choudoufu

module
v0.2.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 12, 2026 License: MPL-2.0

README

choudoufu

Go Reference

Ownership on the resource.

Latest release: v0.1.0, built on OpenTofu 1.13.0 (fork point 03743ce6e8).

Choudoufu is OpenTofu with live resource markers. There is no state file, no backend and no lock. Each resource carries its own ownership record as plain tags, and every plan rebuilds prior state by reading those markers off the live system. It is experimental and AWS only at the moment. Everything else is stock OpenTofu. The binary is choudoufu.

If you already use OpenTofu, the short version is that terraform.tfstate stops existing. Adoption is a tag you write. A rename is a tag you rewrite.

New here? Start with the FAQ. It answers the questions an OpenTofu user tends to ask in the first five minutes. The fork's docs also render as a site at intentius.io/choudoufu.

Where this stands

Live markers are experimental, and the scope is deliberately narrow. The mode covers AWS only, a fixed subset of resource types, and the root module. Configs outside that subset are refused up front by a lint pass rather than half supported. The full boundary, with the reasoning for each limit, is in live/LIMITATIONS.md.

Install

Every tagged release publishes prebuilt binaries for macOS and Linux (amd64 and arm64), with a SHA256SUMS file, on the releases page. To fetch the latest for your platform:

os=$(uname -s | tr '[:upper:]' '[:lower:]')
arch=$(uname -m | sed 's/x86_64/amd64/; s/aarch64/arm64/')
gh release download -R INTENTIUS/choudoufu --pattern "*_${os}_${arch}.tar.gz"
tar xzf choudoufu_*_"${os}"_"${arch}".tar.gz   # unpacks ./choudoufu

Building from source stays one command (below).

Moving an existing estate over

A greenfield estate is two steps: declare a live block and apply. An estate that already has live resources is not, and the difference matters before you try this on anything you care about. Adoption is a deliberate tag write, and nothing binds a live resource to your configuration until its markers are on it.

  1. Add live { estate = "..." } to your terraform block, remove any backend or cloud block, and delete the state file.
  2. Run choudoufu plan and read it. Live resources carrying no markers appear in the plan's Adoptable and Unowned sections, each naming the exact tags that claim it.
  3. Write those tags, using the command the plan prints or your own tooling. There is no adopt command; two tags is the whole contract (live/MARKERS.md).
  4. Plan again. Adopted resources read back their own markers and report no changes.
  5. Apply once the plan is what you expect.

Applying at step 2 rather than reading is how you get duplicates: an unmarked resource is not yours yet, so the plan proposes creating a second one beside it. Which types can be offered automatically, which need a hand-written tag, and which have no adoption path at all are covered in "Migrating an Existing Estate".

See it prove itself

The demo is also the test suite. It stands up a real estate of resources against a local AWS emulator, deletes the state file partway through, and shows the plans stay exact anyway. It needs Docker and takes about two minutes. The exit code is the verdict.

bash live/e2e/run.sh --expect 5

Or paste this to a coding agent (Claude Code or similar) and let it run the demo end to end.

Clone https://github.com/INTENTIUS/choudoufu, then do the following.

1. Confirm Docker is running (`docker info` must succeed).
2. If Go is installed, skip this step. Otherwise download the latest
   release tarball for this platform from
   https://github.com/INTENTIUS/choudoufu/releases, extract it, and
   export TOFU_BIN=<absolute path to the extracted choudoufu binary>.
3. From the repo root, run: bash live/e2e/run.sh --expect 5
4. Report each step's result as the script prints it, and the final exit code.

Exit code 0 means every claim the script makes about live resource markers
held. Non-zero means one of them did not. Report which step failed.

Building and testing

go build ./cmd/choudoufu
go test ./...

The integration tier needs Docker and TF_FLOCI_TEST=1.

Docs

The docs unique to this fork, in reading order.

  • live/FAQ.md covers the questions a first-time reader asks, including what happens to an existing state file.
  • website/docs/language/live-markers.mdx is the concept page. What live resource markers are, the quickstart, the concurrency story, and the full contract.
  • live/MARKERS.md is the marker tag spec, the one integration surface external tooling relies on.
  • live/LIMITATIONS.md lists every construct the mode bounds or rejects, each with its lint rule and fixture.
  • live/RECEIPTS.md shows how to record an effect that leaves nothing in the live system to read back.
  • live/e2e/README.md documents the demo/test harness and how to read its output.

