Sensitive output values in Terraform - Time & Space Complexity
Start learning this pattern below
Jump into concepts and practice - no test required
We want to understand how marking output values as sensitive affects the time it takes Terraform to run.
Specifically, how does this choice impact the number of operations Terraform performs?
Analyze the time complexity of marking outputs as sensitive in Terraform.
output "db_password" {
value = aws_db_instance.example.password
sensitive = true
}
output "db_endpoint" {
value = aws_db_instance.example.endpoint
}
This code marks the database password output as sensitive, hiding it from normal display, while the endpoint is shown normally.
Terraform reads and processes each output value during plan and apply.
- Primary operation: Reading and optionally masking output values.
- How many times: Once per output defined in the configuration.
As the number of outputs increases, Terraform processes each output once.
| Input Size (n) | Approx. Api Calls/Operations |
|---|---|
| 10 | 10 output processing steps |
| 100 | 100 output processing steps |
| 1000 | 1000 output processing steps |
Pattern observation: The work grows directly with the number of outputs.
Time Complexity: O(n)
This means the time to process outputs grows linearly with how many outputs you have.
[X] Wrong: "Marking outputs as sensitive makes Terraform run much slower because it hides values."
[OK] Correct: Marking outputs sensitive only changes display behavior; Terraform still processes each output once, so the time grows linearly, not slower or faster.
Understanding how output configurations affect Terraform's work helps you design efficient infrastructure code and explain your choices clearly.
"What if we added many outputs that are all marked sensitive? How would that affect the time complexity?"
Practice
sensitive = true in Terraform?Solution
Step 1: Understand the role of sensitive outputs
Marking an output as sensitive hides it from the normal Terraform output display to protect secrets.Step 2: Clarify what sensitive does not do
Sensitive does not make outputs public, increase size, or encrypt state automatically.Final Answer:
To hide the output value from the standard Terraform output display -> Option AQuick Check:
sensitive output hides value [OK]
- Thinking sensitive makes output public
- Assuming sensitive encrypts state file
- Believing sensitive increases output size
Solution
Step 1: Recall Terraform block syntax
Terraform blocks use new lines or spaces between arguments without semicolons or commas.Step 2: Identify correct syntax for sensitive output
The correct syntax placessensitive = trueon a new line inside the output block without semicolons or commas.Final Answer:
output "db_password" { value = var.db_password sensitive = true } -> Option AQuick Check:
Terraform blocks use new lines, no semicolons [OK]
- Using semicolons inside blocks
- Using commas between arguments
- Placing sensitive outside the output block
output "api_key" {
value = var.api_key
sensitive = true
}
What will Terraform display when you run terraform output?Solution
Step 1: Understand sensitive output display behavior
Terraform replaces sensitive output values with<sensitive>to avoid showing secrets.Step 2: Confirm output command behavior
Runningterraform outputshows<sensitive>for sensitive outputs, not the real value or errors.Final Answer:
<sensitive> placeholder instead of the value -> Option DQuick Check:
sensitive outputs show <sensitive> [OK]
- Expecting actual secret value to display
- Thinking terraform throws error for sensitive outputs
- Assuming no output is shown at all
output "admin_password" {
value = var.admin_password
sensitive = "true"
}
Terraform gives an error. What is the problem?Solution
Step 1: Check the sensitive attribute type
The sensitive attribute expects a boolean (true/false), not a string with quotes.Step 2: Identify the error cause
Using quotes around true makes it a string, causing Terraform syntax error.Final Answer:
The sensitive attribute must be a boolean, not a string -> Option BQuick Check:
sensitive = true (no quotes) [OK]
- Putting quotes around boolean true/false
- Adding commas inside blocks
- Misnaming output blocks
Solution
Step 1: Protect password in output
Marking output as sensitive hides it from console output, preventing accidental exposure.Step 2: Enable programmatic access
Usingterraform output -jsonallows other configs or scripts to read the secret safely without showing it on screen.Final Answer:
Declare output with sensitive = true and use terraform output -json to pass value programmatically -> Option CQuick Check:
Use sensitive output + json output for safe secret sharing [OK]
- Printing secrets openly in outputs
- Hardcoding secrets in configs
- Ignoring sensitive flag for secrets
