What choudoufu is, how to run it, and the evidence behind each claim it makes. Every figure on these pages names its fixture and its commit.
Documentation
choudoufu is OpenTofu with one thing changed: what you own is written on the
resources themselves, as a marker your platform’s access control can read,
and the state file becomes a cache you may delete. Almost everything else in
the fork is stock OpenTofu, unmodified. A configuration with no live block
gets stock behaviour exactly, measured at the same number of AWS API calls
as tofu plan
(#588).
Start here
| If you want to | Read |
|---|---|
| Understand it in five minutes | What it is |
| Watch it work, with Docker and no AWS account | Tutorial |
| Start a new estate | Start a new estate |
| Bring in resources you already run | Migrate an existing estate |
| Know what you must create first | What you set up by hand |
| Check your own configuration | Check a configuration |
The commands you will use
choudoufu init, plan and apply work as they do in OpenTofu, and with a
live block present they use the live backend. Three commands are new.
| Command | What it does |
|---|---|
choudoufu live-import | Bulk migration: reads a stock state file once, verifies each entry against the live resource, and writes a marker on everything that verifies |
choudoufu live-mv <old> <new> | Renames a resource by rewriting its marker, with an empty plan on both sides |
choudoufu live-check | Says what in a configuration would be refused, before anything runs |
The promise, and where it is proven
If OpenTofu runs an estate, choudoufu runs it too: an equal plan, or a refusal
this documentation names in advance. Anything else is a defect.
Plan fidelity states the
contract, and the claims are where it is
proven: one runnable scenario per promise, each with an arm that breaks it on
purpose and must be caught. just smoke import runs one in about two minutes.
| Evidence | What it is |
|---|---|
| The claims | Runnable scenarios, one per claim, each with an arm that breaks it on purpose. This is the proof surface |
| What a plan costs | The measured cost of a plan, with links to every figure behind it |
| Resource tier lookup | Every provider resource type, and what recovers its identity |
live/LIMITATIONS.md | Every construct that is refused, the rule that refuses it, and the remedy |
| How close AWS is | The contributors’ regression net: real-world configurations run through every stage beside stock OpenTofu, re-measured before a release |
The stock base
4194 files diverge from stock OpenTofu 1.13.0 at fork point 2b6193043d ("Bump version v1.13.0"). 2896 of them sit under 5th fork-owned roots; the remaining 1298 are outside those roots, each named with its own one-line reason in live/forkdiff_test.go's guard rather than assumed stock. A further 1176 files (not counted above) change only the Go module import path, github.com/opentofu/opentofu to github.com/intentius/choudoufu, with no other line touched - the mechanical cost of forking a Go module, not a fact about this fork's own surface.
Counted at choudoufu commit 84a2fa6abf on 2026-10-04T01:29:24Z. Run go run ./tools/forkdiff-gen to recount against the current HEAD before trusting this against a newer commit.
| Root | Files |
|---|---|
internal/live/ | 1692 |
tools/ | 488 |
live/ | 551 |
site/ | 129 |
.github/ | 36 |
| other (individually justified) | 1298 |
| Total | 4194 |
Full file-by-file detail: live/fork-surface.json, regenerated by go run ./tools/forkdiff-gen.
Everything outside those fork-owned roots is stock OpenTofu, unmodified beyond the module path it is built under. Compatibility reference covers what running under this fork changes about how a configuration behaves.