> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/infrastructure-as-code-management/3.0/new-to-iacm/get-started/opentofu-get-started.md).

# OpenTofu

{% @harness-package-selector/package-selector platforms="%5B%7B%22label%22%3A%22AWS%20CDK%22%2C%22slug%22%3A%22aws-cdk%22%2C%22path%22%3A%22infrastructure-as-code-management%2Fnew-to-iacm%2Fget-started%2Faws-cdk-get-started%22%7D%2C%7B%22label%22%3A%22OpenTofu%22%2C%22slug%22%3A%22opentofu%22%2C%22path%22%3A%22infrastructure-as-code-management%2Fnew-to-iacm%2Fget-started%2Fopentofu-get-started%22%7D%2C%7B%22label%22%3A%22Terragrunt%22%2C%22slug%22%3A%22terragrunt%22%2C%22path%22%3A%22infrastructure-as-code-management%2Fnew-to-iacm%2Fget-started%2Fterragrunt-get-started%22%7D%2C%7B%22label%22%3A%22Terraform%22%2C%22slug%22%3A%22terraform%22%2C%22path%22%3A%22infrastructure-as-code-management%2Fnew-to-iacm%2Fget-started%2Fterraform-get-started%22%7D%5D" selectedPlatform="opentofu" %}

OpenTofu is an open-source infrastructure-as-code tool, and Harness Infrastructure as Code Management (IaCM) runs your OpenTofu workspaces and pipelines with Git-backed configuration, connectors, and optional cost estimation.

This guide walks you from connectors and workspace creation through a standard provision pipeline (init, plan, apply) and an optional approval between plan and apply.

#### What will you learn? <a href="#what-will-you-learn" id="what-will-you-learn"></a>

This guide covers the following:

* **Connectors and workspace:** Create cloud and Git connectors, then create an OpenTofu workspace wired to your repository and OpenTofu version.
* **Provision pipeline:** Generate or author a pipeline that runs init, plan, and apply for your workspace.
* **Approvals:** Optionally gate apply behind an approval step.

### Before you begin <a href="#before-you-begin" id="before-you-begin"></a>

Before you use this guide, ensure you have the following:

* **Harness account with IaCM enabled:** You need **Infrastructure as Code Management** under **Infrastructure** in Harness when it is entitled on your account. Go to [Getting started with Harness Platform](/harness-ai/new-to-harness-platform/get-started.md) to access or create a Harness account.

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>CONTACT HARNESS SUPPORT</strong></p><p>If IaCM does not appear, go to <a href="/pages/xz8JJA2qaiAVn2EGF2Mc">Get started with IaCM</a>, or contact your account administrator or <a href="mailto:support@harness.io">Harness Support</a>.</p></div>
* **Pipeline permissions:** View, Create/Edit, and Execute on [Pipelines](/harness-ai/use-harness-platform/platform-access-control/permissions-reference.md#pipelines). Go to [RBAC in Harness](/harness-ai/use-harness-platform/platform-access-control.md) to review the permissions model, and go to [Manage roles](/harness-ai/use-harness-platform/platform-access-control/add-manage-roles.md) to assign a role that includes them.
* **Git repository:** Access to a Git provider with your [OpenTofu](https://opentofu.org/) project.
* **Cloud provider:** Access to a cloud provider such as AWS or Google Cloud Platform for the infrastructure you manage.
* **Harness organization and project:** An [organization and project set up](/harness-ai/new-to-harness-platform/get-started.md) on the Harness Platform.

<details>

<summary>Sample OpenTofu</summary>

The following example OpenTofu (.tf) file declares:

* **Provider Configuration:** Specifies the AWS provider and sets the region to "us-east-1". Go to [AWS Regions & Availability Zones](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Concepts.RegionsAndAvailabilityZones.html) for a complete region list.
* **Resource Definition:** Creates an EC2 instance with the identifier `my_first_ec2_instance`.
* **AMI:** Utilizes ami-123abc321cba18, go to [AWS EC2 User Guide](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/finding-an-ami.html) to find your AMI image ID.
* **Instance Type:** Configures the instance to use a t2.micro. Go to the [AWS t2 instances list](https://aws.amazon.com/ec2/instance-types/t2/).\
  Tags: To facilitate easy identification and management within AWS resources, a tag name with the value `my_first_ec2_instance` is applied.

```hcl
provider "aws" {
  region = "us-east-1"
}

resource "aws_instance" "my_first_ec2_instance" {
  ami = "ami-123abc321cba18"
  instance_type = "t2.micro" # Go to https://aws.amazon.com/ec2/instance-types/t2/ for a full T2 instance type list.

  tags = {
    Name = "my_first_ec2_instance"
  }
}
```

Go to [OpenTofu Documentation](https://opentofu.org/docs/) to review currently supported workspace types.

