Terraform Security · Terraform systems note
Terraform sensitive Does Not Mean Secret
Marking a value sensitive redacts normal CLI and UI output. It does not remove that value from Terraform state or saved plan files.
The word sensitive sounds stronger than the behavior it implements. Terraform uses the flag primarily to reduce accidental disclosure in normal human-facing output.
Redaction is presentation control
A sensitive variable or output is hidden in standard plan and apply rendering. Expressions derived from sensitive values usually inherit the marking, which prevents routine terminal and CI output from displaying them.
The value can still be in state
HashiCorp's documentation is explicit: sensitive values remain in state and saved plan files unless a newer ephemeral or write-only mechanism prevents persistence. Anyone who can read state may therefore be able to retrieve the value.
Automation can reveal it
Machine-readable or raw output is designed for tools, not visual redaction. Some JSON and raw-output workflows can expose values that normal display hides.
Backend permissions are security permissions
If state contains credentials, access to the backend is effectively access to those credentials. Encryption at rest protects storage media but does not replace authorization.
Use the right property
sensitive = hide from routine display
ephemeral = omit from plan/state where allowed
write-only = pass to a managed resource without persistingThose are different security properties. Treating sensitive as complete secret management leaves the most important artifact—the state—outside the threat model.