Dashboard › institutional-transition-lab › Distillation
97522f2d-bea5-4cb2-9c9b-65eb97f47a00["lore_tm_v1_-vfEZ4ipjkpWb_fPBCe-__fRifP-twz-OlM7_LonJ9U","lore_tm_v1_fuIMoIBTy24Or3o2suzEysZ9SeNX7lwqwB-jD0gdxsc","lore_tm_v1_KCuy1ji-o8dUvRoABKqC1t7-OEKgZunXhLLq662x1X0","lore_tm_v1_fqDryH5-jpdfM8hl2WshIIuhow4kIoB2DSXlursphoE","lore_tm_v1_NkeqynhbDDg-YBDDEwmUieJb1zn2Uqfz8tVvCD7DD1w","lore_tm_v1__YF8_DhZwxw9H-WaoYm9RlVq7rc0WCYPufFNc2FBuIA","lore_tm_v1_Xpq1ahrRIEOM4SGza5xpQgCGwCz_cA-3uKDOH3R_3vE","lore_tm_v1_umBqjx871iJulcMgDN_9HruzjXQKMRShCtt2B8-3OyA","lore_tm_v1_VJuqq_xO4jhxjVdhbTVS-nOL4s6KKuApShqkVuaHdJk","lore_tm_v1_IxrrZlZbxpwp5202n5pH_FVworJa5TmKfM_0g9ERS5o","lore_tm_v1_DrGWu3qicr81nJUuCjK1ZoZLd0SDVgtWmm--p9zUoc0","lore_tm_v1_8gPfEzIV5vtRbBOGx6N73I4Vvjn1n42_HOhNOhvkffk","lore_tm_v1_zqsJICwHb7DeLO10B0lktXNjhF_xgZxgyCir0ickqNY","lore_tm_v1_Jpb0KxiUFL_YSF-dGrPQEmaoHgNDmXu9drse2io6Ipc","lore_tm_v1_w0z-IYa5LdI-lmAn9XTz9nNaMo0ZtruO26YJkd4odSw","lore_tm_v1_Gqd1JsxbHSGakRcXZqPBLHakZedTQWY4s9cwif-wxYs","lore_tm_v1_zMn969-83FuxxkYBGqU6C0ZtmuvCfWbqXiDMZESOBtc"]
Date: Sep 8, 2026
contributing/FAQ.md guidance redirected Technical Steering Committee decisions and notes from local TSC to https://github.com/opentofu/org/tree/main/TSC.https://github.com/opentofu/opentofu/issues/741) unanimously. Reasons: keep the core team focused on the CLI rather than a highly available mission-critical SaaS; maximize availability using GitHub/AWS; make the registry transparent as a Git repository; and decouple artifact resolution from documentation and signing so each component can evolve under its own non-functional requirements. Initial signing security would match the legacy registry, while allowing later improvements; a user-facing registry/documentation design was deferred. (meaning Nov 2, 2023)@RLRabinowitz and @cube2222, in order: 1. announce the selected RFC ASAP; 2. resolve implementation details covering whether to scrape existing modules/providers and keys, key submission, version bumps, sharing the detailed design, and defining scope/task breakdown for the core team. (meaning Nov 2, 2023)@allofthesepeople; agenda items had to be posted at least 24 hours beforehand or the meeting would be canceled. A founders’ personnel decision favored employing core-team members through pledging companies that donate their time instead of direct foundation payroll; Spacelift had hired 2 dedicated maintainers and created a Tofu-specific hiring profile and pipeline to share with interested companies. (meaning Nov 2, 2023)opentofu received a quick unanimous yes. A registry UI/docs was not prioritized that quarter: Roni Frantchi favored it for discoverability and branding; Igor Savchenko considered it core-team defocus and disclosed work on library.tf, a non-associated Terraform/OpenTofu/other-IaC registry; Roger Simms preferred UI/docs through the CLI; Marcin Wyszynski had no strong view but considered it non-priority. The TSC invited RFCs for the proposed options before reconsideration. (meaning Dec 5, 2023)https://github.com/opentofu/opentofu/issues/874 accepted and raised in priority unanimously as a highly requested differentiator, despite Marcin Wyszynski preferring the long-term model of not storing secrets in state; 2. OpenTofu support in the VS Code Language Server (issue #970) was not a core-team priority, though an RFC might be accepted; 3. gunzipbase64 PR #799 accepted unanimously because it is the inverse of an existing function, while longer-term custom function extension/reuse remained desirable; 4. filesystem-state-backend performance PR #579 accepted unanimously. (meaning Dec 5, 2023)#988. Options were: (a) change the namespace, (b) add a deprecation notice for unqualified use, or (c) make no such change and mention it as softly as possible in documentation. Marcin Wyszynski accepted a warning, Roni Frantchi saw little upside and feared warnings would deter users, and Igor Savchenko suggested softer documentation; option (c) won unanimously. (meaning Dec 11, 2023)#812, allowing unknown input variables in tofu plan, broadened into workspace dependencies, Terragrunt’s role, and whether first-party functionality belonged in OpenTofu core or should remain layerable. The TSC wanted the issue reframed around the wider problem, followed by criteria for RFCs before soliciting them; the meeting ended before criteria were decided. (meaning Dec 11, 2023)1.xxx to OpenTofu 1.xxx—with Roni