Agent skill

Opentofu Migration

by sickn33 in sickn33/agentic-awesome-skills

Migrate from Terraform to OpenTofu with state compatibility, provider registry setup, and CI/CD pipeline updates.

MITAuto-check passedDevOps & Cloud

Install Opentofu Migration

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill opentofu-migration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills opentofu-migration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/opentofu-migration .claude/skills/opentofu-migration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
opentofu-migration
GitHub stars
47k
Used in
2 other repos
Token cost
~2k tokens
SKILL.md length
266 words
Files
1
Skills in repo
1,497
Repo updated
First seen
Licence
MIT

At a glance

Migrate from Terraform to OpenTofu with state compatibility, provider registry setup, and CI/CD pipeline updates.

  • Works in 5 steps: Verify Compatibility → Replace CLI Commands → Update Provider Lock File → …
  • Adopting the open-source Terraform fork
  • SKILL.md covers When to Use This Skill, Prerequisites, Install OpenTofu and Migration Checklist, plus 6 more sections
  • Calls tofu, terraform and brew; reaches get.opentofu.org

What it does

Opentofu Migration is an agent skill from sickn33/agentic-awesome-skills. Migrate from Terraform to OpenTofu with state compatibility, provider registry setup, and CI/CD pipeline updates. Use when adopting the open-source Terraform fork or evaluating license-free IaC.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.

It sits in DevOps & Cloud, covering Infrastructure as code. It works with Terraform, Amazon Web Services, Microsoft Azure and Google Cloud. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Adopting the open-source Terraform fork
  • Evaluating license-free IaC

Example prompts

  • “/opentofu-migration”

Requirements

  • Docker
  • Compatibility (from SKILL.md): Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Verify Compatibility
  2. Replace CLI Commands
  3. Update Provider Lock File
  4. Update State Backend
  5. Provider Registry

What it can do on your machine

Read from SKILL.md and the folder at commit b84d35a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • tofu
    • terraform
    • brew
    • curl
    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • get.opentofu.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.

    From compatibility in the SKILL.md frontmatter.

Context cost

Opentofu Migration loads about 2k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 266 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit b84d35a, republished under its MIT licence (© sickn33). 266 words, ~2,000 tokens.

Download SKILL.mdSave it as .claude/skills/opentofu-migration/SKILL.md (or your agent's skills folder).
name
opentofu-migration
description
Migrate from Terraform to OpenTofu with state compatibility, provider registry setup, and CI/CD pipeline updates. Use when adopting the open-source Terraform fork or evaluating license-free IaC.
compatibility
Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.
category
devops
risk
critical
source
https://github.com/BagelHole/DevOps-Security-Agent-Skills
source_repo
BagelHole/DevOps-Security-Agent-Skills
source_type
community
date_added
2026-09-20
license
MIT
license_source
https://github.com/BagelHole/DevOps-Security-Agent-Skills/blob/main/LICENSE
metadata.author
devops-skills
metadata.version
1.0

OpenTofu Migration

Migrate infrastructure-as-code from HashiCorp Terraform to the open-source OpenTofu fork.

When to Use This Skill

Use this skill when:

  • Migrating from Terraform to OpenTofu for licensing reasons
  • Setting up a new IaC project and evaluating OpenTofu vs Terraform
  • Updating CI/CD pipelines to use OpenTofu
  • Configuring the OpenTofu provider registry

Prerequisites

  • Existing Terraform codebase (0.13+)
  • OpenTofu CLI installed
  • State backend access (S3, GCS, Azure Blob, etc.)

Install OpenTofu

bash
# macOS
brew install opentofu

# Linux (Debian/Ubuntu)
curl --proto '=https' --tlsv1.2 -fsSL https://get.opentofu.org/install-opentofu.sh \
  -o install-opentofu.sh
chmod +x install-opentofu.sh
./install-opentofu.sh --install-method deb
rm install-opentofu.sh

# Linux (RPM)
./install-opentofu.sh --install-method rpm

# Docker
docker run --rm -v $(pwd):/workspace -w /workspace \
  ghcr.io/opentofu/opentofu:latest init

# Verify installation
tofu --version

Migration Checklist

1. Verify Compatibility
bash
# OpenTofu reads Terraform state files directly — no migration needed
# Check your Terraform version (must be <= 1.6.x for full compat)
terraform version

# Run plan with OpenTofu against existing state
tofu init
tofu plan
2. Replace CLI Commands
TerraformOpenTofu
terraform inittofu init
terraform plantofu plan
terraform applytofu apply
terraform destroytofu destroy
terraform fmttofu fmt
terraform validatetofu validate
terraform statetofu state
terraform importtofu import
3. Update Provider Lock File
bash
# Remove Terraform lock and regenerate for OpenTofu
rm .terraform.lock.hcl
tofu init -upgrade

