← Terraform: plan changes and operate infrastructure
05 / 6 · 40 MIN

Secrets and controls

Distinguish redaction, persistence, and protection against destructive changes.

Concept and mechanism

The sensitive argument reduces exposure in ordinary presentation but does not automatically remove values from state or saved plans. A pipeline archiving those artifacts must treat access, retention, and logs as part of protection. Output using raw or JSON formats may reveal values hidden by ordinary output. Ephemeral and write-only arguments can avoid value persistence in supported contexts with version and provider requirements. Do not assume adding one keyword to any attribute removes every secret copy. Connect each credential to its necessary use and avoid passing it into files, reports, or logs that do not need it.

Guided application

Lifecycle controls also have limits. prevent_destroy can reject a destructive plan while present in configuration, but removing the entire resource block removes that declared protection. It does not prevent operations performed directly through the provider. create_before_destroy changes replacement order without guaranteeing available names, quota, or coexistence of versions. ignore_changes may allow shared ownership of attributes but can also hide drift when scoped too broadly. In a fictional scenario, a team wants to ignore every difference to clean up a production plan. First identify who manages each attribute and which divergence is authorized. When a condition must block an operation, select validation or policy with blocking semantics; a warning-only check cannot satisfy that requirement alone.

IN PRACTICE

A value hidden in the terminal may remain in a saved plan accessible to the whole team.

Common pitfalls

Sensitive as encryption; prevent_destroy after removing the block; ignore_changes as drift resolution.

Related topics: Configuration and dependencies · Plans and validation · State and collaboration

Take this idea with you

Assess each control’s actual effect on data and operations.

Create account

Reference: Sensitive ephemeral and write-only values · Terraform v1.16 concepts; official documentation consulted 2026-09-30; provider and backend capabilities must be confirmed