Platform

AWS

Every headline stage passes on every core estate against the pinned emulator, and two estates have run on a real account.

Every resource this fork manages carries two tags, tofu-estate and tofu-address, written on the create call. The tags are the identity the next plan binds to and the attribute your IAM conditions on. Everything else is stock OpenTofu.

  1. Adopt Bring resources that already run under management, one marker at a time, with no state migration.
  2. Gate Your IAM is the whole permission model: conditions on the ownership tag decide who may act on what, per resource.
  3. Operate Rename, remove, scale, review a plan before applying it, and run the whole thing from CI.
  4. Compatibility What live-check refuses in a real configuration, and why each refusal exists.
  5. Proof Which claims hold on AWS, how many real estates clear every stage, what a plan costs against stock, and how to run any of it yourself.

Everything on these five pages links down into the evidence: the runnable claims, the gauntlet, the measurements, and the per-type lookup.