Bird
Raised Fist0
Terraformcloud~5 mins

Sensitive variables in Terraform - Commands & Configuration

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Introduction
Sometimes you need to keep secrets like passwords or keys safe when using Terraform. Sensitive variables help hide these secrets so they don't show up in logs or outputs.
When you need to store a database password in your Terraform configuration without exposing it.
When you want to keep API keys secret while deploying cloud resources.
When sharing Terraform code but want to avoid leaking sensitive information.
When you want Terraform to warn you if a secret is accidentally printed.
When you want to pass sensitive data securely between Terraform modules.
Config File - variables.tf
variables.tf
variable "db_password" {
  description = "The password for the database"
  type        = string
  sensitive   = true
}

variable "db_user" {
  description = "The username for the database"
  type        = string
  sensitive   = false
}

output "db_user_output" {
  value = var.db_user
}

output "db_password_output" {
  value     = var.db_password
  sensitive = true
}

This file defines two variables: db_password marked as sensitive to hide its value, and db_user which is not sensitive. It also defines outputs for both variables. The password output is marked sensitive so Terraform will not show it in the output.

Commands
This command initializes the Terraform working directory and downloads necessary provider plugins.
Terminal
terraform init
Expected OutputExpected
Initializing the backend... Initializing provider plugins... - Finding latest version of hashicorp/aws... - Installing hashicorp/aws v4.0.0... - Installed hashicorp/aws v4.0.0 (signed by HashiCorp) Terraform has been successfully initialized!
This command shows what Terraform will do, passing the sensitive password and user as variables. The password value will not be shown in the plan output.
Terminal
terraform plan -var='db_password=MySecret123' -var='db_user=admin'
Expected OutputExpected
An execution plan has been generated and is shown below. Resource actions are indicated with the following symbols: + create Terraform will perform the following actions: # example_resource will be created + resource "example_resource" "db" { + user = "admin" + password = (sensitive value) } Plan: 1 to add, 0 to change, 0 to destroy.
→
-var - Passes variable values to Terraform
This command applies the changes to create resources using the sensitive variables. The password will not be shown in the output.
Terminal
terraform apply -auto-approve -var='db_password=MySecret123' -var='db_user=admin'
Expected OutputExpected
example_resource.db: Creating... example_resource.db: Creation complete after 2s [id=12345] Apply complete! Resources: 1 added, 0 changed, 0 destroyed.
→
-auto-approve - Skips interactive approval prompt
→
-var - Passes variable values to Terraform
This command shows the outputs. The sensitive output value will be hidden.
Terminal
terraform output
Expected OutputExpected
db_user_output = admin Warning: Output "db_password_output" is sensitive, and its value will not be shown.
Key Concept

If you remember nothing else from this pattern, remember: marking variables and outputs as sensitive keeps secrets hidden from Terraform logs and outputs.

Common Mistakes
Not marking a secret variable as sensitive
Terraform will show the secret value in logs and outputs, exposing it.
Add sensitive = true to the variable definition to hide its value.
Marking outputs as sensitive but not variables
The secret value can still appear in plan or apply logs if the variable is not sensitive.
Mark both variables and outputs as sensitive to fully protect the secret.
Passing sensitive values directly in command line without care
Command history or process lists may expose the secret.
Use environment variables or Terraform Cloud variables to pass secrets more securely.
Summary
Define variables with sensitive = true to hide secret values.
Pass sensitive variables using -var flag or secure methods.
Terraform hides sensitive values in plan, apply, and output commands.

Practice

(1/5)
1.

What is the main purpose of marking a variable as sensitive in Terraform?

easy
A. To hide the variable's value from Terraform plan and apply outputs
B. To make the variable read-only
C. To encrypt the variable in the state file automatically
D. To allow the variable to be used only in modules

Solution

  1. Step 1: Understand what sensitive means in Terraform

    Marking a variable as sensitive tells Terraform not to show its value in command outputs like plan or apply, protecting secrets from accidental exposure.
  2. Step 2: Clarify what sensitive does not do automatically

    Sensitive does not make the variable read-only, nor does it encrypt the state file automatically. It only hides the value in outputs.
  3. Final Answer:

    To hide the variable's value from Terraform plan and apply outputs -> Option A
  4. Quick Check:

    Sensitive hides values in outputs = B [OK]
Hint: Sensitive hides secrets in outputs, not encryption [OK]
Common Mistakes:
  • Thinking sensitive encrypts the state file
  • Confusing sensitive with read-only variables
  • Believing sensitive restricts variable usage
2.