# Verify providers resolve correctly
tofu providers
4. Update State Backend

State files are compatible — no migration needed. Just verify:

hcl
# backend.tf — works identically with OpenTofu
terraform {
  backend "s3" {
    bucket         = "mycompany-tfstate"
    key            = "prod/infrastructure.tfstate"
    region         = "us-east-1"
    dynamodb_table = "terraform-locks"
    encrypt        = true
  }
}
bash
# Verify state access
tofu init
tofu state list
5. Provider Registry

OpenTofu uses its own registry but mirrors most Terraform providers:

hcl
# versions.tf
terraform {
  required_version = ">= 1.6.0"

  required_providers {
    aws = {
      source  = "hashicorp/aws"
      version = "~> 5.0"
    }
    kubernetes = {
      source  = "hashicorp/kubernetes"
      version = "~> 2.25"
    }
    # OpenTofu-specific providers
    random = {
      source  = "hashicorp/random"
      version = "~> 3.6"
    }
  }
}

OpenTofu-Specific Features

State Encryption (Not in Terraform)
hcl
# OpenTofu supports native state encryption
terraform {
  encryption {
    key_provider "pbkdf2" "my_key" {
      passphrase = var.state_passphrase
    }
    method "aes_gcm" "encrypt" {
      keys = key_provider.pbkdf2.my_key
    }
    state {
      method   = method.aes_gcm.encrypt
      enforced = true
    }
    plan {
      method   = method.aes_gcm.encrypt
      enforced = true
    }
  }
}
Early Variable/Local Evaluation
hcl
# OpenTofu allows variables in backend config and module sources
terraform {
  backend "s3" {
    bucket = var.state_bucket  # Works in OpenTofu, not Terraform
    key    = "${var.project}/terraform.tfstate"
    region = var.aws_region
  }
}

CI/CD Pipeline Updates

GitHub Actions
yaml
# .github/workflows/tofu.yml
name: OpenTofu
on:
  pull_request:
    paths: ["infra/**"]
  push:
    branches: [main]
    paths: ["infra/**"]

permissions:
  id-token: write
  contents: read
  pull-requests: write

jobs:
  plan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Setup OpenTofu
        uses: opentofu/setup-opentofu@v1
        with:
          tofu_version: "1.8.0"

      - name: Configure AWS credentials
        uses: aws-actions/configure-aws-credentials@v4
        with:
          role-to-assume: arn:aws:iam::123456789:role/tofu-deploy
          aws-region: us-east-1

      - name: Init
        run: tofu init
        working-directory: infra/

      - name: Plan
        id: plan
        run: tofu plan -no-color -out=tfplan
        working-directory: infra/

      - name: Comment PR with plan
        if: github.event_name == 'pull_request'
        uses: actions/github-script@v7
        with:
          script: |
            const output = `#### OpenTofu Plan
            \`\`\`
            ${{ steps.plan.outputs.stdout }}
            \`\`\``;
            github.rest.issues.createComment({
              issue_number: context.issue.number,
              owner: context.repo.owner,
              repo: context.repo.repo,
              body: output.substring(0, 65536)
            });

  apply:
    needs: plan
    if: github.ref == 'refs/heads/main'
    runs-on: ubuntu-latest
    environment: production
    steps:
      - uses: actions/checkout@v4
      - uses: opentofu/setup-opentofu@v1
      - uses: aws-actions/configure-aws-credentials@v4
        with:
          role-to-assume: arn:aws:iam::123456789:role/tofu-deploy
          aws-region: us-east-1
      - run: tofu init && tofu apply -auto-approve
        working-directory: infra/
GitLab CI
yaml
# .gitlab-ci.yml
stages: [validate, plan, apply]

variables:
  TOFU_VERSION: "1.8.0"

.tofu-base:
  image: ghcr.io/opentofu/opentofu:${TOFU_VERSION}
  before_script:
    - tofu init

validate:
  extends: .tofu-base
  stage: validate
  script:
    - tofu fmt -check
    - tofu validate

plan:
  extends: .tofu-base
  stage: plan
  script:
    - tofu plan -out=tfplan
  artifacts:
    paths: [tfplan]

apply:
  extends: .tofu-base
  stage: apply
  script:
    - tofu apply tfplan
  when: manual
  only: [main]
  dependencies: [plan]

Coexistence Strategy

If you need both tools during migration:

bash
# Use aliases to avoid conflicts
alias tf="terraform"
alias tofu="tofu"

# Or use direnv per-project
# .envrc
export PATH="/opt/opentofu/bin:$PATH"

# Wrapper script for gradual migration
#!/bin/bash
if [ -f ".use-opentofu" ]; then
    exec tofu "$@"
else
    exec terraform "$@"
fi

