AI-native infrastructure engine · governed by the plan

The infrastructure engine built for AI agents.

Turf plans, applies, and converges Terraform®-compatible infrastructure at any scale — driven by agents in natural language or HCL. Every change is planned, visible, and approved before it happens. Nothing runs off-plan.

$ brew install turfbuild/tap/turf
Terraform HCL & modules OpenTofu providers MCP-native Local AI models and GPU clouds
plan — 1 effect · 3 deferred phase 1
+ kind_cluster.demo planned
+ helm_release.cert_manager deferred · cluster not yet known
+ helm_release.external_dns deferred · cluster not yet known
+ kubernetes_manifest.issuer deferred · CRD not yet known
⏸ awaiting your approval
✓ converged — 4 applied · 3 phases · 0 drift

the Terraform plan becomes the agent’s TODO list — worked one effect at a time

One engine. Five ways to put it to work.

From a laptop experiment to a datacenter build-out — the same plans, the same gate, the same converging loop.

Scale

Terraform at 10x scale

Thousands of resources per stack. Turf’s durable, scale-out engine parallelizes provider operations until the cloud API — not the tool — is the ceiling. Run a Kubernetes cluster as your control plane for infrastructure ops, or run it all on a laptop.

Datacenter

Datacenter automation

Orchestrate the build-out: servers, networks, Kubernetes, workloads. Terraform, Ansible, and Helm converge in one governed run — powered by Terraform Actions, which Turf runs and stock OpenTofu doesn’t — and day-2 operations are plannable too.

Embedded

Autonomous products

Turf is a smart installation tool for your AI product: it automates the infrastructure layer — in your cloud or your customer’s account — from any mix of HCL and natural language. Deploy an enterprise data lake from a reference architecture; Turf auto-detects and heals drift.

talk to us →
Governed

AI under control

Every change is planned, visible, and approved before it happens. The Terraform plan becomes the agent’s TODO list — worked one effect at a time, with a gate between every round. Nothing runs off-plan.

see how it works →
MCP-native

Agentic infrastructure-as-code

Turf is an MCP server at its core. Drive it from Claude Code, Claude Desktop, Codex, or VS Code — natural language or HCL, or both — to plan and carry out any sort of infrastructure change.

get started →

Nobody wants to hand an AI the keys to prod. Good.

That instinct is correct — and it’s exactly the problem Turf is built around.

01 · The fear is rational

Unconstrained agents are click-ops at machine speed

An agent holding raw cloud credentials mutates infrastructure with no diff, no review, and no state — the same failure mode as console click-ops, only faster.

02 · The reframe

Turf doesn’t put AI in control — it puts AI under control

The governing instrument is the industry-standard Terraform plan. Turf constrains the agent to work in terms of plans and their effects. Nothing runs off-plan.

03 · What you get

Visibility · Governance · Flexibility

Every proposed change is visible before it happens, gated on your approval, and applied one effect at a time — with room to pause, back up, or re-plan.

The plan is the governor.

AI does the work. The plan keeps it honest. Here’s the loop every Turf change goes through.

step 1

Declare intent

Natural language, a diagram, or Terraform HCL — desired state always lands in a reviewable configuration directory.

step 2

Plan

Turf produces a standard Terraform plan. Its effects become the agent’s TODO list — it can’t act outside them.

step 3 · the gate

You approve

Humans and policy checks sign off on the plan. Nothing crosses the gate without approval and clearance.

step 4

Apply, one effect at a time

There is deliberately no apply_all. Between effects the agent can pause, take a backup, or ask for help.

step 5

Replan & converge

Deferred work — the CRD that didn’t exist yet — loops back through a fresh plan until the graph settles.

step 5 feeds back into step 2 — every round crosses the approval gate again

Turf loves HCL.

Your configs, your modules, your providers, your mental model — Turf runs them unchanged. With agentic superpowers on top.

Turf is an independent product built on the OpenTofu framework — not affiliated with or endorsed by HashiCorp.

  • Full Terraform HCL — the entire expression language and function library, on the OpenTofu framework.
  • Module registry — build on battle-tested community modules, from AVM on down.
  • OpenTofu providers — the whole provider ecosystem, unmodified.
  • Brownfield adoption — an import block brings existing infrastructure under management, reviewed as a real diff before anything changes.
  • Terraform Actions — the 1.14 action model, carried on Turf’s fork.ahead of OpenTofu
  • Deferred changes — a first-class, agent-resolved convergence loop, no experimental flags.ahead of OpenTofu
  • Stacks-class multi-environment deploys — one configuration, fanned out across workspaces, converged by phases.coming soon
Radically honest compatibility. Where a construct isn’t supported yet, Turf refuses loudly — it never silently mis-plans. Every gap is published and labeled coming soon on the matrix.
See the full compatibility matrix →

cluster → operators → CRDs → workloads. no -target hacks, no two-stage applies.

Built for the hard parts.

Govern the agent

Plan-gated approval, effects as a TODO list. The agent acts only with approval and clearance.

Deploy layered stacks

turf up converges the whole graph across phases — with Actions and first-class deferrals that OpenTofu doesn’t have.

§

Enforce policy at the gate

Compose policy into plan approval — OPA policy checks, cloud best practices — through your security vendors’ MCP servers. Org- and provider-specific skills encode your rules.

provider skills — coming soon
±

Protect stateful things

A second set of eyes with semantic knowledge: Turf knows replacing a stateful resource destroys data — and takes backups, seeks approval, or proposes a safer plan.

+

Skip the HCL classes

Start with plots — agent-authored, reviewable HCL. Build on registry modules. Promote to idiomatic .tf when you’re ready to shift left.

Compose your own loop

GitOps, planning, approval, and execution are building blocks — compose them in novel ways. Plan locally, approve in CI, commit what converged — not one rigid commit → PR → plan → apply pipeline.

planfile round-trip — coming soon

Runs where you work. On any model — even yours.

Interfaces

One engine, many surfaces — Turf is an MCP server first.

Any MCP clientClaude Desktop & Code, cagent, kagent — stdio or HTTP
supported
CLI & TUIthe Turf CLI: chat, up, destroy, exec
supported
Kubernetes, in-clusterdeployed as an agent via kagent
supported
Remote agent · A2Adrive Turf from other agents over the network
coming soon

Models

Model flexibility is a governance feature, not a checkbox.

Hosted frontier modelsAnthropic, Google, and OpenAI-compatible endpoints
supported
Local modelsturf --model dmr/ai/qwen3 — no API key, no cost
supported
Private GPU cloudsvLLM, LM Studio, gateways via --base-url
supported

Your infrastructure intent never has to leave your network.

Help us build it. On your turf.

We’re looking for design partners — teams working on layered infrastructure, policy gates, and AI under real governance constraints. Partner with us early: white-glove onboarding, direct roadmap influence, and discounted commercial terms while we build together.