These also render as a small docs site at https://intentius.io/choudoufu/. All stock OpenTofu documentation lives at opentofu.org.

a plate of choudoufu

License

MPL-2.0. Forked from opentofu/opentofu at 03743ce6e8. LICENSE and all copyright headers are unchanged from upstream.

choudoufu is not affiliated with or endorsed by OpenTofu or the Linux Foundation. OpenTofu is a registered trademark of the Linux Foundation.

Directories

Path Synopsis
cmd
choudoufu command
internal
addrs
Package addrs contains types that represent "addresses", which are references to specific objects within a OpenTofu configuration or state.
Package addrs contains types that represent "addresses", which are references to specific objects within a OpenTofu configuration or state.
backend
Package backend provides interfaces that the CLI uses to interact with OpenTofu.
Package backend provides interfaces that the CLI uses to interact with OpenTofu.
backend/init
Package init contains the list of backends that can be initialized and basic helper functions for initializing those backends.
Package init contains the list of backends that can be initialized and basic helper functions for initializing those backends.
backend/remote-state/gcs
Package gcs implements remote storage of state on Google Cloud Storage (GCS).
Package gcs implements remote storage of state on Google Cloud Storage (GCS).
checks
Package checks contains the models for representing various kinds of declarative condition checks that can be defined in a OpenTofu module and then evaluated and reported by OpenTofu Core during plan and apply operations.
Package checks contains the models for representing various kinds of declarative condition checks that can be defined in a OpenTofu module and then evaluated and reported by OpenTofu Core during plan and apply operations.
command/cliconfig
Package cliconfig has the types representing and the logic to load CLI-level configuration settings.
Package cliconfig has the types representing and the logic to load CLI-level configuration settings.
command/cliconfig/ociauthconfig
Package ociauthconfig contains types used for describing OCI authentication settings, and helpers for discovering such settings from container engine configuration files as described in https://github.com/containers/image/blob/main/docs/containers-auth.json.5.md .
Package ociauthconfig contains types used for describing OCI authentication settings, and helpers for discovering such settings from container engine configuration files as described in https://github.com/containers/image/blob/main/docs/containers-auth.json.5.md .
command/cliconfig/svcauthconfig
Package svcauthconfig contains some helper functions and types to support the cliconfig package's use of github.com/opentofu/svchost/svcauth, which is our mechanism for representing the policy for authenticating to OpenTofu-native services such as implementations OpenTofu's provider registry protocol.
Package svcauthconfig contains some helper functions and types to support the cliconfig package's use of github.com/opentofu/svchost/svcauth, which is our mechanism for representing the policy for authenticating to OpenTofu-native services such as implementations OpenTofu's provider registry protocol.
command/clistate
Package state exposes common helpers for working with state from the CLI.
Package state exposes common helpers for working with state from the CLI.
command/e2etest
Package e2etest contains a set of tests that run against a real OpenTofu binary, compiled on the fly at the start of the test run.
Package e2etest contains a set of tests that run against a real OpenTofu binary, compiled on the fly at the start of the test run.
command/e2etest/fakeocireg
Package fakeocireg provides a minimal, read-only implementation of the OCI Distribution protocol that interacts with a local filesystem directory.
Package fakeocireg provides a minimal, read-only implementation of the OCI Distribution protocol that interacts with a local filesystem directory.
command/format
Package format contains helpers for formatting various OpenTofu structures for human-readable output.
Package format contains helpers for formatting various OpenTofu structures for human-readable output.
command/jsonchecks
Package jsonchecks implements the common JSON representation of check results/statuses that we use across both the JSON plan and JSON state representations.
Package jsonchecks implements the common JSON representation of check results/statuses that we use across both the JSON plan and JSON state representations.
command/jsonconfig
Package jsonconfig implements methods for outputting a configuration snapshot in machine-readable json format
Package jsonconfig implements methods for outputting a configuration snapshot in machine-readable json format
command/jsonentities
Package jsonentities contains the entities for representing a few common resources used around the json* packages.
Package jsonentities contains the entities for representing a few common resources used around the json* packages.
command/jsonformat/computed
Package computed contains types that represent the computed diffs for OpenTofu blocks, attributes, and outputs.
Package computed contains types that represent the computed diffs for OpenTofu blocks, attributes, and outputs.
command/jsonformat/structured
