Skip to main content
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.otf-ubuntu-24-04-49b553f4-6923-43b3-92c7-024a3f70021f/image6_logolarge.png

otf on Ubuntu 24.04 LTS

by cloudimg

Self hosted OpenTofu and Terraform runs with a web UI, remote state and RBAC, by cloudimg

otf is an open source, self hosted alternative to Terraform Enterprise and HCP Terraform. It runs OpenTofu and Terraform plans and applies with a web interface, remote state management, run history and role based access control, so a team can collaborate on infrastructure as code on their own infrastructure instead of a hosted SaaS.

This cloudimg image installs otf 0.6.3 as a complete single node deployment on Ubuntu 24.04 LTS. The otfd daemon includes a built in server runner, so it executes remote runs on its own with no separate agent to deploy. It is backed by a local PostgreSQL database and fronted by nginx terminating TLS.

What is included

  • otf 0.6.3 and the OpenTofu 1.12.4 CLI, with a pre warmed engine cache so the first run does not wait on a download
  • PostgreSQL backing otf state, runs and RBAC, bound to loopback
  • nginx terminating TLS on port 443 with an automatic redirect from port 80
  • otfd running as a dedicated unprivileged system user, bound to loopback behind nginx
  • A per VM site admin token, application secret and database password generated on first boot into a root only credentials file
  • otfd, PostgreSQL and nginx as systemd units, enabled and active

Secure by default

Nothing is baked into the image. On the first boot of every VM, otf generates the PostgreSQL role password, the otfd encryption secret and the site admin token fresh and unique, regenerates the TLS certificate for the VM address, and writes the token to a root only credentials file. There is no default login. VCS integration with GitHub or GitLab is configured by you at runtime and is never baked in.

Run infrastructure as code with no VCS required

Sign in to the web UI with the site admin token, or drive runs from your workstation with the OpenTofu or Terraform CLI driven remote workflow: point a cloud block at your otf server and plans and applies execute on the daemon, with the streamed output, run status and state all recorded in the workspace.

Licensing is MPL-2.0 and free. The cloudimg charge of 0.04 US dollars per vCPU hour covers packaging, security patching, image maintenance and 24/7 expert support. Recommended size: Standard_B2s to start. Prerequisites: an Azure subscription, a VNet and an SSH key. NSG inbound: port 22 for SSH and port 443 for the web UI and API.

At a glance

https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.otf-ubuntu-24-04-49b553f4-6923-43b3-92c7-024a3f70021f/image5_screenshot01.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.otf-ubuntu-24-04-49b553f4-6923-43b3-92c7-024a3f70021f/image7_screenshot02.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.otf-ubuntu-24-04-49b553f4-6923-43b3-92c7-024a3f70021f/image1_screenshot03.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.otf-ubuntu-24-04-49b553f4-6923-43b3-92c7-024a3f70021f/image2_screenshot04.png
English (United States)
Your Privacy Choices Opt-Out Icon Your Privacy Choices
Consumer Health Privacy Sitemap Contact Us Privacy & Cookies Terms of Use Trademarks About our ads Manage cookies