Using Locally with the OpenTofu AzAPI Provider

Preview

Sign in during Public Preview to get the Team plan free, plus an early-adopter discount when we launch. Sign in

Using Locally with the OpenTofu AzAPI Provider

OpenTofu is an infrastructure as code tool which uses providers to interact with different clouds - and the Azure/azapi provider lets you call any Azure REST API directly.

This guide was tested using the following versions of OpenTofu and the Azure/azapi provider, but newer versions should work too:

  • tofu - v1.12.6
  • Azure/azapi provider - v2.13.0

Provisioning a Resource Group

In this example we're going to provision a Resource Group within the First Subscription. We first need to define a provider block for the Azure/azapi provider in a file named main.tf. As the provider isn't published under the hashicorp namespace, we also need to tell OpenTofu where to find it in a required_providers block:

terraform {
  required_providers {
    azapi = {
      source = "Azure/azapi"
    }
  }
}

provider "azapi" {}

Note that we haven't specified any credentials for the Azure/azapi provider, as Locally will automatically configure the provider for you to run against Locally rather than Azure when you run locally run tofu [command].

Next we need to add the OpenTofu resource to provision a Resource Group - in this case with the name rg-from-tofu in the location berlin:

terraform {
  required_providers {
    azapi = {
      source = "Azure/azapi"
    }
  }
}

provider "azapi" {}

data "azapi_client_config" "current" {}

resource "azapi_resource" "example" {
  type      = "Microsoft.Resources/resourceGroups@2025-04-01"
  name      = "rg-from-tofu"
  location  = "berlin"
  parent_id = "/subscriptions/${data.azapi_client_config.current.subscription_id}"
}

Rather than a dedicated resource for each type, the Azure/azapi provider uses a single azapi_resource resource: the type field names the Azure resource type and the API version to use, and parent_id is the ID of the resource it's created within - here the Subscription, which the azapi_client_config data source looks up for us. Locally needs to support the API version you specify, as it would in Azure.

Now that we've created our OpenTofu configuration, we need to download the Azure/azapi provider by running:

$ tofu init

If Locally isn't already running, we'll need to start it by running:

$ locally build

At which point we can deploy this OpenTofu configuration against Locally by running:

$ locally run tofu apply

Once that's applied, if we open the First Subscription within the Locally Dashboard, and view the Resource Groups then we should see our newly created Resource Group.

Next steps

If you'd rather use a dedicated resource for each Azure resource type, see the AzureRM guide. To run tofu apply against Locally in your pipeline, see Using Locally in CI.

Should you encounter any issues, please take a look at the troubleshooting section.

Working examples of using the Azure/azapi provider with Locally - from Storage Accounts and Key Vaults to Virtual Machines - are available in the opentofu directory of the locallybuild/examples repository, and you can find more examples of how to use OpenTofu with Locally in the Examples in the Documentation.

Preview

Sign in during Public Preview to get the Team plan free, plus an early-adopter discount when we launch. Sign in

A local cloud for you and your agents.

Your Azure infrastructure, running on your machine. Deploy in seconds, break things freely, and ship to Azure when you're ready.