Skip to content

How to migrate from AWS CloudFormation to OpenTofu on Quake AI

Migration · Updated Jun 2026

Coming from another cloud?

▸AWS·Stacks, EC2 Instances, Amazon Virtual Private Cloud, ALB, RDS Postgres, Amazon S3

EC2 Instanceshigh

  • Uses EC2 RunInstances API instead of Nova servers.create.
  • Requires predefined instance type selection.
  • Supports per-second On-Demand billing and Spot/Reserved options.
  • Includes hibernation state not standard in OpenStack.
AWS docs ↗

Amazon Virtual Private Cloudhigh

  • AWS VPC is regional with CIDR /16-/28.
  • OpenStack Networks project-scoped L2 with flexible CIDR.
  • AWS requires IGW for public.
  • OpenStack provider nets or floating IPs.
AWS docs ↗

Stackshigh

  • Quake AI offers Heat (legacy OpenStack orchestration) and recommends OpenTofu for new IaC work; EKS uses declarative console/CLI.
  • EKS Auto Mode automates data plane; Quake AI uses OpenTofu modules for infrastructure provisioning.
  • CloudFormation stacks are managed via AWS-specific REST API (e.g., cloudformation.us-east-1.amazonaws.com) requiring AWS SigV4 auth, while Heat (legacy) uses OpenStack Identity API v3 (keystoneauth) and OpenTofu uses the OpenStack provider with application credentials. Migrators notice different endpoint discovery and auth flows.
  • Stacks support StackSets for cross-region/account deployment; Heat has no equivalent. OpenTofu workspaces offer a different multi-environment pattern.
AWS docs ↗

How to migrate from AWS CloudFormation to OpenTofu on Quake AI

If your infrastructure runs on AWS and is defined in CloudFormation, moving to Quake AI means rewriting those stack definitions in OpenTofu HCL. This guide maps common CloudFormation resource types to their Quake AI OpenTofu equivalents and outlines a practical migration workflow.

Conceptual mapping#

CloudFormation and OpenTofu serve the same purpose (declarative infrastructure definition) but differ in execution:

ConceptCloudFormationOpenTofu on Quake AI
Template formatJSON or YAMLHCL (.tf files)
State managementServer-side (AWS manages)Client-side state file (local or S3 remote)
Provider modelAWS-only (with some Custom Resources)Multi-provider (OpenStack + AWS S3 + DNS)
Change previewChange Setstofu plan
ExecutionAWS serviceLocal CLI or CI runner
RollbackAutomatic on failureManual (restore state or re-apply)

Resource equivalents#

AWS CloudFormation ResourceQuake AI OpenTofu ResourceNotes
AWS::EC2::Instanceopenstack_compute_instance_v2Map AMIs to Quake AI images
AWS::EC2::VPCopenstack_networking_network_v2 + openstack_networking_subnet_v2Quake AI uses flat networking; no NAT gateway equivalent
AWS::EC2::SecurityGroupopenstack_networking_secgroup_v2 + rulesSame concept, different API
AWS::EC2::EIPopenstack_networking_floatingip_v2Associate with openstack_compute_floatingip_associate_v2
AWS::ElasticLoadBalancingV2::LoadBalancerSelf-managed reverse proxy or API gateway instance with a floating IPTranslate listeners and target groups into proxy routes and private backend addresses
AWS::RDS::DBInstanceopenstack_compute_instance_v2 + cloud-initNo managed DB yet; use Self-Managed PostgreSQL template
AWS::S3::Bucketaws_s3_bucket (with Quake AI S3 endpoint)See S3 Storage with ACLs template
AWS::EC2::Volumeopenstack_blockstorage_volume_v3NVMe block storage
AWS::CloudFormation::Stack (nested)OpenTofu modulesUse module blocks for composition

Migration workflow#

1. Audit your CloudFormation stacks#

Export your current stack resources:

bash
aws cloudformation describe-stack-resources \
  --stack-name YOUR_STACK_NAME \
  --query 'StackResources[].{Type:ResourceType,Logical:LogicalResourceId,Physical:PhysicalResourceId}' \
  --output table

Document each resource type and its configuration. Pay attention to:

  • Instance types and AMIs (map to Quake AI flavors and images)
  • VPC CIDR ranges and subnet layout
  • Security group rules
  • Load balancer listeners and target groups
  • S3 bucket policies and lifecycle rules

2. Map to Quake AI resources#

For each CloudFormation resource, identify the OpenTofu equivalent from the table above. Start with the Quake AI template library; many common patterns are already authored:

3. Write OpenTofu configuration#

Start with a single resource (typically a compute instance) and validate the provider setup:

HCL
terraform {
  required_version = ">= 1.6.0"

  required_providers {
    openstack = {
      source  = "terraform-provider-openstack/openstack"
      version = "~> 2.0"
    }
  }
}

provider "openstack" {}

data "openstack_images_image_v2" "ubuntu" {
  name        = "Ubuntu-24.04"
  most_recent = true
}

resource "openstack_compute_instance_v2" "web" {
  name        = "web-server"
  flavor_name = "s1a.medium"

  block_device {
    uuid                  = data.openstack_images_image_v2.ubuntu.id
    source_type           = "image"
    destination_type      = "volume"
    volume_size           = 20
    boot_index            = 0
    delete_on_termination = true
  }

  network {
    name = "PublicStatic"
  }
}

Run tofu plan to verify the configuration is valid, then iterate to add the rest of your resources.

4. Set up remote state#

Before applying, configure remote state with Quake AI S3 so your team can collaborate on the infrastructure.

5. Apply incrementally#

Deploy resources in dependency order:

  1. Networking (networks, subnets, security groups)
  2. Storage (block volumes, S3 buckets)
  3. Compute (instances, cloud-init)
  4. Edge proxy or API gateway and DNS

Key differences from AWS#

  • No managed databases. Use the Self-Managed PostgreSQL template, or pair Quake AI with the managed database service your architecture uses externally.
  • Network translation. Instances use floating IPs or direct network attachment for internet access. Put a self-managed edge reverse proxy or API gateway on one floating IP when several private backends need a shared public entry point.
  • No IAM roles. Authentication uses OpenStack Keystone credentials via environment variables.
  • Fixed monthly pricing. No per-hour billing surprises; plan capacity based on monthly cost rather than usage estimates.

See also#

Usage Guidelines

The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.

Comparisons to third-party providers in this material reflect publicly documented behavior as of the validation date below. Pricing, quotas, service limits, and feature availability change frequently on every cloud. Verify provider-specific claims against the provider's own current documentation before relying on them for a procurement, architecture, or migration decision.

For the full policy, see Usage Guidelines.

Last validated: 22.06.2026

Was this page helpful?