Frantchi, Roger Simms, Igor Savchenko, and Jim voting yes and Wojciech Barczynski no; it unanimously approved improving the “why OpenTofu” page. (meaning Feb 21, 2024)check command for Terraform-to-OpenTofu migration split yes (Roger Simms, Igor Savchenko, Jim) versus no (Roni Frantchi, Wojciech Barczynski), so the development team was asked for a concrete proposal. A reverse OpenTofu-to-Terraform check command was rejected, with only Jim voting yes; researching other projects’ migration tooling required no vote. (meaning Feb 21, 2024)x.y.z versions to specific OpenTofu a.b.c versions, documenting required code changes and unsupported features and committing to fix bugs on those paths. (meaning Feb 27, 2024).otf files where xyz.otf takes precedence over same-named xyz.tf; the TSC requested holistic RFC(s) covering community feedback, Terraform/OpenTofu divergence use cases, and IDE handling. For module-variable deprecation, approach 1—embed @deprecated: message or @deprecated{message} in descriptions—was rejected as magical, implicit, and hacky despite Terraform compatibility; approach 2—an explicit deprecated string field—was cleaner and first-class but Terraform-incompatible, so it was deferred for treatment in the divergence RFCs. (meaning Feb 27, 2024)tofu keyword as a one-off exception despite potential tool compatibility breakage; Igor Savchenko noted state encryption already broke compatibility and favored a long-term OpenTofu 1.8 solution, while Roni Frantchi, Roger Simms, and Marcin Wyszynski supported allowing no further exceptions until the divergence problem was solved. Alternatives rejected were waiting for the divergence RFC or reopening unrestricted divergence. (meaning Apr 3, 2024)1.X for Terraform-parity features and use 2.X for OpenTofu-specific features, with unresolved 1.X support duration and state encryption already complicating this; 2. continue current versioning; 3. solicit development-team/stakeholder input; 4. let module authors explicitly forbid OpenTofu; 5. ignore Terraform module-version constraints unless explicit OpenTofu constraints exist. Concerns included confusing OpenTofu/Terraform feature parity, Terraform constraints in modules, hostile module authors, and not making the project hostage to individuals. The decision was to consult stakeholders for 1 week and resume later. (meaning Apr 3, 2024)issue #1042, proof of concept PR #1107) proposed inserting a constant-evaluation stage between configuration loading and graph construction. It aimed to enable variables/locals in module sources, provider for_each, module provider mappings, backend configuration, lifecycle attributes, and variable defaults/validation, reducing copy/paste and workarounds such as Terragrunt, -backend-config, and override files. The remaining stated technical hurdle was interaction with module-tree construction when for_each is evaluated in constant context. Igor Savchenko favored proceeding but requested performance tests on large configurations and noted that it would break Terraform compatibility; the visible source was truncated before the discussion concluded. (meaning May 7, 2024)opentofu-github-pr-2959 updated CODEOWNERS because the governance chart changed and the new team was named opentofu-maintainers; existing code ownership was not working. The PR changed 1 file, with base SHA 0afbaae42d70c49159f25bac5a95f94f7048a17c, head SHA 6c1afd075a69497c77a5341eb47162aeacb8f67f, and merge commit SHA b82ed64756670f0ff54f034120d1e71aefa21358; it was merged and closed at 2025-06-25T15:47:24Z.opentofu-github-pr-3473 proposed a Databricks state backend with locking in rfc/20251021-databricks-backend.md. It was open and unmerged, changed 1 file, and had base SHA a961f737b7938f51a52202fdc6de5a2917b3c250, head SHA 3679fe6fa8e9cbcacbd5a0904f937a41151aa16a, and prospective merge commit SHA 799d04a68409e921b5402033488017b304c99797./Volumes/{catalog}/{schema}/{volume}/{key} through the Databricks Files API/SDK, relying on underlying cloud-storage versioning and cloud-provider encryption plus optional client-side encryption. Locking choices were: 1. Lakebase, recommended for PostgreSQL-compatible ACID locking and sub-50-ms acquisition but higher always-on compute cost; 2. Delta Lake primary-key constraints, a fallback with ACID semantics, approximately 1-second stated latency, possible SQL Warehouse cost, and a potentially inexpensive delta-kernel-rs access