</details>

***

### Set up your workspace <a href="#set-up-your-workspace" id="set-up-your-workspace"></a>

A workspace is a named environment for storing your OpenTofu configurations and resources. Connect your cloud provider and code repository through **Connectors** to manage infrastructure changes and updates with Harness IaCM pipelines.

{% hint style="info" %}
Harness recommends configuring your connector before creating your workspace, however, you can also add new connectors during the [Create Workspace flow](/infrastructure-as-code-management/3.0/new-to-iacm/get-started.md#add-a-new-workspace).
{% endhint %}

#### Step 1: create a connector <a href="#step-1-create-a-connector" id="step-1-create-a-connector"></a>

Use **Harness AI** to create and configure your cloud provider and code repository connectors before you create a workspace:

{% tabs %}
{% tab title="Create a Connector" %}
{% embed url="<https://app.tango.us/app/embed/73d9628e-7093-4c6b-a9f7-dac8125c8441?skipCover=true&defaultListView=false&skipBranding=false&makeViewOnly=true&hideAuthorAndDetails=true>" %}
Create Cloud Provider Connector with Harness AI
{% endembed %}
{% endtab %}

{% tab title="Step-by-step" %}
When adding any connector, start by:

1. Sign in to [app.harness.io](https://app.harness.io).
2. In the module pane, select **Infrastructure**.
3. Select **Project Setup**, and then select **Connectors**.
4. Select **New Connector (AI)**.
5. Select an option, for example "Create a GitHub connector", or type your request to create a connector for your chosen cloud provider or code repository.

Harness creates a YAML file for your connector. Once you select **Create**, Harness creates your connector and adds it to your project.

{% hint style="info" %}
**EDIT CONNECTOR**

Edit your connector by updating the AI generated YAML file, or by selecting **Edit Details** in the connectors panel.
{% endhint %}

Go to [Connect your Cloud Provider](/harness-ai/use-harness-platform/connectors/cloud-providers.md) and [Connect your Code Repository](/harness-ai/use-harness-platform/connectors/code-repositories/connect-to-code-repo.md) to connect your cloud provider and code repository.
{% endtab %}
{% endtabs %}

{% hint style="info" %}
**OIDC CONNECTORS**

For easier access and token management, use the **OIDC** (OpenID Connect) option in the Credentials panel. This allows your connector to assume roles with permissions set in your Cloud Provider, updated only by authorized users. Go to [the Use OIDC tab](/harness-ai/use-harness-platform/connectors/cloud-providers/ref-cloud-providers/aws-connector-settings-reference.md#credentials) for setup details.
{% endhint %}

***

#### Step 2: create your workspace <a href="#step-2-create-your-workspace" id="step-2-create-your-workspace"></a>

Once you have configured your connectors, you can create a workspace and select them in the **New Workspace** panel:

{% hint style="info" %}
**MIGRATE EXISTING PROJECTS**

For first-time use, go to [State Migration](/infrastructure-as-code-management/3.0/use-iacm/remote-backends/state-migration.md) to import the state of your existing Terraform projects into a Harness workspace.
{% endhint %}

{% tabs %}
{% tab title="Interactive Guide" %}
{% embed url="<https://app.tango.us/app/embed/e6ec4051-90e5-4430-a003-a9bcce4d8981?skipCover=true&defaultListView=false&skipBranding=false&makeViewOnly=true&hideAuthorAndDetails=true>" %}
Create an OpenTofu Workspace in Harness IaCM
{% endembed %}
{% endtab %}

{% tab title="Step-by-step" %}

1. In the module pane, select **Infrastructure**.
2. Select an existing project or create a new project.
3. Select **Workspaces**, and then select **New Workspace**.
4. Select **Create new Workspace**, then select **Start from scratch** and complete the following fields in the new workspace wizard:

**About workspace**

* **Name** - Enter a unique name to identify the workspace.
* **Description (optional)**: Enter an optional description to help identify the workspace.
* **Tags (optional)**: Add a unique tag to identify the workspace.

