Infrastructure agent · governed by the plan

Control your infrastructure AI with Terraform plans.

Turf is a drop-in replacement for Terraform® that lets an AI agent operate your infrastructure — governed by the artifact your team already trusts. Every change is planned, visible, and approved before it happens. Nothing runs off-plan.

$ brew install turfbuild/tap/turf
Terraform HCL & modules OpenTofu providers MCP-native Local AI models and GPU clouds
plan — 1 effect · 3 deferred phase 1
+ kind_cluster.demo planned
+ helm_release.cert_manager deferred · cluster not yet known
+ helm_release.external_dns deferred · cluster not yet known
+ kubernetes_manifest.issuer deferred · CRD not yet known
⏸ awaiting your approval
✓ converged — 4 applied · 3 phases · 0 drift

the Terraform plan becomes the agent’s TODO list — worked one effect at a time

Nobody wants to hand an AI the keys to prod. Good.

That instinct is correct — and it’s exactly the problem Turf is built around.

01 · The fear is rational

Unconstrained agents are click-ops at machine speed

An agent holding raw cloud credentials mutates infrastructure with no diff, no review, and no state — the same failure mode as console click-ops, only faster.

02 · The reframe

Turf doesn’t put AI in control — it puts AI under control

The governing instrument is the industry-standard Terraform plan. Turf constrains the agent to work in terms of plans and their effects. Nothing runs off-plan.

03 · What you get

Visibility · Governance · Flexibility

Every proposed change is visible before it happens, gated on your approval, and applied one effect at a time — with room to pause, back up, or re-plan.

The plan is the governor.

AI does the work. The plan keeps it honest. Here’s the loop every Turf change goes through.

step 1

Declare intent

Natural language, a diagram, or Terraform HCL — desired state always lands in a reviewable configuration directory.

step 2

Plan

Turf produces a standard Terraform plan. Its effects become the agent’s TODO list — it can’t act outside them.

step 3 · the gate

You approve

Humans and policy checks sign off on the plan. Nothing crosses the gate without approval and clearance.

step 4

Apply, one effect at a time

There is deliberately no apply_all. Between effects the agent can pause, take a backup, or ask for help.

step 5

Replan & converge

Deferred work — the CRD that didn’t exist yet — loops back through a fresh plan until the graph settles.

step 5 feeds back into step 2 — every round crosses the approval gate again

Turf loves HCL.

Turf is a drop-in replacement — your configs, your modules, your providers, your mental model. With agentic superpowers on top.

Turf is an independent product built on the OpenTofu framework — not affiliated with or endorsed by HashiCorp.

  • Full Terraform HCL — the entire expression language and function library, on the OpenTofu framework.
  • Module registry — build on battle-tested community modules, from AVM on down.
  • OpenTofu providers — the whole provider ecosystem, unmodified.
  • Terraform Actions — the 1.14 action model, carried on Turf’s fork.ahead of OpenTofu
  • Deferred changes — a first-class, agent-resolved convergence loop, no experimental flags.ahead of OpenTofu
  • Stacks-class multi-environment deploys — one configuration, fanned out across workspaces, converged by phases.coming soon
Radically honest compatibility. Where a construct isn’t supported yet, Turf refuses loudly — it never silently mis-plans. Every gap is published and labeled coming soon on the matrix.
See the full compatibility matrix →

cluster → operators → CRDs → workloads. no -target hacks, no two-stage applies.

One command. The whole stack converges.

turf up iterates plan → approve → apply until your infrastructure matches intent — including the layers Terraform makes you deploy in awkward stages.

Flagship

Kubernetes stacks

Cluster + addons (operators, CRDs) + workloads (manifests, Helm charts) in one converging deploy. Deferrals bridge the “CRD doesn’t exist yet” gap natively.

Fits your stack

Turf loves TACOs

Remote state backends, policy checks, private module registries, org skills — Turf slots into your Terraform automation platform. Complement, not rip-and-replace.

run it yourself →
Day-2, governed

Planned day-2 operations

Governance isn’t just for deployments. Failovers, rotations, upgrades run as Terraform Actions — planned, approved, and executed under the same gate as everything else.

run it yourself →

Built for the hard parts.

Govern the agent

Plan-gated approval, effects as a TODO list. The agent acts only with approval and clearance.

Deploy layered stacks

turf up converges the whole graph across phases — with Actions and first-class deferrals that OpenTofu doesn’t have.

§

Enforce policy at the gate

Compose policy into plan approval — OPA policy checks, cloud best practices — through your security vendors’ MCP servers. Org- and provider-specific skills encode your rules.

provider skills — coming soon
±

Protect stateful things

A second set of eyes with semantic knowledge: Turf knows replacing a stateful resource destroys data — and takes backups, seeks approval, or proposes a safer plan.

+

Skip the HCL classes

Start with plots — agent-authored, reviewable HCL. Build on registry modules. Promote to idiomatic .tf when you’re ready to shift left.

Compose your own loop

GitOps, planning, approval, and execution are building blocks — compose them in novel ways. Plan locally, approve in CI, commit what converged — not one rigid commit → PR → plan → apply pipeline.

planfile round-trip — coming soon

Runs where you work. On any model — even yours.

Interfaces

One engine, many surfaces — Turf is an MCP server first.

Any MCP clientClaude Desktop & Code, cagent, kagent — stdio or HTTP
supported
CLI & TUIthe Turf CLI: chat, up, destroy, exec
supported
Kubernetes, in-clusterdeployed as an agent via kagent
supported
Remote agent · A2Adrive Turf from other agents over the network
coming soon

Models

Model flexibility is a governance feature, not a checkbox.

Hosted frontier modelsAnthropic, Google, and OpenAI-compatible endpoints
supported
Local modelsturf --model dmr/ai/qwen3 — no API key, no cost
supported
Private GPU cloudsvLLM, LM Studio, gateways via --base-url
supported

Your infrastructure intent never has to leave your network.

Help us build it. On your turf.

We’re looking for design partners — teams working on layered infrastructure, policy gates, and AI under real governance constraints. Partner with us early: white-glove onboarding, direct roadmap influence, and discounted commercial terms while we build together.