Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Terraform state secrets: redaction is not removal

Last updated: 7 Oct 20266 min read
tutorial
AdvancedBy AITrove Editorial

Marking a Terraform input or output sensitive hides its value from ordinary command display. It does not generally remove the value from state or a saved plan. The backend, runner disk, artifact store, and anyone who can read snapshots may therefore gain access to credentials or private configuration. Avoiding a value in console output is a presentation control; containing or omitting it from persistent artifacts is a separate design decision.

Operational decision

A receipt service bootstrap uses a database password. Trace where that password enters the run: CI secret store, environment, provider request, plan file, state snapshot, logs, support bundle, and backup. Restrict backend read and write roles separately, encrypt stored state and backup copies, set short retention for saved plans, and avoid attaching plan binaries to broad-access tickets. The fragment shows a sensitive variable for output redaction; it is not a promise that state is secret-free. If the supported Terraform version and provider allow an ephemeral input or write-only argument for this exact use, test that path with a disposable credential and inspect both plan and state. Rotate a test password, then verify old state versions and backup policies account for the retired value. Redact values from diagnostics before sharing an incident record.

hcl
variable "receipt_db_password" {
  type      = string
  sensitive = true
}

Cost and verification

Encryption and narrow access add key-management and audit overhead, but keeping saved plans indefinitely grows the exposure window. A remote backend may charge for state versions, encryption operations, and access logs. Removing a secret from current configuration does not delete it from old snapshots. Count principals with state-read rights, plan artifact lifetime, successful access reviews, and rotation completion across retained copies. The best reduction is to keep the credential out of Terraform-managed attributes where the provider and workflow permit it.

Common Mistakes

  • Do not commit state or saved plan files to source control.
  • Do not treat a sensitive flag as state encryption or omission.
  • Do not paste raw plan JSON into a widely shared ticket.

Connected lessons

Practice and check

Continue with: Infrastructure prompts: quarantine state secrets and drift.

devops
operations
Storage details