Package structured contains the structured representation of the JSON changes returned by the jsonplan package.
Package structured contains the structured representation of the JSON changes returned by the jsonplan package.
command/jsonplan
Package jsonplan implements methods for outputting a plan in a machine-readable json format
Package jsonplan implements methods for outputting a plan in a machine-readable json format
command/jsonprovider
Package jsonprovider contains types and functions to marshal OpenTofu provider schemas into a json formatted output.
Package jsonprovider contains types and functions to marshal OpenTofu provider schemas into a json formatted output.
command/jsonstate
Package jsonstate implements methods for outputting a state in a machine-readable json format
Package jsonstate implements methods for outputting a state in a machine-readable json format
command/workdir
Package workdir models the various local artifacts and state we keep inside a OpenTofu "working directory".
Package workdir models the various local artifacts and state we keep inside a OpenTofu "working directory".
configs
Package configs contains types that represent OpenTofu configurations and the different elements thereof.
Package configs contains types that represent OpenTofu configurations and the different elements thereof.
configs/configload
Package configload knows how to install modules into the .terraform/modules directory and to load modules from those installed locations.
Package configload knows how to install modules into the .terraform/modules directory and to load modules from those installed locations.
configs/configschema
Package configschema contains types for describing the expected structure of a configuration block whose shape is not known until runtime.
Package configschema contains types for describing the expected structure of a configuration block whose shape is not known until runtime.
dag
depsfile
Package depsfile contains the logic for reading and writing OpenTofu's dependency lock and development override configuration files.
Package depsfile contains the logic for reading and writing OpenTofu's dependency lock and development override configuration files.
e2e
encryption/keyprovider/pbkdf2
Package pbkdf2 contains a key provider that takes a passphrase and emits a PBKDF2 hash of the configured length.
Package pbkdf2 contains a key provider that takes a passphrase and emits a PBKDF2 hash of the configured length.
encryption/keyprovider/static
Package static contains a key provider that emits a static key.
Package static contains a key provider that emits a static key.
encryption/keyprovider/xor
Package xor contains a key provider that combines two other keys.
Package xor contains a key provider that combines two other keys.
engine/internal/exec
Package exec contains the models and main interface used for apply phase execution.
Package exec contains the models and main interface used for apply phase execution.
engine/internal/execgraph/execgraphproto
Package execgraphproto contains just the protocol buffers models we use for marshaling and unmarshaling execution graphs.
Package execgraphproto contains just the protocol buffers models we use for marshaling and unmarshaling execution graphs.
engine/planning
Package planning implements a planning engine for OpenTofu, which takes a prior state and a configuration instance (which can be evaluated to produce a desired state) and proposes a set of changes to make to bring the remote system closer to convergence with the desired state.
Package planning implements a planning engine for OpenTofu, which takes a prior state and a configuration instance (which can be evaluated to produce a desired state) and proposes a set of changes to make to bring the remote system closer to convergence with the desired state.
experiments
Package experiments contains the models and logic for opt-in experiments that can be activated for a particular OpenTofu module.
Package experiments contains the models and logic for opt-in experiments that can be activated for a particular OpenTofu module.
genconfig
Package genconfig implements config generation from provided state values.
Package genconfig implements config generation from provided state values.
getmodules
Package getmodules contains the low-level functionality for fetching remote module packages.
Package getmodules contains the low-level functionality for fetching remote module packages.
getproviders
Package getproviders is the lowest-level provider automatic installation functionality.
Package getproviders is the lowest-level provider automatic installation functionality.
initwd
Package initwd contains various helper functions used by the "tofu init" command to initialize a working directory.
Package initwd contains various helper functions used by the "tofu init" command to initialize a working directory.
ipaddr
Package ipaddr is a fork of a subset of the Go standard "net" package which retains parsing behaviors from Go 1.16 or earlier.
Package ipaddr is a fork of a subset of the Go standard "net" package which retains parsing behaviors from Go 1.16 or earlier.
lang
Package lang deals with the runtime aspects of OpenTofu's configuration language, with concerns such as expression evaluation.
