Terraform sensitive Does Not Mean Secret
Marking a value sensitive redacts normal CLI and UI output. It does not remove that value from Terraform state or saved plan files.
Marking a value sensitive redacts normal CLI and UI output. It does not remove that value from Terraform state or saved plan files.
Operational confusion falls when desired configuration, mutable data and confidential values stop competing to be one source of truth.
Production readiness has to treat leaked credentials as compromised even after the file disappears from the latest commit.
OpenBao adds identity, policy, versioning, leases and audit around secrets instead of merely moving plaintext to a different file.
How to think about credentials when application manifests are intentionally stored in Git.
Separating secrets from source control creates a recovery dependency that must be documented and tested.
Moving alert delivery to authenticated self-hosted ntfy introduced a publisher token that the alert-sink needs at runtime.
Per-device PBX credentials should be provisioned after identity is established, not cloned into every unit.
Copying every application database password into the observability stack would have expanded the secret blast radius just to collect metrics.
Terraform 1.10+ ephemeral values and 1.11+ write-only arguments let temporary values pass through a run without being persisted in state or plan artifacts when providers support them.
A service can be allowed through one protected directory without being allowed to inspect the directory itself.
Most operational confusion came from mixing desired configuration, live state and credentials into the same place.