2017-03-28 21:12:32 +02:00
|
|
|
---
|
2021-12-15 03:41:17 +01:00
|
|
|
page_title: 'State: Sensitive Data'
|
|
|
|
description: Sensitive data in Terraform state.
|
2017-03-28 21:12:32 +02:00
|
|
|
---
|
|
|
|
|
|
|
|
# Sensitive Data in State
|
|
|
|
|
2019-12-18 20:26:10 +01:00
|
|
|
Terraform state can contain sensitive data, depending on the resources in use
|
2017-03-28 21:12:32 +02:00
|
|
|
and your definition of "sensitive." The state contains resource IDs and all
|
|
|
|
resource attributes. For resources such as databases, this may contain initial
|
|
|
|
passwords.
|
|
|
|
|
2019-12-18 20:26:10 +01:00
|
|
|
When using local state, state is stored in plain-text JSON files.
|
2017-03-28 21:12:32 +02:00
|
|
|
|
2021-12-15 03:41:17 +01:00
|
|
|
When using [remote state](/language/state/remote), state is only ever held in
|
2019-12-18 20:26:10 +01:00
|
|
|
memory when used by Terraform. It may be encrypted at rest, but this depends on
|
|
|
|
the specific remote state backend.
|
2017-03-28 21:12:32 +02:00
|
|
|
|
|
|
|
## Recommendations
|
|
|
|
|
2019-12-18 20:26:10 +01:00
|
|
|
If you manage any sensitive data with Terraform (like database passwords, user
|
|
|
|
passwords, or private keys), treat the state itself as sensitive data.
|
2017-03-28 21:12:32 +02:00
|
|
|
|
2019-12-18 20:26:10 +01:00
|
|
|
Storing state remotely can provide better security. As of Terraform 0.9,
|
|
|
|
Terraform does not persist state to the local disk when remote state is in use,
|
|
|
|
and some backends can be configured to encrypt the state data at rest.
|
2017-03-28 21:12:32 +02:00
|
|
|
|
2019-12-18 20:26:10 +01:00
|
|
|
For example:
|
2017-03-28 21:12:32 +02:00
|
|
|
|
2021-12-15 03:41:17 +01:00
|
|
|
- [Terraform Cloud](/cloud) always encrypts state at rest and
|
2019-12-18 20:26:10 +01:00
|
|
|
protects it with TLS in transit. Terraform Cloud also knows the identity of
|
|
|
|
the user requesting state and maintains a history of state changes. This can
|
2021-12-15 03:41:17 +01:00
|
|
|
be used to control access and track activity. [Terraform Enterprise](/enterprise)
|
2019-12-18 20:26:10 +01:00
|
|
|
also supports detailed audit logging.
|
|
|
|
- The S3 backend supports encryption at rest when the `encrypt` option is
|
|
|
|
enabled. IAM policies and logging can be used to identify any invalid access.
|
|
|
|
Requests for the state go over a TLS connection.
|