Package lang deals with the runtime aspects of OpenTofu's configuration language, with concerns such as expression evaluation.
lang/blocktoattr
Package blocktoattr includes some helper functions that can perform preprocessing on a HCL body where a configschema.Block schema is available in order to allow list and set attributes defined in the schema to be optionally written by the user as block syntax.
Package blocktoattr includes some helper functions that can perform preprocessing on a HCL body where a configschema.Block schema is available in order to allow list and set attributes defined in the schema to be optionally written by the user as block syntax.
lang/eval
Package eval aims to encapsulate the details of evaluating the objects in an overall configuration, including all of the expressions written inside their declarations, in a way that can be reused across various different phases of execution.
Package eval aims to encapsulate the details of evaluating the objects in an overall configuration, including all of the expressions written inside their declarations, in a way that can be reused across various different phases of execution.
lang/eval/internal/tofu2024
Package tofu2024 contains the "module compiler" implementation for the first edition of the OpenTofu language, established with OpenTofu v1.6 in 2024 and then gradually evolved in backward-compatible ways.
Package tofu2024 contains the "module compiler" implementation for the first edition of the OpenTofu language, established with OpenTofu v1.6 in 2024 and then gradually evolved in backward-compatible ways.
lang/exprs
Package exprs contains supporting code for expression evaluation.
Package exprs contains supporting code for expression evaluation.
lang/globalref
Package globalref is home to some analysis algorithms that aim to answer questions about references between objects and object attributes across an entire configuration.
Package globalref is home to some analysis algorithms that aim to answer questions about references between objects and object attributes across an entire configuration.
lang/grapheval
Package grapheval contains some low-level helpers for coordinating interdependent work happening across different parts of the system, including detection and reporting of self-dependency problems that would otherwise cause a deadlock.
Package grapheval contains some low-level helpers for coordinating interdependent work happening across different parts of the system, including detection and reporting of self-dependency problems that would otherwise cause a deadlock.
lang/lint
Package lint contains a collection of helpers for performing "lint-like" checks to try to detect configuration constructs that are valid but nonetheless very likely to be a mistake.
Package lint contains a collection of helpers for performing "lint-like" checks to try to detect configuration constructs that are valid but nonetheless very likely to be a mistake.
lang/types
Package types contains non-standard cty types used only within OpenTofu.
Package types contains non-standard cty types used only within OpenTofu.
legacy/hcl2shim
Package hcl2shim contains a small number of "shimming" utilities that the other packages under internal/legacy use to adapt from HCL 2 concepts to legacy concepts.
Package hcl2shim contains a small number of "shimming" utilities that the other packages under internal/legacy use to adapt from HCL 2 concepts to legacy concepts.
legacy/helper/acctest
Package acctest contains for OpenTofu Acceptance Tests
Package acctest contains for OpenTofu Acceptance Tests
legacy/helper/schema
Package schema is a legacy package that used to represent the SDK, which is now its own library external to OpenTofu Core https://github.com/hashicorp/terraform-plugin-sdk Some of it is still used by OpenTofu's remote state backends, but this entire package should be removed in the future.
Package schema is a legacy package that used to represent the SDK, which is now its own library external to OpenTofu Core https://github.com/hashicorp/terraform-plugin-sdk Some of it is still used by OpenTofu's remote state backends, but this entire package should be removed in the future.
live
Package stateless implements OpenTofu's stateless mode: a run mode with no authoritative state file, no backend, and no lock.
Package stateless implements OpenTofu's stateless mode: a run mode with no authoritative state file, no backend, and no lock.
live/discovery
Package discovery finds the live resources of a stateless estate by their ownership markers and binds them to the addresses that declare them.
Package discovery finds the live resources of a stateless estate by their ownership markers and binds them to the addresses that declare them.
live/flocitest
Package flocitest holds the gate, the fixture paths and the container bookkeeping that the floci integration tests share.
Package flocitest holds the gate, the fixture paths and the container bookkeeping that the floci integration tests share.
live/foreign
Package foreign classifies the live resources an estate does not own, and is the safety property of stateless mode: a live resource nobody claims is surfaced, and is never a deletion candidate.
Package foreign classifies the live resources an estate does not own, and is the safety property of stateless mode: a live resource nobody claims is surfaced, and is never a deletion candidate.
