Terraform operators lack fine-grained control over CLI workflows
Terraform operators want more control over what CLI commands reveal and which resources they affect. Refresh output can expose values users consider sensitive, while other requests seek concise plans, simpler access to sensitive state, and more selective handling of protected resources. Current workarounds include inspecting raw state JSON or reverse-engineering module code; a companion tool could address several of these needs, though some require changes to Terraform itself.
For terraform infrastructure operators. Mentioned from Apr 2017 to Dec 2022 on GitHub.
6 different people described this problem in 5 separate discussions.
- Indie fit
- 4.0/10
- Pain
- 6.0/10
- Frequency
- 7.0/10
- Willingness to pay
- 0.0/10
- Momentum
- 5.0/10
- Who pays
- Professionals
- Competition
- Medium
- Build difficulty
- Medium
What people said
Quoted word for word. Follow a link to read the whole discussion.
For instance, you have a kubernetes configmap managed by terraform, but the field gets updated by something outside terraform. Even if is listed in , during the refresh stage, it outputs any changes that have occurred. This could expose things the user doesn't want exposed
right now extracting a sensitive value is unnecessarily complicated. 1. the sensitive values are easily viewable in the state file. a simple terraform state pull will let anyone see them
Build brief
See what to build and who will buy it
- 2 product ideas with the smallest useful version and pricing
- 4 places to find your first customers
- 4 more quotes from people who have this problem
- Current workarounds, existing solutions and risks