Jump into concepts and practice - no test required
or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Sensitive output values
📖 Scenario: You are managing cloud infrastructure using Terraform. Some outputs contain sensitive information like passwords or API keys. You want to keep these values hidden when Terraform shows outputs after applying changes.
🎯 Goal: Create a Terraform configuration that defines an output with a sensitive value. Mark the output as sensitive so Terraform does not display it openly.
📋 What You'll Learn
Create a Terraform output named db_password with the value "supersecret123"
Mark the db_password output as sensitive using the sensitive = true attribute
💡 Why This Matters
🌍 Real World
Cloud engineers often manage secrets like passwords or API keys. Marking outputs as sensitive helps keep these secrets safe from accidental exposure.
💼 Career
Knowing how to handle sensitive data in Terraform is essential for secure infrastructure management and compliance.
Progress0 / 4 steps
1
Create a basic Terraform output
Write a Terraform output block named db_password with the value "supersecret123".
Terraform
Hint
Use the output block with a value attribute.
2
Add the sensitive attribute
Add the attribute sensitive = true inside the db_password output block to mark it as sensitive.
Terraform
Hint
The sensitive attribute hides the output value from Terraform's normal output.
3
Add a second non-sensitive output
Create another Terraform output named db_username with the value "adminuser" without marking it sensitive.
Terraform
Hint
Outputs without sensitive = true will show their values normally.
4
Complete the Terraform outputs configuration
Ensure the Terraform configuration includes both outputs: db_password marked sensitive and db_username not sensitive, exactly as before.
Terraform
Hint
Both outputs should be present with correct attributes.
Practice
(1/5)
1. What is the main purpose of marking an output as sensitive = true in Terraform?
easy
A. To hide the output value from the standard Terraform output display
B. To make the output value publicly accessible
C. To increase the output value size limit
D. To automatically encrypt the output value in the state file
Solution
Step 1: Understand the role of sensitive outputs
Marking an output as sensitive hides it from the normal Terraform output display to protect secrets.
Step 2: Clarify what sensitive does not do
Sensitive does not make outputs public, increase size, or encrypt state automatically.
Final Answer:
To hide the output value from the standard Terraform output display -> Option A
Quick Check:
sensitive output hides value [OK]
Hint: Sensitive outputs hide secrets from console output [OK]
Common Mistakes:
Thinking sensitive makes output public
Assuming sensitive encrypts state file
Believing sensitive increases output size
2. Which of the following is the correct syntax to declare a sensitive output in Terraform?
easy
A. output "db_password" { value = var.db_password
sensitive = true }
B. output "db_password" { value = var.db_password sensitive = true }
C. output "db_password" { value = var.db_password; sensitive = true }
D. output "db_password" { value = var.db_password, sensitive = true }
Solution
Step 1: Recall Terraform block syntax
Terraform blocks use new lines or spaces between arguments without semicolons or commas.
Step 2: Identify correct syntax for sensitive output
The correct syntax places sensitive = true on a new line inside the output block without semicolons or commas.
Final Answer:
output "db_password" { value = var.db_password
sensitive = true } -> Option A
Quick Check:
Terraform blocks use new lines, no semicolons [OK]
Hint: Terraform blocks use new lines, no semicolons or commas [OK]
Common Mistakes:
Using semicolons inside blocks
Using commas between arguments
Placing sensitive outside the output block
3. Given this Terraform output declaration:
output "api_key" {
value = var.api_key
sensitive = true
}
What will Terraform display when you run terraform output?
Terraform replaces sensitive output values with <sensitive> to avoid showing secrets.
Step 2: Confirm output command behavior
Running terraform output shows <sensitive> for sensitive outputs, not the real value or errors.
Final Answer:
<sensitive> placeholder instead of the value -> Option D
Quick Check:
sensitive outputs show <sensitive> [OK]
Hint: Sensitive outputs show <sensitive> instead of real value [OK]
Common Mistakes:
Expecting actual secret value to display
Thinking terraform throws error for sensitive outputs
Assuming no output is shown at all
4. You wrote this output block:
output "admin_password" {
value = var.admin_password
sensitive = "true"
}
Terraform gives an error. What is the problem?
medium
A. The value attribute cannot reference variables
B. The sensitive attribute must be a boolean, not a string
C. The output name cannot be admin_password
D. Missing a comma between value and sensitive
Solution
Step 1: Check the sensitive attribute type
The sensitive attribute expects a boolean (true/false), not a string with quotes.
Step 2: Identify the error cause
Using quotes around true makes it a string, causing Terraform syntax error.
Final Answer:
The sensitive attribute must be a boolean, not a string -> Option B
Quick Check:
sensitive = true (no quotes) [OK]
Hint: Boolean values in Terraform have no quotes [OK]
Common Mistakes:
Putting quotes around boolean true/false
Adding commas inside blocks
Misnaming output blocks
5. You want to output a database password securely and also allow other Terraform configurations to access it without exposing it in the console. Which approach is best?
hard
A. Store the password in a public output without sensitive flag
B. Print the password normally in output and rely on user caution
C. Declare output with sensitive = true and use terraform output -json to pass value programmatically
D. Remove the output block and hardcode the password in other configs
Solution
Step 1: Protect password in output
Marking output as sensitive hides it from console output, preventing accidental exposure.
Step 2: Enable programmatic access
Using terraform output -json allows other configs or scripts to read the secret safely without showing it on screen.
Final Answer:
Declare output with sensitive = true and use terraform output -json to pass value programmatically -> Option C
Quick Check:
Use sensitive output + json output for safe secret sharing [OK]
Hint: Use sensitive output plus JSON output for safe secret sharing [OK]