live/identity
Package identity classifies the identity of every managed resource instance in a configuration, using nothing but the configuration itself.
Package identity classifies the identity of every managed resource instance in a configuration, using nothing but the configuration itself.
live/lifecycle
Package lifecycle holds five integration tests and nothing else: the lifecycle test itself (P4.1), the snapshot test (P4.2), the exactness test (P5.1), the crash-mid-apply test (the concurrency taxonomy's crash row, run rather than argued), and the existence-flavor receipt test (RA.6).
Package lifecycle holds five integration tests and nothing else: the lifecycle test itself (P4.1), the snapshot test (P4.2), the exactness test (P5.1), the crash-mid-apply test (the concurrency taxonomy's crash row, run rather than argued), and the existence-flavor receipt test (RA.6).
live/lint
Package lint is the stateless-mode subset check: the pass that decides whether a configuration can be planned with no authoritative state at all.
Package lint is the stateless-mode subset check: the pass that decides whether a configuration can be planned with no authoritative state at all.
live/listclient
Package listclient is stateless mode's client for the provider list protocol: the ListResource server-streaming RPC and the list resource schemas that parameterize it.
Package listclient is stateless mode's client for the provider list protocol: the ListResource server-streaming RPC and the list resource schemas that parameterize it.
live/markers
Package markers is live/MARKERS.md in code: the ownership tag keys, the escaping rule that lets a resource address live in a tag value, and the reading of those tags off a live object.
Package markers is live/MARKERS.md in code: the ownership tag keys, the escaping rule that lets a resource address live in a tag value, and the reading of those tags off a live object.
live/mv
Package mv performs the rename operation stateless mode has instead of `moved` blocks and state surgery: it rewrites the tofu-address ownership marker on one live resource.
Package mv performs the rename operation stateless mode has instead of `moved` blocks and state surgery: it rewrites the tofu-address ownership marker on one live resource.
live/projection
Package projection materializes an ephemeral prior state by reading the live system.
Package projection materializes an ephemeral prior state by reading the live system.
live/slots
Package slots is the set matcher for count instances: the rule that turns "N declared instances and M live resources" into a binding, without any index participating in identity.
Package slots is the set matcher for count instances: the rule that turns "N declared instances and M live resources" into a binding, without any index participating in identity.
live/stamp
Package stamp makes ownership markers something the tool guarantees rather than something the configuration author remembered to write.
Package stamp makes ownership markers something the tool guarantees rather than something the configuration author remembered to write.
modsdir
Package modsdir is an internal package containing the model types used to represent the manifest of modules in a local modules cache directory.
Package modsdir is an internal package containing the model types used to represent the manifest of modules in a local modules cache directory.
oci
plans
Package plans contains the types that are used to represent OpenTofu plans.
Package plans contains the types that are used to represent OpenTofu plans.
plans/internal/planproto
Package planproto is home to the Go stubs generated from the tfplan protobuf schema.
Package planproto is home to the Go stubs generated from the tfplan protobuf schema.
plans/objchange
Package objchange deals with the business logic of taking a prior state value and a config value and producing a proposed new merged value, along with other related rules in this domain.
Package objchange deals with the business logic of taking a prior state value and a config value and producing a proposed new merged value, along with other related rules in this domain.
plans/planfile
Package planfile deals with the file format used to serialize plans to disk and then deserialize them back into memory later.
Package planfile deals with the file format used to serialize plans to disk and then deserialize them back into memory later.
plugin/mock_proto
Package mock_tfplugin5 is a generated GoMock package.
Package mock_tfplugin5 is a generated GoMock package.
plugin6/mock_proto
Package mock_tfplugin6 is a generated GoMock package.
Package mock_tfplugin6 is a generated GoMock package.
provider-simple
simple provider a minimal provider implementation for testing
simple provider a minimal provider implementation for testing
provider-simple-v6
simple provider a minimal provider implementation for testing
simple provider a minimal provider implementation for testing
providercache
Package providercache contains the logic for auto-installing providers from packages obtained elsewhere, and for managing the local directories that serve as global or single-configuration caches of those auto-installed providers.
