Bird
Raised Fist0
Terraformcloud~10 mins

Sensitive output values in Terraform - Step-by-Step Execution

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Process Flow - Sensitive output values
Define output variable
↓
Mark output as sensitive?
No→Output visible in CLI and state
Yes↓
Output value hidden in CLI
↓
Output stored in state file
This flow shows how marking an output as sensitive hides its value from CLI output but still stores it securely in the state file.
Execution Sample
Terraform
output "db_password" {
  value     = aws_db_instance.example.password
  sensitive = true
}
Defines a sensitive output for a database password that hides the value in CLI output.
Process Table
StepActionOutput Value Visible?State File Storage
1Define output 'db_password' with sensitive=trueNo (hidden)Stored in state file
2Run 'terraform apply'No (hidden in CLI)Stored in state file
3Run 'terraform output db_password'No (hidden)Stored in state file
4Remove sensitive flagYes (visible in CLI)Stored in state file
5Run 'terraform output db_password'Yes (visible)Stored in state file
💡 Sensitive outputs hide values in CLI but keep them stored securely; removing sensitive flag shows values.
Status Tracker
VariableStartAfter Step 1After Step 4Final
db_passwordundefinedhidden in CLI, stored in statevisible in CLI, stored in statevisible in CLI, stored in state
Key Moments - 3 Insights
Why can't I see the sensitive output value in the CLI after apply?
Because the output is marked sensitive (see execution_table step 2), Terraform hides it in CLI to protect secrets.
Is the sensitive output value lost or not stored anywhere?
No, it is stored in the state file (execution_table step 1 and 2), just hidden from CLI output.
What happens if I remove the sensitive flag from the output?
The output value becomes visible in CLI (execution_table step 4 and 5).
Visual Quiz - 3 Questions
Test your understanding
Look at the execution_table, at which step does the output value become visible in CLI?
AStep 4
BStep 3
CStep 2
DStep 1
💡 Hint
Check the 'Output Value Visible?' column in execution_table rows.
According to variable_tracker, what is the state of 'db_password' after step 1?
AUndefined
BVisible in CLI, stored unencrypted
CHidden in CLI, stored in state
DVisible in CLI, stored encrypted
💡 Hint
Look at the 'After Step 1' column for 'db_password' in variable_tracker.
If you want to keep the output value visible in CLI, what should you do?
ASet sensitive = true
BRemove sensitive = true
CEncrypt the state file manually
DUse a different output name
💡 Hint
Refer to execution_table steps 4 and 5 about sensitive flag effect.
Concept Snapshot
Terraform outputs can be marked sensitive to hide their values in CLI output.
Sensitive outputs are still stored securely in the state file.
Removing the sensitive flag makes the output visible in CLI.
Use sensitive outputs to protect secrets like passwords from accidental exposure.
Full Transcript
This lesson shows how Terraform handles sensitive output values. When you mark an output as sensitive, Terraform hides its value in the command line interface to protect secrets. However, the value is still stored securely in the state file. If you remove the sensitive flag, the output value becomes visible in the CLI. This helps keep sensitive information safe while still allowing you to output necessary data.

Practice

(1/5)
1. What is the main purpose of marking an output as sensitive = true in Terraform?
easy
A. To hide the output value from the standard Terraform output display
B. To make the output value publicly accessible
C. To increase the output value size limit
D. To automatically encrypt the output value in the state file

Solution

  1. Step 1: Understand the role of sensitive outputs

    Marking an output as sensitive hides it from the normal Terraform output display to protect secrets.
  2. Step 2: Clarify what sensitive does not do

    Sensitive does not make outputs public, increase size, or encrypt state automatically.
  3. Final Answer:

    To hide the output value from the standard Terraform output display -> Option A
  4. Quick Check:

    sensitive output hides value [OK]
Hint: Sensitive outputs hide secrets from console output [OK]
Common Mistakes:
  • Thinking sensitive makes output public
  • Assuming sensitive encrypts state file
  • Believing sensitive increases output size
2. Which of the following is the correct syntax to declare a sensitive output in Terraform?
easy
A. output "db_password" { value = var.db_password sensitive = true }
B. output "db_password" { value = var.db_password sensitive = true }
C. output "db_password" { value = var.db_password; sensitive = true }
D. output "db_password" { value = var.db_password, sensitive = true }

Solution

  1. Step 1: Recall Terraform block syntax

    Terraform blocks use new lines or spaces between arguments without semicolons or commas.
  2. Step 2: Identify correct syntax for sensitive output

    The correct syntax places sensitive = true on a new line inside the output block without semicolons or commas.
  3. Final Answer:

    output "db_password" { value = var.db_password sensitive = true } -> Option A
  4. Quick Check:

    Terraform blocks use new lines, no semicolons [OK]
Hint: Terraform blocks use new lines, no semicolons or commas [OK]
Common Mistakes:
  • Using semicolons inside blocks
  • Using commas between arguments
  • Placing sensitive outside the output block
3. Given this Terraform output declaration:
output "api_key" {
  value     = var.api_key
  sensitive = true
}
What will Terraform display when you run terraform output?
medium
A. The actual API key value
B. An error saying output is sensitive
C. No output at all
D. <sensitive> placeholder instead of the value

Solution

  1. Step 1: Understand sensitive output display behavior

    Terraform replaces sensitive output values with <sensitive> to avoid showing secrets.
  2. Step 2: Confirm output command behavior

    Running terraform output shows <sensitive> for sensitive outputs, not the real value or errors.
  3. Final Answer:

    <sensitive> placeholder instead of the value -> Option D
  4. Quick Check:

    sensitive outputs show <sensitive> [OK]
Hint: Sensitive outputs show <sensitive> instead of real value [OK]
Common Mistakes:
  • Expecting actual secret value to display
  • Thinking terraform throws error for sensitive outputs
  • Assuming no output is shown at all
4. You wrote this output block:
output "admin_password" {
  value = var.admin_password
  sensitive = "true"
}
Terraform gives an error. What is the problem?
medium
A. The value attribute cannot reference variables
B. The sensitive attribute must be a boolean, not a string
C. The output name cannot be admin_password
D. Missing a comma between value and sensitive

Solution

  1. Step 1: Check the sensitive attribute type

    The sensitive attribute expects a boolean (true/false), not a string with quotes.
  2. Step 2: Identify the error cause

    Using quotes around true makes it a string, causing Terraform syntax error.
  3. Final Answer:

    The sensitive attribute must be a boolean, not a string -> Option B
  4. Quick Check:

    sensitive = true (no quotes) [OK]
Hint: Boolean values in Terraform have no quotes [OK]
Common Mistakes:
  • Putting quotes around boolean true/false
  • Adding commas inside blocks
  • Misnaming output blocks
5. You want to output a database password securely and also allow other Terraform configurations to access it without exposing it in the console. Which approach is best?
hard
A. Store the password in a public output without sensitive flag
B. Print the password normally in output and rely on user caution
C. Declare output with sensitive = true and use terraform output -json to pass value programmatically
D. Remove the output block and hardcode the password in other configs

Solution

  1. Step 1: Protect password in output

    Marking output as sensitive hides it from console output, preventing accidental exposure.
  2. Step 2: Enable programmatic access

    Using terraform output -json allows other configs or scripts to read the secret safely without showing it on screen.
  3. Final Answer:

    Declare output with sensitive = true and use terraform output -json to pass value programmatically -> Option C
  4. Quick Check:

    Use sensitive output + json output for safe secret sharing [OK]
Hint: Use sensitive output plus JSON output for safe secret sharing [OK]
Common Mistakes:
  • Printing secrets openly in outputs
  • Hardcoding secrets in configs
  • Ignoring sensitive flag for secrets