Bird
Raised Fist0
Terraformcloud~5 mins

Sensitive output values in Terraform - Cheat Sheet & Quick Revision

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Recall & Review
beginner
What does marking an output as sensitive in Terraform do?
It hides the output value from the CLI output and logs to protect sensitive information like passwords or keys.
Click to reveal answer
beginner
How do you declare a sensitive output in Terraform?
Use the sensitive = true argument inside the output block, for example:
output "db_password" {
  value     = aws_db_instance.example.password
  sensitive = true
}
Click to reveal answer
beginner
Why should sensitive outputs not be printed in logs or shared publicly?
Because they may contain secrets like passwords or API keys that can compromise security if exposed.
Click to reveal answer
intermediate
Can sensitive outputs be accessed programmatically in Terraform?
Yes, sensitive outputs can be used by other Terraform configurations or modules but remain hidden in CLI output and logs.
Click to reveal answer
beginner
What happens if you do not mark a sensitive value as sensitive in Terraform outputs?
The value will be shown in the CLI output and stored in the state file in plain text, risking exposure of secrets.
Click to reveal answer
What keyword do you use to mark an output as sensitive in Terraform?
Aprivate = true
Bsensitive = true
Chidden = true
Dsecure = true
What is the main benefit of marking outputs as sensitive?
AThey are hidden from CLI output and logs
BThey are encrypted in the state file
CThey run faster
DThey can be shared publicly
If an output is sensitive, can other Terraform modules still use its value?
ANo, sensitive outputs are blocked
BOnly if you decrypt it manually
COnly in the same module
DYes, but the value is hidden in CLI output
What risk do you take if you do NOT mark a secret output as sensitive?
AThe secret will be exposed in CLI output and state files
BTerraform will fail to apply
CThe output will be encrypted automatically
DThere is no risk
Which of these is NOT a recommended practice for sensitive outputs?
AMark outputs as sensitive
BAvoid printing secrets in logs
CStore secrets in plain text outputs
DUse outputs carefully in automation
Explain how to protect sensitive information in Terraform outputs and why it matters.
Think about what happens if secrets are shown in logs or terminal.
You got /4 concepts.
    Describe the behavior of sensitive outputs in Terraform when accessed by other modules or automation.
    Consider how Terraform shares outputs internally vs. what it shows to users.
    You got /4 concepts.

      Practice

      (1/5)
      1. What is the main purpose of marking an output as sensitive = true in Terraform?
      easy
      A. To hide the output value from the standard Terraform output display
      B. To make the output value publicly accessible
      C. To increase the output value size limit
      D. To automatically encrypt the output value in the state file

      Solution

      1. Step 1: Understand the role of sensitive outputs

        Marking an output as sensitive hides it from the normal Terraform output display to protect secrets.
      2. Step 2: Clarify what sensitive does not do

        Sensitive does not make outputs public, increase size, or encrypt state automatically.
      3. Final Answer:

        To hide the output value from the standard Terraform output display -> Option A
      4. Quick Check:

        sensitive output hides value [OK]
      Hint: Sensitive outputs hide secrets from console output [OK]
      Common Mistakes:
      • Thinking sensitive makes output public
      • Assuming sensitive encrypts state file
      • Believing sensitive increases output size
      2. Which of the following is the correct syntax to declare a sensitive output in Terraform?
      easy
      A. output "db_password" { value = var.db_password sensitive = true }
      B. output "db_password" { value = var.db_password sensitive = true }
      C. output "db_password" { value = var.db_password; sensitive = true }
      D. output "db_password" { value = var.db_password, sensitive = true }

      Solution

      1. Step 1: Recall Terraform block syntax

        Terraform blocks use new lines or spaces between arguments without semicolons or commas.
      2. Step 2: Identify correct syntax for sensitive output

        The correct syntax places sensitive = true on a new line inside the output block without semicolons or commas.
      3. Final Answer:

        output "db_password" { value = var.db_password sensitive = true } -> Option A
      4. Quick Check:

        Terraform blocks use new lines, no semicolons [OK]
      Hint: Terraform blocks use new lines, no semicolons or commas [OK]
      Common Mistakes:
      • Using semicolons inside blocks
      • Using commas between arguments
      • Placing sensitive outside the output block
      3. Given this Terraform output declaration:
      output "api_key" {
        value     = var.api_key
        sensitive = true
      }
      What will Terraform display when you run terraform output?
      medium
      A. The actual API key value
      B. An error saying output is sensitive
      C. No output at all
      D. <sensitive> placeholder instead of the value

      Solution

      1. Step 1: Understand sensitive output display behavior

        Terraform replaces sensitive output values with <sensitive> to avoid showing secrets.
      2. Step 2: Confirm output command behavior

        Running terraform output shows <sensitive> for sensitive outputs, not the real value or errors.
      3. Final Answer:

        <sensitive> placeholder instead of the value -> Option D
      4. Quick Check:

        sensitive outputs show <sensitive> [OK]
      Hint: Sensitive outputs show <sensitive> instead of real value [OK]
      Common Mistakes:
      • Expecting actual secret value to display
      • Thinking terraform throws error for sensitive outputs
      • Assuming no output is shown at all
      4. You wrote this output block:
      output "admin_password" {
        value = var.admin_password
        sensitive = "true"
      }
      Terraform gives an error. What is the problem?
      medium
      A. The value attribute cannot reference variables
      B. The sensitive attribute must be a boolean, not a string
      C. The output name cannot be admin_password
      D. Missing a comma between value and sensitive

      Solution

      1. Step 1: Check the sensitive attribute type

        The sensitive attribute expects a boolean (true/false), not a string with quotes.
      2. Step 2: Identify the error cause

        Using quotes around true makes it a string, causing Terraform syntax error.
      3. Final Answer:

        The sensitive attribute must be a boolean, not a string -> Option B
      4. Quick Check:

        sensitive = true (no quotes) [OK]
      Hint: Boolean values in Terraform have no quotes [OK]
      Common Mistakes:
      • Putting quotes around boolean true/false
      • Adding commas inside blocks
      • Misnaming output blocks
      5. You want to output a database password securely and also allow other Terraform configurations to access it without exposing it in the console. Which approach is best?
      hard
      A. Store the password in a public output without sensitive flag
      B. Print the password normally in output and rely on user caution
      C. Declare output with sensitive = true and use terraform output -json to pass value programmatically
      D. Remove the output block and hardcode the password in other configs

      Solution

      1. Step 1: Protect password in output

        Marking output as sensitive hides it from console output, preventing accidental exposure.
      2. Step 2: Enable programmatic access

        Using terraform output -json allows other configs or scripts to read the secret safely without showing it on screen.
      3. Final Answer:

        Declare output with sensitive = true and use terraform output -json to pass value programmatically -> Option C
      4. Quick Check:

        Use sensitive output + json output for safe secret sharing [OK]
      Hint: Use sensitive output plus JSON output for safe secret sharing [OK]
      Common Mistakes:
      • Printing secrets openly in outputs
      • Hardcoding secrets in configs
      • Ignoring sensitive flag for secrets