Which of the following is the correct way to declare a sensitive variable in Terraform?

variable "db_password" {
  type = string
  sensitive = true
}
easy
A. variable "db_password" { sensitive = true; type = string }
B. variable "db_password" { type = string sensitive = true }
C. variable "db_password" { type = string; sensitive = true }
D. variable "db_password" { sensitive: true type: string }

Solution

  1. Step 1: Recall Terraform variable block syntax

    Terraform uses HCL syntax where attributes are set with key = value pairs separated by new lines or spaces.
  2. Step 2: Identify correct attribute order and syntax

    Attributes order does not matter, but semicolons or colons are invalid in HCL. So sensitive = true and type = string with equals signs and no semicolons is correct.
  3. Final Answer:

    variable "db_password" { type = string sensitive = true } -> Option B
  4. Quick Check:

    Correct HCL syntax uses equals and no semicolons = A [OK]
Hint: Use equals signs and no semicolons in Terraform blocks [OK]
Common Mistakes:
  • Using semicolons or colons instead of equals
  • Putting attributes on the same line without proper syntax
  • Incorrect attribute order causing confusion
3.

Given this Terraform code snippet, what will be the output of terraform apply regarding the db_password variable?

variable "db_password" {
  type = string
  sensitive = true
}

output "password_output" {
  value = var.db_password
  sensitive = true
}
medium
A. The password value will be hidden in the output after apply
B. The password value will be shown in the output after apply
C. Terraform will throw a syntax error due to sensitive output
D. The password value will be printed in the plan but hidden in apply

Solution

  1. Step 1: Understand sensitive variable and output behavior

    Marking a variable and output as sensitive hides their values from Terraform CLI outputs during plan and apply.
  2. Step 2: Check if syntax allows sensitive outputs

    Terraform supports marking outputs as sensitive to prevent showing secret values. No syntax error occurs.
  3. Final Answer:

    The password value will be hidden in the output after apply -> Option A
  4. Quick Check:

    Sensitive outputs hide values in apply output = A [OK]
Hint: Sensitive outputs hide values in apply output [OK]
Common Mistakes:
  • Expecting sensitive values to show in outputs
  • Thinking sensitive outputs cause syntax errors
  • Confusing plan output with apply output
4.

What is wrong with this Terraform variable declaration if the goal is to keep the value secret?

variable "api_key" {
  type = string
  default = "mysecret"
}
medium
A. Default values cannot be used with sensitive variables
B. The variable type should be secret instead of string
C. The variable is missing sensitive = true to hide the value
D. The variable name must start with secret_

Solution

  1. Step 1: Check if variable is marked sensitive

    The variable is not marked with sensitive = true, so its value will be shown in outputs and state.
  2. Step 2: Validate other options

    Terraform does not have a secret type, default values are allowed, and variable names have no required prefix.
  3. Final Answer:

    The variable is missing sensitive = true to hide the value -> Option C
  4. Quick Check:

    Missing sensitive attribute means value not hidden = C [OK]
Hint: Add sensitive = true to hide secret values [OK]
Common Mistakes:
  • Assuming type secret exists
  • Thinking default values are forbidden for secrets
  • Believing variable names must have secret prefix
5.

You want to pass a sensitive database password from a Terraform module to the root module without exposing it in any output or logs. Which approach is best?

hard
A. Use a non-sensitive variable and rely on Terraform state encryption
B. Pass the password as a normal variable and print it in the root output for verification
C. Store the password in a plain text file and read it in both modules
D. Mark the variable as sensitive in the module and mark the output as sensitive in the module and root

Solution

  1. Step 1: Protect sensitive data in modules

    Marking variables and outputs as sensitive in both the module and root prevents accidental exposure in CLI outputs and logs.
  2. Step 2: Avoid insecure practices

    Printing secrets in outputs, storing in plain text files, or relying only on state encryption risks exposure.
  3. Final Answer:

    Mark the variable as sensitive in the module and mark the output as sensitive in the module and root -> Option D
  4. Quick Check:

    Mark sensitive in variables and outputs to keep secrets safe = D [OK]
Hint: Mark sensitive on variables and outputs in all modules [OK]
Common Mistakes:
  • Printing secrets in outputs for debugging
  • Storing secrets in plain text files
  • Assuming state encryption alone is enough