Package providercache contains the logic for auto-installing providers from packages obtained elsewhere, and for managing the local directories that serve as global or single-configuration caches of those auto-installed providers.
providers
Package providers contains the interface and primary types required to implement a OpenTofu resource provider.
Package providers contains the interface and primary types required to implement a OpenTofu resource provider.
provisioners
Package provisioners contains the interface and primary types to implement a OpenTofu resource provisioner.
Package provisioners contains the interface and primary types to implement a OpenTofu resource provisioner.
repl
Package repl provides the structs and functions necessary to run REPL for OpenTofu.
Package repl provides the structs and functions necessary to run REPL for OpenTofu.
replacefile
Package replacefile is a small helper package focused directly at the problem of atomically "renaming" one file over another one.
Package replacefile is a small helper package focused directly at the problem of atomically "renaming" one file over another one.
resources
Package resources contains helpers that encapsulate the main interactions OpenTofu has with resource instance objects, wrapping the raw provider client calls with certain preprocessing, postprocessing, and validation logic that ought to happen regardless of why OpenTofu is asking each of these questions.
Package resources contains helpers that encapsulate the main interactions OpenTofu has with resource instance objects, wrapping the raw provider client calls with certain preprocessing, postprocessing, and validation logic that ought to happen regardless of why OpenTofu is asking each of these questions.
states
Package states contains the types that are used to represent OpenTofu states.
Package states contains the types that are used to represent OpenTofu states.
states/statefile
Package statefile deals with the file format used to serialize states for persistent storage and then deserialize them into memory again later.
Package statefile deals with the file format used to serialize states for persistent storage and then deserialize them into memory again later.
states/statemgr
Package statemgr defines the interfaces and some supporting functionality for "state managers", which are components responsible for writing state to some persistent storage and then later retrieving it.
Package statemgr defines the interfaces and some supporting functionality for "state managers", which are components responsible for writing state to some persistent storage and then later retrieving it.
terminal
Package terminal encapsulates some platform-specific logic for detecting if we're running in a terminal and, if so, properly configuring that terminal to meet the assumptions that the rest of OpenTofu makes.
Package terminal encapsulates some platform-specific logic for detecting if we're running in a terminal and, if so, properly configuring that terminal to meet the assumptions that the rest of OpenTofu makes.
tfdiags
Package tfdiags is a utility package for representing errors and warnings in a manner that allows us to produce good messages for the user.
Package tfdiags is a utility package for representing errors and warnings in a manner that allows us to produce good messages for the user.
tools
find-dep-upgrades command
find-dep-upgrades is a utility for finding the available upgrades for our Go module dependencies and proposing an order to upgrade them in so that as far as possible each upgrade touches only one upstream module at a time.
find-dep-upgrades is a utility for finding the available upgrades for our Go module dependencies and proposing an order to upgrade them in so that as far as possible each upgrade touches only one upstream module at a time.
find-pkg-importer command
find-pkg-importer is a utility for finding which packages in our dependency graph import a given package path.
find-pkg-importer is a utility for finding which packages in our dependency graph import a given package path.
loggraphdiff command
protobuf-compile command
protobuf-compile is a helper tool for running protoc against all of the .proto files in this repository using specific versions of protoc and protoc-gen-go, to ensure consistent results across all development environments.
protobuf-compile is a helper tool for running protoc against all of the .proto files in this repository using specific versions of protoc and protoc-gen-go, to ensure consistent results across all development environments.
selected-go-version command
selected-go-version determines which version of Go is currently selected in the go.mod file.
selected-go-version determines which version of Go is currently selected in the go.mod file.
survey-gen command
survey-gen generates stateless/survey.json, the machine-derived companion to live/SURVEY.md's hand-written per-type table (issue #25, increments 1 and 2).
survey-gen generates stateless/survey.json, the machine-derived companion to live/SURVEY.md's hand-written per-type table (issue #25, increments 1 and 2).
The version package provides a location to set the release versions for all packages to consume, without creating import cycles.
The version package provides a location to set the release versions for all packages to consume, without creating import cycles.
website

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL