Q: Your team runs `terraform plan` inside a GitHub Actions workflow. You notice that the plan output printed in the CI logs exposes the full contents of a secret stored in AWS Secrets Manager (because a developer added `output "db_password" { value = data.aws_secretsmanager_secret_version.db.secret_string }`). How do you prevent secret exfiltration via plan output?
Three controls must work together:
#CI/CD #๐ Supply Chain Security & Advanced CI/CD #L2 #DevOps #Automation #Pipelines
๐๏ธ Candidate Opening & Architectural Context
""When developers encounter this build or release bottleneck, my first goal is unblocking velocity safely. The interviewer is testing: Terraform sensitive outputs, CI log masking, least-privilege planning.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
๐ ๏ธ Production Runbook & Step-by-Step Resolution
1๏ธโฃ
Initial Diagnostics & Root Cause Analysis
Three controls must work together:
- Mark outputs sensitive in Terraform:
output "db_password" { value = "..." sensitive = true }. Terraform will redact its value in plan output with(sensitive value). - Use a read-only IAM role for
planjobs โ the plan role has permissions to *read* state but notsecretsmanager:GetSecretValue. This means the plan step never even retrieves the plaintext secret. - Scrub logs in CI: GitHub Actions allows adding secrets to the masked list dynamically:
echo "::add-mask::$SECRET_VALUE". Any occurrence of that string in subsequent log output is replaced with***.
2๏ธโฃ
Remediation & Permanent Safeguards
๐ก The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Mark outputs sensitive in Terraform: output "db_password" { value = "..." sensitive = true }. Terraform will redact its value in p."
โก 60-Second Elevator Pitch Talking Points
- Mark outputs sensitive in Terraform: output "db_password" { value = "..." sensitive = true }. Ter...
- Use a read-only IAM role for plan jobs โ the plan role has permissions to *read* state but not se...
- Scrub logs in CI: GitHub Actions allows adding secrets to the masked list dynamically: echo "::ad...
Advertisement