Originally published on DevToolHub.
OpenTofu 1.13.0 shipped on September 30, 2026. Officially-supported Windows on ARM64, a set of new functions, and upgrades to the state-encryption system it shipped ahead of Terraform. Here's what actually changed, verified against the official release changelog, plus a close look at state encryption itself — still the single biggest feature gap between OpenTofu and Terraform.
What's Actually New in OpenTofu 1.13
Per the official v1.13 changelog:
- Windows ARM64 is now officially supported. Previously unofficial or community-built; OpenTofu now ships official binaries for it.
-
New
convertfunction for type conversion, plus a set of functions with anassume...prefix that "give OpenTofu additional hints about what's expected as the final result of an unknown value" — useful for reducing unknown-value noise inplanoutput. -
Linting support (experimental), enabled with a
-lintflag on supported commands. - Symbol libraries (experimental) — a new capability to define reusable functions and types in hcl-lang based libraries.
- Unicode 17 for all string processing.
-
Plan files now include the provider schemas needed to render the plan, which matters if you consume
.tfplanfiles outside the CLI.
What Breaks in OpenTofu 1.13: Upgrade Notes
Three things worth checking before you upgrade a CI pipeline to 1.13:
-
The
winrmprovisioner connection type is removed. If anything in your config still uses WinRM for Windows provisioning, it's gone — OpenSSH is the supported path on modern Windows. -
base64gzipoutput changed. Results are "equivalent to but not equal to" previous output, due to optimized DEFLATE compression — don't diff old and newbase64gzipoutput expecting a byte match. - macOS 13 Ventura is now the minimum. And 1.13 is explicitly called out as the last release series shipping official 32-bit CPU builds.
None of these are exotic — they're the kind of thing that silently breaks a pipeline that hasn't been touched in a year.
The Feature Terraform Still Doesn't Have: State Encryption
OpenTofu's state and plan encryption isn't new to 1.13 — it shipped in an earlier release, and 1.13 extends it — but it remains the clearest structural difference between OpenTofu and Terraform. Per OpenTofu's encryption docs, it's stable, GA functionality, not experimental: "If an attacker were to gain access to your state file, they should not be able to read it and use the sensitive values (e.g. access keys) contained in the state file."
The config lives inside the terraform block:
terraform {
encryption {
key_provider "pbkdf2" "mykey" {
passphrase = var.state_passphrase # minimum 16 characters
}
method "aes_gcm" "mymethod" {
keys = key_provider.pbkdf2.mykey
}
state {
method = method.aes_gcm.mymethod
}
plan {
method = method.aes_gcm.mymethod
}
}
}
Supported key providers go beyond a passphrase: AWS KMS, GCP KMS, Azure Vault, OpenBao's Transit Secret Engine (compatible with HashiCorp Vault 1.14), and a generic external-program option for anything else. 1.13 specifically extended this: GCP KMS gained additional_authenticated_data support, AWS KMS gained an encryption_context field, and OpenBao gained an associated_data argument — all ways to bind the encryption to additional context so a stolen key alone isn't enough to decrypt a state file from a different environment.
Terraform has no equivalent built-in feature. State-at-rest protection in Terraform means encrypting the storage backend itself (S3 bucket encryption, for instance) — the state content isn't encrypted by Terraform's own logic the way OpenTofu's encryption block does it.
Two Quiet But Real Bug Fixes
Two fixes in 1.13 are worth knowing even if they don't affect your specific setup:
-
connection.script_pathescaping now prevents command injection. If a provisioner script path was ever built from a variable, this closes a real injection vector. - SSH proxy connection errors now report properly instead of crashing the run — previously a connection failure could crash rather than surface a readable error.
Should You Upgrade Now?
If you're not using WinRM provisioners and you're on macOS 13+ already, there's no real reason to hold back — the breaking changes are narrow and well-documented. If you're on an older macOS or a 32-bit build target, plan the migration now: 1.13 is the last release series supporting 32-bit builds, and there won't be a grace period on the next major bump.
For a broader look at whether OpenTofu is the right call over Terraform for your team at all — licensing, provider registry compatibility, migration steps — see our OpenTofu vs Terraform guide. And if Terragrunt is part of your stack, it works the same way on top of either engine — see our Terragrunt vs Terraform guide for what it actually adds. If you're keeping module docs in sync as part of that CI pipeline, our terraform-docs GitHub Action guide covers automating that.
Frequently Asked Questions
Q: When did OpenTofu 1.13 release?
A: September 30, 2026, per the official GitHub releases page.
Q: Does OpenTofu 1.13 support Windows on ARM64?
A: Yes, officially for the first time in this release, per the changelog.
Q: Is OpenTofu's state encryption a new feature in 1.13?
A: No — it's an existing, stable feature that 1.13 extended with additional key-provider options (GCP KMS authenticated data, AWS KMS encryption context, OpenBao associated data). The core encryption capability predates this release.
Q: Does Terraform have state encryption like OpenTofu?
A: Not as a built-in feature. Terraform relies on backend-level encryption (like S3 bucket encryption) rather than encrypting state file contents itself the way OpenTofu's encryption block does.
Q: What breaks when upgrading to OpenTofu 1.13?
A: The winrm provisioner connection type is removed, base64gzip output changed (not byte-identical to older output), and the minimum macOS version is now 13 Ventura.
Quick Summary:
- OpenTofu 1.13.0 released September 30, 2026: official Windows ARM64 support, new
convert/assume...functions, experimental linting and symbol libraries - Breaking on upgrade: WinRM provisioner removed,
base64gzipoutput changed, macOS 13+ required, last release with 32-bit builds - State and plan encryption remains OpenTofu's biggest structural advantage over Terraform — stable, GA, supports AWS/GCP/Azure KMS, OpenBao, and passphrase-based keys
- 1.13 extended encryption with additional-authenticated-data options for GCP KMS, AWS KMS, and OpenBao
- Two security-relevant bug fixes: a
connection.script_pathinjection vector closed, SSH proxy errors now report instead of crashing
Check the official OpenTofu changelog before pinning 1.13 in CI if you're running WinRM provisioners or 32-bit builds — those are the two changes actually capable of breaking a pipeline.
Top comments (0)