Bird
Raised Fist0
Terraformcloud~5 mins

Sensitive variables in Terraform - Cheat Sheet & Quick Revision

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Recall & Review
beginner
What is a sensitive variable in Terraform?
A sensitive variable is a variable that holds secret or private information, like passwords or keys, which Terraform hides from output to keep it safe.
Click to reveal answer
beginner
How do you declare a sensitive variable in Terraform?
You declare a variable with the attribute sensitive = true inside the variable block to mark it as sensitive.
Click to reveal answer
beginner
Why should sensitive variables not be printed in Terraform outputs?
Printing sensitive variables can expose secrets in logs or terminal, risking security. Terraform hides them to protect sensitive data.
Click to reveal answer
intermediate
Can sensitive variables be used in Terraform resource configurations?
Yes, sensitive variables can be used normally in resource configurations, but Terraform will avoid showing their values in plan or apply outputs.
Click to reveal answer
intermediate
What happens if you try to output a sensitive variable without marking the output as sensitive?
Terraform will warn you and hide the value in the output to prevent accidental exposure of secrets.
Click to reveal answer
How do you mark a variable as sensitive in Terraform?
APrefix the variable name with 'secret_'
BUse <code>private = true</code> in the variable block
CAdd <code>sensitive = true</code> in the variable block
DSet <code>hidden = true</code> in the variable block
What does Terraform do when you output a sensitive variable without marking the output as sensitive?
AShows the value normally
BThrows an error and stops
CDeletes the variable
DHides the value and shows a warning
Why should sensitive variables be used in Terraform?
ATo keep secret information safe
BTo store large data files
CTo speed up Terraform runs
DTo make variables public
Can you use sensitive variables inside resource definitions?
AYes, but values are hidden in outputs
BNo, Terraform blocks it
COnly if you disable sensitivity
DOnly for string variables
What is a best practice when handling sensitive variables in Terraform?
AStore them in plain text files
BMark them as sensitive and avoid printing
CShare them in team chats
DPrint them in logs for debugging
Explain how to declare and use sensitive variables in Terraform and why it is important.
Think about how you keep passwords safe in real life.
You got /4 concepts.
    Describe what happens when you output a sensitive variable without marking the output as sensitive in Terraform.
    Terraform acts like a privacy guard for secrets.
    You got /3 concepts.

      Practice

      (1/5)
      1.

      What is the main purpose of marking a variable as sensitive in Terraform?

      easy
      A. To hide the variable's value from Terraform plan and apply outputs
      B. To make the variable read-only
      C. To encrypt the variable in the state file automatically
      D. To allow the variable to be used only in modules

      Solution

      1. Step 1: Understand what sensitive means in Terraform

        Marking a variable as sensitive tells Terraform not to show its value in command outputs like plan or apply, protecting secrets from accidental exposure.
      2. Step 2: Clarify what sensitive does not do automatically

        Sensitive does not make the variable read-only, nor does it encrypt the state file automatically. It only hides the value in outputs.
      3. Final Answer:

        To hide the variable's value from Terraform plan and apply outputs -> Option A
      4. Quick Check:

        Sensitive hides values in outputs = B [OK]
      Hint: Sensitive hides secrets in outputs, not encryption [OK]
      Common Mistakes:
      • Thinking sensitive encrypts the state file
      • Confusing sensitive with read-only variables
      • Believing sensitive restricts variable usage
      2.

