Cluster API Provider Terraform
Your modules are the provider.
Turn the Terraform and OpenTofu you already trust into Kubernetes clusters, on any platform. No Go controller to write. No second copy of your infrastructure logic to keep in sync.
Try the quick start Read the docs
- Cluster API infrastructure provider
- OpenTofu
- Terraform
- Apache 2.0
Stop writing a new provider for every platform.
Cluster API needs an infrastructure provider for every platform you run on, and you already have the Terraform that builds it. CAPTF makes that module the provider.
Why you should reach for CAPTF
Any platform
If Terraform or OpenTofu can provision it, CAPTF can build a cluster on it: public cloud, private cloud, bare metal, or the libvirt box under your desk.
Zero Go
Your module is the provider. CAPTF runs it, reads its outputs from state, and reconciles
Cluster,MachineandMachinePoolagainst them.The whole Cluster API
Clusters, machines and autoscaled machine pools. ClusterClass. Kubeadm and RKE2 control planes.
clusterctl move.State that lives with the cluster
Terraform state is stored in Kubernetes Secrets next to the object it belongs to, and backed up. There’s no bucket to create and no backend to wire up.
Drift, caught
Scheduled drift checks and your module’s own health outputs feed Cluster API conditions and machine remediation, so problems come to you.
Guardrails built in
Plan approval before apply. Credentials scoped to the namespaces you name. Locked-down Jobs, with privilege escalation rejected at admission.
Lint before you ship
tfcapi-lintchecks your module and its image against the contract before a cluster ever sees them.Operable on day one
Prometheus metrics and alerts, documented conditions and events, and runbooks for failing Jobs, stuck destroys, stale locks and more.
A supply chain you can audit
Multi-arch OpenTofu and Terraform base images, rebuilt weekly, shipped with SBOMs and provenance attestations.
From module to cluster in two moves
Package the module you already have on one of our base images, using its example
Dockerfile:podman build --build-arg ROLE=machine -t registry.example.com/acme/machine:v1.0.0 .Then point Cluster API at it:
apiVersion: infrastructure.cluster.x-k8s.io/v1alpha1 kind: TerraformMachineTemplate metadata: name: acme spec: template: spec: source: image: registry.example.com/acme/machine:v1.0.0
That's the core of it: every machine stamped from that template is now built by your module. Your First Module walks through it end to end.