Q: How would you pass sensitive data to Terraform if there is currently no Vault or cloud-based Secrets Manager available?
Secure architectural patterns for injecting secrets into Terraform when dedicated secret vaults or cloud Secrets Managers are unavailable.
Want to master this scenario in a live sandbox? KodeKloud's HashiCorp Certified Terraform Associate (003) Interactive Labs covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Pattern 1: Environment Variables via TF_VAR_ Injection
Terraform automatically reads environment variables prefixed with `TF_VAR_`. In CI/CD pipelines (GitHub Actions, GitLab CI), inject secrets from masked pipeline variables into the runner environment at runtime.
# In CI/CD runner script:
export TF_VAR_db_password="$SECRET_FROM_CI_RUNNER"
terraform plan
Pattern 2: Encrypted Git Repositories Using Mozilla SOPS
Use **Mozilla SOPS** (Secrets OPerationS). SOPS allows encrypting values inside `.tfvars.json` or `.yaml` files using local PGP keys or age keys while keeping keys in plaintext. The encrypted file is safely committed to Git, and decrypted on-the-fly during pipeline execution.
# Encrypt secret tfvars file
sops --encrypt --in-place secrets.enc.tfvars.json
# Decrypt during terraform run:
terraform apply -var-file=<(sops -d secrets.enc.tfvars.json)
Mark Variables as Sensitive in HCL
Declare `sensitive = true` on all input variables in Terraform. This prevents Terraform from printing plaintext passwords in console logs, pipeline terminal streams, and `terraform plan` outputs.
variable "db_password" {
type = string
sensitive = true
}
Protect Remote State File (State Encryption)
Remember that Terraform state files store sensitive variables in plaintext JSON! Always enable server-side encryption (SSE-KMS) on the S3 remote state bucket and restrict bucket access with strict IAM policies.
- Use TF_VAR_ environment variables injected dynamically from masked CI/CD pipeline stores.
- Use Mozilla SOPS to encrypt secrets committed to Git using PGP or Age keys.
- Flag all secret variables with sensitive = true to redact values from console outputs.
- Enforce SSE-KMS encryption and strict IAM policies on the remote S3/GCS state file backend.