path.host, catalog, schema, volume, and key; optional settings included lock_backend = "lakebase" or "delta" with Delta as default, lock_timeout = "10m", and token = "${env:DATABRICKS_TOKEN}". Unified Auth order was: 1. explicit token/service-principal configuration, 2. environment variables, 3. ~/.databrickscfg.databricks catalogs create terraform_state; 2. databricks schemas create production terraform_state; 3. databricks volumes create terraform_state production \ infrastructure MANAGED; 4. update backend configuration; 5. run tofu init -migrate-state.internal/backend/remote-state/databricks, with Backend fields client *databricks.WorkspaceClient, catalog, schema, volume, and lockBackend, plus methods StateMgr(workspace string) (statemgr.Full, error), Workspaces() ([]string, error), and DeleteWorkspace(name string, force bool) error. Development phases, in order: 1. core backend and state operations, 2. Lakebase and Delta locking, 3. performance/error-handling production hardening, 4. documentation, migration tools, and benchmarks.>80% coverage, integration tests against a real Unity Catalog instance, concurrent/lock-contention stress tests, and performance tests. p95 targets were State GET < 3 seconds, State PUT < 5 seconds, Lakebase lock acquisition < 50ms, and Delta lock acquisition < 2 seconds. Retry policy: network errors get 3 retries, HTTP 429 gets automatic backoff, and authentication failures are not retried.VARIANT column; 3. traditional S3/Azure/GCS storage with Unity Catalog metadata—proven and cheaper, but does not unify governance. Prior art cited S3 with DynamoDB/native S3 locking, Azure Blob leases, GCS preconditions, and PostgreSQL database state/locking; the RFC found no existing Databricks backend in Terraform/OpenTofu ecosystems.opentofu-github-pr-3559 updated the support policy in RELEASE.md following the @opentofu/technical-steering-committee meeting on 09-12-25. It changed 1 file, with base SHA 1907ce104cbd6ec9a60e347b973b0f262eb4d43b, head SHA d06503ad9f725637a690bf9348bcff1f6ade528f, and merge commit SHA b2c6b935e06bfca47662792e7f71a7df8a6a36ad; it was merged at 2025-12-09T17:53:08Z.opentofu-github-pr-4018 implemented an in-band OpenTofu v1.13 warning that official support for 386 and arm 32-bit CPU builds was forthcomingly ending, in response to issue #3912 and a TSC request for at least 1 warning release. The warning was limited to official builds and tofu init: official-only avoids irrelevant warnings in third-party builds, while init avoids repeated warnings on every plan or apply, accepting the risk that users may not run init immediately after upgrading.opentofu-github-pr-4018 defined official builds by setting BUILD_OPENTOFU_OFFICIAL: '1' in .github/workflows/release.yml. New version/official.go added global officialBuild, IsOfficialBuild() bool, and test helper WithFakedOfficialBuild(official bool, f func()); documentation described linker activation with -X 'github.com/opentofu/opentofu/version.officialBuild=1'. WithFakedOfficialBuild saves/restores global state and must not be used in parallel tests.opentofu-github-pr-4018 changed 7 files, with base SHA 34e03c9fc38eb1b290e7db57537e42506aca1c28, head SHA 38a52bc2038c180c9ca1859c8ff2e2fb24a6326f, and merge commit SHA 82676082728b0dc5fb14552f2a663850d7422817; it was merged and closed at 2026-08-11T20:53:09Z.opentofu-github-pr-727 added # SPDX-License-Identifier: MPL-2.0 immediately after the shebang in .github/scripts/compare-release-versions.sh, correcting a license omitted when the release-workflow version-comparison script was written. It changed 1 file, with base SHA 913578a9f45acebbb2c35279925e475ff839c14b, head SHA 8e98cd47b7dccb37b6ac437680d18a50d81bc7f6, and merge commit SHA 131b15c45e373c743648b0059d022b58b2f53251; it was merged at 2023-10-15T08:04:41Z.opentofu-github-pr-823 created TSC_SUMMARY.md with the Nov. 2, 2023 TSC summary. It changed 1 file, with base SHA b2069bb0bbfc7dd121a5d72613bb71ca12375405, head SHA f449ce3afb8fe0bc1866291652348499c20d35ae, and merge commit SHA 60a3f72d43c002f83246e657a15b9b2157fd74c6; it was merged at 2023-11-06T11:21:40Z.opentofu-github-pr-990 prepended the Dec. 5, 2023 TSC summary to TSC_SUMMARY.md. It changed 1 file, with base SHA 5fc6ba240dbbe6ecc3643040150686f88e223583, head SHA 7db41d4cfbbd4c54cfd9db70c3d58282a0118bb3, and merge commit SHA 6b864ef262d6b924d94a61a0e1e29ff27b834a02; it was merged at 2023-12-11T11:52:31Z.