4 ms·
You don't want to store secrets in state files. Imagine you run a CI/CD system where you run terraform plan. Now secrets is all public.
by yeukhon 8y ago
You don't want to store secrets in state files. Imagine you run a CI/CD system where you run terraform plan. Now secrets is all public.
- toomuchtodo 8y agohttps://github.com/hashicorp/terraform/issues/516 https://github.com/hashicorp/terraform/issues/516 TLDR: Terraform should use Vault for storing secrets in state, but does not support it yet. (it is occasionally unavoidable storing secrets in state due to resources orchestrated)
- zimbatm 8y agoThat's fine. Secrets are market as "sensitive" and not displayed in the plan output.