**Configure repository details**

* Select your Git provider, either **Harness Code Repository** or **Third-party Git provider** for other providers like GitHub or GitLab.
* **Git Connector**: Select the Git connector you created in the previous step.
* **Git Fetch Type**: Select the Git fetch type, either **Latest from branch**, **Git tag** or **Commit SHA**.
* **Git Branch**: Specify the branch you want to use for the workspace.

{% hint style="info" %}
**BRANCH WITH JEXL**

You can configure the workspace branch as a [JEXL expression](/harness-ai/use-harness-platform/variables-and-expressions/harness-variables.md) that references a pipeline variable, and then set the pipeline variable as a runtime input.

<img src="/files/9s0Ke2NG272mYVymn3tQ" alt="" data-size="original">

Set your branch variable as a runtime input in the pipeline:

```yaml
variables:
 - name: iacm_branch
   type: String
   description: ""
   required: true
   value: <+input>.default(main)
```

{% endhint %}

* **Folder Path**: Specify the folder path to the OpenTofu configuration files in the repository.

**Advanced** options allow you to **include submodules** if your code repository includes modules and submodules. Go to [Module Registry](/infrastructure-as-code-management/3.0/registry/module-registry.md) to review module registry concepts.

**Provisioner**

* **Connector**: Select the cloud provider connector you created in the previous step.
* **Cloud Cost Estimation**: Toggle the **Enable Cost Estimation** switch to enable cloud cost estimation. This lets you estimate the cost of your infrastructure changes before you apply them.
* **Workspace Type**: Select **OpenTofu** as the workspace type you want to use for the workspace.
* **OpenTofu Version**: Select the OpenTofu version you want to use for the workspace

**Add variable set (optional)**

If you have configured variable sets for reuse, select the variable set you want to use for the workspace.

5. Select **Create**.
   {% endtab %}
   {% endtabs %}

***

#### Step 3: add a provision pipeline <a href="#step-3-add-a-provision-pipeline" id="step-3-add-a-provision-pipeline"></a>

A pipeline structures workflows to manage tasks like planning infrastructure changes, enforcing policies, and approvals. Go to [Harness Pipelines](/harness-ai/use-harness-platform/pipelines.md) to review pipeline concepts. You can also add pipelines through the Harness Platform or [use a code-first approach with YAML](/harness-ai/use-harness-platform/pipelines/create-pipeline-quickstart.md).

**Harness AI pipeline generation**

{% tabs %}
{% tab title="Interactive Guide" %}
{% embed url="<https://app.tango.us/app/embed/5e8d0ffa-f4a6-4b02-9953-dcd42e608ac8?skipCover=true&defaultListView=false&skipBranding=false&makeViewOnly=true&hideAuthorAndDetails=true>" %}
Create a Provision Pipeline in Harness IaCM
{% endembed %}
{% endtab %}

{% tab title="Step-by-step" %}
Start by adding the pipeline:

1. Select the **Infrastructure** module.
2. Select **Pipelines**, then select **Create a Pipeline**.
3. Select an option from Harness AI chat or type a request to generate one, for example:
   * "Create a pipeline to Provision an OpenTofu files with an init, plan and apply step."
4. Review the generated YAML and Harness AI chat summary, and make any changes if necessary.
5. Select **Accept**.
   {% endtab %}
   {% endtabs %}

The Provision operation adds three Terraform plugin steps: `init`, `plan`, and `apply`. Go to [Tofu/Terraform Plugins](/infrastructure-as-code-management/3.0/use-iacm/iacm-cli-commands/terraform-plugins.md) to review supported OpenTofu/Terraform commands.

***

#### Step 4: run your pipeline <a href="#step-4-run-your-pipeline" id="step-4-run-your-pipeline"></a>

Now run your pipeline to provision your infrastructure.

To run your provision pipeline, do the following:

1. Click **Save** to save your pipeline.
2. Click **Run** in the top right corner.
3. Confirm any runtime inputs if prompted.
4. Click **Run Pipeline**.

The pipeline executes the three steps in order: init, plan, and apply. Each step shows progress in real time. Click any step to view detailed logs.

After the apply step completes successfully, your infrastructure is provisioned. Go to the **Workspaces** view, select your workspace, and open the **Resources** tab to see the resources created.

{% hint style="info" %}
**ADD PRODUCTION FEATURES**

Go to [Set Up OpenTofu Provisioner](/infrastructure-as-code-management/3.0/use-iacm/iac-provisioners/opentofu/setup-opentofu-provisioner.md) to add approval gates, cost estimation, and variable management to your provisioner.
{% endhint %}
