it is better to know that from a blog post than from a migration.
If you need the Terraform binary itself
Then run it yourself, on machines you own, under your own grant — which is squarely inside the grant, because you are not offering the software to anyone. A self-hosted agent does not change the binary: it moves a run’s execution onto machines you own, and executes it with OpenTofu, as a hosted run does.
The full comparison, including the parts we have not built, is on the HCP Terraform comparison page.