⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All Terraform & IaC Interview Questions Scenario 114 of 117 in Terraform & IaC
Senior Cloud Engineer (L2) Terraform Secret Governance & Variables L2 Cloud Screen

Q: How would you pass sensitive data to Terraform if there is currently no Vault or cloud-based Secrets Manager available?

Secure architectural patterns for injecting secrets into Terraform when dedicated secret vaults or cloud Secrets Managers are unavailable.

#Terraform #Security #Secrets #Environment Variables #SOPS #IaC
🎙️ Candidate Opening & Architectural Context
"When dedicated enterprise secrets management systems (HashiCorp Vault, AWS Secrets Manager) are not deployed, sensitive values (database passwords, API tokens) must still NEVER be committed to Git in plaintext `.tf` or `.tfvars` files. I use environment variables (`TF_VAR_`), Mozilla SOPS with PGP/KMS encryption in Git, and Terraform `sensitive = true` variable masking."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? KodeKloud's HashiCorp Certified Terraform Associate (003) Interactive Labs covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1

Pattern 1: Environment Variables via TF_VAR_ Injection

Terraform automatically reads environment variables prefixed with `TF_VAR_`. In CI/CD pipelines (GitHub Actions, GitLab CI), inject secrets from masked pipeline variables into the runner environment at runtime.

# In CI/CD runner script:
export TF_VAR_db_password="$SECRET_FROM_CI_RUNNER"
terraform plan
2

Pattern 2: Encrypted Git Repositories Using Mozilla SOPS

Use **Mozilla SOPS** (Secrets OPerationS). SOPS allows encrypting values inside `.tfvars.json` or `.yaml` files using local PGP keys or age keys while keeping keys in plaintext. The encrypted file is safely committed to Git, and decrypted on-the-fly during pipeline execution.

# Encrypt secret tfvars file
sops --encrypt --in-place secrets.enc.tfvars.json
# Decrypt during terraform run:
terraform apply -var-file=<(sops -d secrets.enc.tfvars.json)
Advertisement
3

Mark Variables as Sensitive in HCL

Declare `sensitive = true` on all input variables in Terraform. This prevents Terraform from printing plaintext passwords in console logs, pipeline terminal streams, and `terraform plan` outputs.

variable "db_password" {
  type      = string
  sensitive = true
}
4

Protect Remote State File (State Encryption)

Remember that Terraform state files store sensitive variables in plaintext JSON! Always enable server-side encryption (SSE-KMS) on the S3 remote state bucket and restrict bucket access with strict IAM policies.

Pro Tip: Security Alert: Even if variables are passed via TF_VAR_, they are stored in plaintext inside terraform.tfstate. Remote state encryption and IAM access controls are mandatory.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pass secrets via TF_VAR_ environment variables from masked CI runners or use Mozilla SOPS to encrypt files in Git. Mark HCL variables with sensitive = true and encrypt the remote state backend."
⚡ 60-Second Elevator Pitch Talking Points
  • Use TF_VAR_ environment variables injected dynamically from masked CI/CD pipeline stores.
  • Use Mozilla SOPS to encrypt secrets committed to Git using PGP or Age keys.
  • Flag all secret variables with sensitive = true to redact values from console outputs.
  • Enforce SSE-KMS encryption and strict IAM policies on the remote S3/GCS state file backend.
Advertisement
Want more Terraform & IaC scenarios?
Explore our complete collection of scenario-based Terraform & IaC interview runbooks.
Browse All Terraform & IaC Questions →