# IaC on Quake AI: OpenTofu and Terraform

Source: https://docs.quake.ai/docs/automation/concepts/iac-comparison
Markdown: https://docs.quake.ai/docs/automation/concepts/iac-comparison.md

---

# IaC on Quake AI: OpenTofu and Terraform

**OpenTofu** is the default Infrastructure as Code tool for Quake AI. It is fully open source (MPL-2.0), backed by the Linux Foundation, and compatible with Terraform providers, modules, and state files. Quake AI templates and IaC how-to guides use OpenTofu.

If your team already uses **Terraform**, Quake AI templates work without modification: replace `tofu` with `terraform` in commands and you are set.

For rules when you author or extend templates, see [Authoring IaC templates for Quake AI](/docs/automation/concepts/authoring-iac-templates).

## OpenTofu vs. Terraform

<Figure size="md" caption="IaC tooling landscape: OpenTofu and Terraform sit in the declarative, stateful quadrant">

```d2
direction: down

ds: Declarative + stateful\nOpenTofu, Terraform, Heat
dl: Declarative + stateless\nKubernetes manifests
is: Imperative + stateful\nAWS CDK, Pulumi
il: Imperative + stateless\nBash, Ansible (ad hoc), CLI

ds -> dl {style.stroke-dash: 4}
ds -> is {style.stroke-dash: 4}
```

</Figure>

The diagram places Ansible in the imperative + stateless quadrant, but only for ad-hoc provisioning. That placement reflects how the `openstack.cloud` modules execute: each task issues an API call and reports `changed: true` based on the response, with no state file kept between runs. For provisioning workloads, OpenTofu's stateful, declarative model is a better fit; reach for OpenTofu first.

Ansible's primary role on Quake AI is **configuration management**, not provisioning. For Day 1 and Day 2 work, configuring an OS, deploying applications, rotating credentials, the same imperative + stateless properties become a feature: Ansible is idempotent at the task level (file present, package installed, service running), so reruns converge a host without needing a global state file. The full split is documented in [Ansible on Quake AI](/docs/automation/concepts/ansible) and the [getting-started how-to](/docs/automation/how-to/getting-started-ansible).

| | OpenTofu | Terraform |
|---|---|---|
| **License** | MPL-2.0 (open source) | BSL 1.1 (source available) |
| **Maintained by** | Linux Foundation | HashiCorp / IBM |
| **Provider model** | OpenStack + AWS providers | OpenStack + AWS providers |
| **State management** | Local or remote (S3-compatible) | Local or remote (S3-compatible) |
| **Template format** | HCL (.tf files) | HCL (.tf files) |
| **Module ecosystem** | Terraform Registry compatible | Terraform Registry |
| **Quake AI status** | **Recommended** | Fully supported |

In practice, there are no functional differences for Quake AI usage. The providers, state format, and HCL syntax are identical. The difference is licensing and governance.

## Why OpenTofu

- **License clarity.** MPL-2.0 is a well-understood open-source license with no usage restrictions. BSL 1.1 restricts competitive use, which creates ambiguity for some organizations.
- **Community governance.** The Linux Foundation provides neutral stewardship. No single vendor controls the roadmap.
- **Feature parity.** OpenTofu tracks Terraform provider compatibility. The OpenStack provider works identically in both tools.

## OpenTofu on Quake AI

OpenTofu uses the [OpenStack provider](https://registry.terraform.io/providers/terraform-provider-openstack/openstack/latest) to manage compute instances, networks, security groups, block storage, and floating IPs. For S3-compatible object storage, it uses the [AWS provider](https://registry.terraform.io/providers/hashicorp/aws/latest) with a custom endpoint.

OpenTofu authenticates to Quake AI via environment variables, with no credentials in template files. Use the application credential file produced by [Generate app credentials](/docs/tools/generate-app-credentials):

```bash
export OS_AUTH_URL="https://keystone.rumble.cloud"
export OS_AUTH_TYPE="v3applicationcredential"
export OS_APPLICATION_CREDENTIAL_ID="YOUR_APP_CREDENTIAL_ID"
export OS_APPLICATION_CREDENTIAL_SECRET="YOUR_APP_CREDENTIAL_SECRET"
export OS_REGION_NAME="us-east-1"
```

## Terraform on Quake AI

Terraform remains fully supported. The same OpenStack and AWS providers, the same HCL syntax, and the same state format work on Quake AI. OpenTofu templates in the Quake AI library run with `terraform` instead of `tofu`.

