Skip to content

Deep Dives

Terraform, OpenTofu and the 1 MiB Secret

Every CAPTF module image carries one of two runtimes, Terraform or OpenTofu, and both keep their state in Kubernetes Secrets through a backend with the same name: kubernetes. Same labels, same lock, same gzip payload, and for most objects the same bytes. The two part ways at one number: 1 MiB, the most data the API server lets a Secret hold. Terraform splits state that grows past it across more Secrets. OpenTofu does not, and an apply that crosses the line loses the record of what it just created.

This post walks through both write paths, what CAPTF does with each, and how to pick a runtime before the difference matters.