Deploying an existing OpenTofu AzureRM Configuration against Locally

Preview

Sign in during Public Preview to get the Team plan free, plus an early-adopter discount when we launch. Sign in

Deploying an existing OpenTofu AzureRM Configuration against Locally

It's possible to update an existing OpenTofu configuration that uses the opentofu/azurerm provider to work with Locally in addition to Azure, with the changes necessary being fairly minimal in most cases.

The opentofu/azurerm provider can source credentials either using Environment Variables, explicit configuration in the provider block - or from the environment where it's being run (such as from the Azure CLI, Managed Identity etc).

If you're new to using Locally with OpenTofu, you may want to start with the Getting Started AzureRM guide first.

Note

Using Claude Code or another agent? Install the Locally skills with npx skills add locallybuild/skills, then ask your agent to make your OpenTofu configuration work against both Locally and Azure. The locally-adapt skill knows the changes below and makes them for you.

Notes

  • Locally intentionally uses different locations to Azure for safety reasons, so that you can be sure you're targeting Locally rather than Azure. If you're hard-coding the location for resources within your OpenTofu configuration, we'd recommend using an OpenTofu Variable for the location.
  • Similarly, if you're hard-coding the Subscription ID for resources within your OpenTofu configuration, Locally will automatically set some OpenTofu Variables containing the Subscription ID, so you'll need to use those values in your OpenTofu configuration.

Variables set by Locally

When run through locally run, Locally also sets the following OpenTofu variables, which you can use in your configuration:

Variable Value
environment_is_locally true - so a configuration can tell it's running against Locally rather than Azure.
location A region from this installation's location set (for example berlin).
primary_subscription_id The ID of the Subscription being targeted (by default, the first Subscription alphabetically).
secondary_subscription_id The ID of another Subscription, for configurations that span more than one.
ternary_subscription_id The ID of a third Subscription.
locally_tls_certificate_path The path to the TLS certificate Locally serves its endpoints with.
locally_tls_certificate_key_path The path to that certificate's private key.

You only need to declare the variables you use - and giving each one a default means the same configuration still works when it's run against Azure. See Automatic Configuration for examples.

When Credentials are sourced from Environment Variables / the Azure CLI

If you configure the opentofu/azurerm provider using either environment variables or from the Azure CLI, meaning that your provider block looks similar to below:

provider "azurerm" {
  features {}
}

Then Locally should be able to Automatically Configure the opentofu/azurerm provider for you to run against Locally rather than Azure - meaning you should be able to run:

$ locally run tofu plan

When specifying the Subscription ID in the provider block

Alternatively, if you specify the subscription to run against within the provider block using an OpenTofu Variable, then you will need to consume the OpenTofu Variables set by locally run and use those in the provider block as shown below:

variable "primary_subscription_id" {
  type        = string
  description = "The primary subscription ID"
}

provider "azurerm" {
  subscription_id = var.primary_subscription_id

  features {}
}

In this case the values for client_id, client_secret and tenant_id are automatically set via environment variables when OpenTofu is run via locally run. After using this variable within the provider block, you should be able to run OpenTofu against Locally by running:

$ locally run tofu plan

Next steps

Since Locally uses its own region names, Locations & Regions lists the ones to use for your location variable. To run tofu plan against Locally in your pipeline, see Using Locally in CI.

Should you encounter any issues, please take a look at the troubleshooting section.

You can find more examples of how to use OpenTofu with Locally in the Examples in the Documentation.

Preview

Sign in during Public Preview to get the Team plan free, plus an early-adopter discount when we launch. Sign in

A local cloud for you and your agents.

Your Azure infrastructure, running on your machine. Deploy in seconds, break things freely, and ship to Azure when you're ready.