      Which of the following is the correct way to declare a sensitive variable in Terraform?

      variable "db_password" {
        type = string
        sensitive = true
      }
      easy
      A. variable "db_password" { sensitive = true; type = string }
      B. variable "db_password" { type = string sensitive = true }
      C. variable "db_password" { type = string; sensitive = true }
      D. variable "db_password" { sensitive: true type: string }

      Solution

      1. Step 1: Recall Terraform variable block syntax

        Terraform uses HCL syntax where attributes are set with key = value pairs separated by new lines or spaces.
      2. Step 2: Identify correct attribute order and syntax

        Attributes order does not matter, but semicolons or colons are invalid in HCL. So sensitive = true and type = string with equals signs and no semicolons is correct.
      3. Final Answer:

        variable "db_password" { type = string sensitive = true } -> Option B
      4. Quick Check:

        Correct HCL syntax uses equals and no semicolons = A [OK]
      Hint: Use equals signs and no semicolons in Terraform blocks [OK]
      Common Mistakes:
      • Using semicolons or colons instead of equals
      • Putting attributes on the same line without proper syntax
      • Incorrect attribute order causing confusion
      3.

      Given this Terraform code snippet, what will be the output of terraform apply regarding the db_password variable?

      variable "db_password" {
        type = string
        sensitive = true
      }
      
      output "password_output" {
        value = var.db_password
        sensitive = true
      }
      medium
      A. The password value will be hidden in the output after apply
      B. The password value will be shown in the output after apply
      C. Terraform will throw a syntax error due to sensitive output
      D. The password value will be printed in the plan but hidden in apply

      Solution

      1. Step 1: Understand sensitive variable and output behavior

        Marking a variable and output as sensitive hides their values from Terraform CLI outputs during plan and apply.
      2. Step 2: Check if syntax allows sensitive outputs

        Terraform supports marking outputs as sensitive to prevent showing secret values. No syntax error occurs.
      3. Final Answer:

        The password value will be hidden in the output after apply -> Option A
      4. Quick Check:

        Sensitive outputs hide values in apply output = A [OK]
      Hint: Sensitive outputs hide values in apply output [OK]
      Common Mistakes:
      • Expecting sensitive values to show in outputs
      • Thinking sensitive outputs cause syntax errors
      • Confusing plan output with apply output
      4.

      What is wrong with this Terraform variable declaration if the goal is to keep the value secret?

      variable "api_key" {
        type = string
        default = "mysecret"
      }
      medium
      A. Default values cannot be used with sensitive variables
      B. The variable type should be secret instead of string
      C. The variable is missing sensitive = true to hide the value
      D. The variable name must start with secret_

      Solution

      1. Step 1: Check if variable is marked sensitive

        The variable is not marked with sensitive = true, so its value will be shown in outputs and state.
      2. Step 2: Validate other options

        Terraform does not have a secret type, default values are allowed, and variable names have no required prefix.
      3. Final Answer:

        The variable is missing sensitive = true to hide the value -> Option C
      4. Quick Check:

        Missing sensitive attribute means value not hidden = C [OK]
      Hint: Add sensitive = true to hide secret values [OK]
      Common Mistakes:
      • Assuming type secret exists
      • Thinking default values are forbidden for secrets
      • Believing variable names must have secret prefix
      5.

      You want to pass a sensitive database password from a Terraform module to the root module without exposing it in any output or logs. Which approach is best?

      hard
      A. Use a non-sensitive variable and rely on Terraform state encryption
      B. Pass the password as a normal variable and print it in the root output for verification
      C. Store the password in a plain text file and read it in both modules
      D. Mark the variable as sensitive in the module and mark the output as sensitive in the module and root

      Solution

      1. Step 1: Protect sensitive data in modules

        Marking variables and outputs as sensitive in both the module and root prevents accidental exposure in CLI outputs and logs.
      2. Step 2: Avoid insecure practices

        Printing secrets in outputs, storing in plain text files, or relying only on state encryption risks exposure.
      3. Final Answer:

        Mark the variable as sensitive in the module and mark the output as sensitive in the module and root -> Option D
      4. Quick Check:

        Mark sensitive in variables and outputs to keep secrets safe = D [OK]
      Hint: Mark sensitive on variables and outputs in all modules [OK]
      Common Mistakes:
      • Printing secrets in outputs for debugging
      • Storing secrets in plain text files
      • Assuming state encryption alone is enough