Troubleshooting

IssueSolution
Provider not foundRun tofu init -upgrade, check registry.opentofu.org
State lock conflictSame as Terraform — check DynamoDB/blob lease
Version constraint errorUpdate required_version to >= 1.6.0
Backend migrationState is compatible — just run tofu init
Missing provider credentialsSame env vars work (AWS_*, GOOGLE_*, ARM_*)
  • terraform-aws (terraform-aws) — AWS IaC patterns (works with both)
  • terraform-azure (terraform-azure) — Azure IaC patterns
  • terraform-gcp (terraform-gcp) — GCP IaC patterns
  • policy-as-code (policy-as-code) — OPA policy checks for IaC

Limitations

  • Infrastructure commands can disrupt services: confirm target host/scope and have backups/snapshots before mutating state.
  • Docs-only import: upstream scripts and templates not bundled.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/opentofu-migration of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit b84d35a

Used in 2 other repositories

We found 6 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Opentofu Migration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Opentofu Migration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Opentofu Migration this skillsickn33/agentic-awesome-skills47k2 repos~2kAutomated safety check: PassMIT
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only
TerrasharkLukasNiessen/terrashark716—~843Automated safety check: PassMIT
Provider Verificationmondoohq/mql412—~3.7kAutomated safety check: PassCustom licence
Terraform Module Librarywshobson/agents40k11 repos~1.3kAutomated safety check: PassMIT
Atmos Migrationcloudposse/atmos1.4k—~5.1kAutomated safety check: WarnApache-2.0

Similar skills

  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated 3 days ago
    DevOps & CloudAuto-check: notes
  • Terrashark

    LukasNiessen/terrashark

    Prevent Terraform/OpenTofu hallucinations by diagnosing and fixing failure modes: identity churn, secret exposure, blast-radius mistakes, CI drift, and compliance gate gaps.

    716 GitHub stars~843 tokensUpdated 7 days ago
    DevOps & CloudAuto-check passed
  • Verify mql provider resource/field changes against real cloud infrastructure.

    412 GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Build reusable, tested Terraform modules for AWS, Azure, GCP and OCI, with a standard file layout, an AWS VPC example, versioning rules and Terratest checks.

    40k GitHub starsUsed in 11 repos~1.3k tokens
    DevOps & CloudAuto-check passed
  • Atmos Migration

    cloudposse/atmos

    Migrate to Atmos from native Terraform, Terraform Workspaces, Terramate, Terragrunt, Make, Just, or Task; migrate tool versions from mise or Aqua CLI; migrate AWS/GCP/Azure CLI configs, Leapp…

    1.4k GitHub stars~5.1k tokensUpdated today
    DevOps & CloudAuto-check: warnings
  • Tsh Implementing Terraform Modules

    TheSoftwareHouse/copilot-collections

    Build reusable Terraform modules for AWS, Azure, and GCP infrastructure following infrastructure-as-code best practices.

    284 GitHub stars~1.6k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,497 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Categories

Questions about Opentofu Migration

What does Opentofu Migration do?

Migrate from Terraform to OpenTofu with state compatibility, provider registry setup, and CI/CD pipeline updates. Opentofu Migration is an agent skill from sickn33/agentic-awesome-skills. Migrate from Terraform to OpenTofu with state compatibility, provider registry setup, and CI/CD pipeline updates.

When should I use Opentofu Migration?

Opentofu Migration fits situations like: adopting the open-source Terraform fork; evaluating license-free IaC.

How do I install Opentofu Migration in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill opentofu-migration -a claude-code`. Or copy the skill folder (skills/opentofu-migration in sickn33/agentic-awesome-skills) into .claude/skills/opentofu-migration in your project. Claude Code loads it when a task matches its description.

How do I install Opentofu Migration in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill opentofu-migration -a codex`. Or copy the skill folder (skills/opentofu-migration in sickn33/agentic-awesome-skills) into .agents/skills/opentofu-migration in your project. Codex loads it when a task matches its description.

Can I use Opentofu Migration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill opentofu-migration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/opentofu-migration, .gemini/skills/opentofu-migration, .github/skills/opentofu-migration and .opencode/skills/opentofu-migration in your project.

What does Opentofu Migration need to run?

Going by SKILL.md and its folder, Opentofu Migration needs the command-line tools its instructions call (tofu, terraform, brew, curl and docker). Our summary lists: Docker. Compatibility (from SKILL.md): Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled..

Does Opentofu Migration access the network?

SKILL.md names 1 domain. In commands or code: get.opentofu.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Opentofu Migration safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Opentofu Migration use?

Opentofu Migration is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Opentofu Migration use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Opentofu Migration?

Skills that share tags, products or a category with Opentofu Migration: Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars), Terrashark (LukasNiessen/terrashark, 716 stars), Provider Verification (mondoohq/mql, 412 stars) and Terraform Module Library (wshobson/agents, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Opentofu Migration?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,405 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.