Marking a Terraform input or output sensitive hides its value from ordinary command display. It does not generally remove the value from state or a saved plan. The backend, runner disk, artifact store, and anyone who can read snapshots may therefore gain access to credentials or private configuration. Avoiding a value in console output is a presentation control; containing or omitting it from persistent artifacts is a separate design decision.
Terraform state secrets: redaction is not removal
Operational decision
A receipt service bootstrap uses a database password. Trace where that password enters the run: CI secret store, environment, provider request, plan file, state snapshot, logs, support bundle, and backup. Restrict backend read and write roles separately, encrypt stored state and backup copies, set short retention for saved plans, and avoid attaching plan binaries to broad-access tickets. The fragment shows a sensitive variable for output redaction; it is not a promise that state is secret-free. If the supported Terraform version and provider allow an ephemeral input or write-only argument for this exact use, test that path with a disposable credential and inspect both plan and state. Rotate a test password, then verify old state versions and backup policies account for the retired value. Redact values from diagnostics before sharing an incident record.
variable "receipt_db_password" {
type = string
sensitive = true
}Cost and verification
Encryption and narrow access add key-management and audit overhead, but keeping saved plans indefinitely grows the exposure window. A remote backend may charge for state versions, encryption operations, and access logs. Removing a secret from current configuration does not delete it from old snapshots. Count principals with state-read rights, plan artifact lifetime, successful access reviews, and rotation completion across retained copies. The best reduction is to keep the credential out of Terraform-managed attributes where the provider and workflow permit it.
Common Mistakes
- Do not commit state or saved plan files to source control.
- Do not treat a sensitive flag as state encryption or omission.
- Do not paste raw plan JSON into a widely shared ticket.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- Terraform state: shared ownership and safe plans
- Secret rotation rollout: update the issuer, consumer, and active connections
- CI OIDC claims: bind cloud access to the exact deployment job
- Software supply chain: SBOM and provenance at admission
Practice and check
- Project: hand off Terraform-managed infrastructure without a replacement surprise
- DevOps Terraform ownership decisions
Continue with: Infrastructure prompts: quarantine state secrets and drift.