If your team uses Terraform Cloud, Terraform Enterprise, or Spacelift for remote state and runs. Those workflows are compatible with Quake AI resources through the OpenStack provider.

## Choosing the right tool

| Situation | Recommendation |
|---|---|
| New project, no existing IaC | OpenTofu |
| Existing Terraform workflows | Keep Terraform, or swap to OpenTofu (same templates) |
| Multi-cloud (Quake AI + AWS/GCP) | OpenTofu or Terraform (multi-provider support) |
| Existing Heat stacks in production | Keep Heat for those stacks; use OpenTofu for new resources |
| Need to install software, deploy apps, or harden OS on existing VMs | Ansible (configuration management above OpenTofu provisioning) |

For a new project, start with OpenTofu. The [getting started guide](/docs/automation/how-to/getting-started-iac) walks you through installation, authentication, and your first deployment.

## Legacy: Heat

Quake AI also supports [Heat](https://docs.openstack.org/heat/latest/) (OpenStack-native orchestration). Heat uses HOT YAML templates with server-side state management. You do not manage `.tfstate` files. However, Heat cannot manage resources outside OpenStack (no S3 buckets, DNS records, or external services), has no module ecosystem, and does not support a `plan` step before applying changes.

Heat is a legacy path. Existing Heat stacks on Quake AI keep running. For new infrastructure, use OpenTofu.

- [Create a Heat stack](/docs/automation/how-to/create-heat-stack)
- [Heat Simple Stack template](/resources/iac-templates/heat-simple-stack)

## Choosing a deployment pattern

Quake AI ships OpenTofu templates under [Infrastructure templates](/resources/iac-templates). Each template is a deployment pattern: a composition of primitives, not a standalone service. Use the table below to pick a starting pattern; each reference page includes a **When to use this pattern** blurb with sibling alternatives.

| Workload shape | Start with | Consider instead when |
|---|---|---|
| Single public VM | [Simple VM with Floating IP](/resources/iac-templates/simple-vm) | [Development Environment](/resources/iac-templates/dev-environment) for multi-subnet labs; [Containerized App](/resources/iac-templates/containerized-app) for Docker on one host |
| Public web entry point | [Edge Reverse Proxy](/resources/iac-templates/edge-reverse-proxy) | [API Gateway](/resources/iac-templates/api-gateway) for API routing and policy enforcement; [Edge WAF](/resources/iac-templates/edge-waf) for a filtered public origin |
| Multi-tier application | [Three-Tier Application](/resources/iac-templates/three-tier-app) or [Full-Stack Application](/resources/iac-templates/full-stack-app) | [Edge Reverse Proxy](/resources/iac-templates/edge-reverse-proxy) in front of private application instances; [WordPress + MySQL](/resources/iac-templates/wordpress-mysql) for a CMS plus database pair |
| Team dev sandbox | [Development Environment](/resources/iac-templates/dev-environment) | [Simple VM](/resources/iac-templates/simple-vm) for one VM; [Private Network + VPN](/resources/iac-templates/private-network-vpn) for WireGuard remote access |
| Managed database host | [Self-Managed PostgreSQL](/resources/iac-templates/self-managed-postgres) | [WordPress + MySQL](/resources/iac-templates/wordpress-mysql) for MySQL; tiered patterns above when the database sits behind web and app layers |
| Object storage bucket | [S3 Storage with ACLs](/resources/iac-templates/s3-storage-acl) | Compute templates when the workload needs VMs alongside storage |
| Kubernetes | [Kubernetes Cluster Bootstrap](/resources/iac-templates/k8s-cluster) | [Containerized App](/resources/iac-templates/containerized-app) for Docker without orchestration |
| Observability | [Monitoring Stack (Prometheus + Grafana)](/resources/iac-templates/monitoring-stack) | Pair with an application pattern above to scrape production instances |

After you deploy, customize any OpenTofu pattern through the shared how-tos linked from each template reference page.

## See also

- [Introduction to Terraform on Quake AI](/docs/automation/concepts/terraform)
- [Infrastructure templates](/resources/iac-templates)
- [Get started with IaC](/docs/automation/how-to/getting-started-iac)
