IdeaSift

Terraform operators lack fine-grained control over CLI workflows

Terraform operators want more control over what CLI commands reveal and which resources they affect. Refresh output can expose values users consider sensitive, while other requests seek concise plans, simpler access to sensitive state, and more selective handling of protected resources. Current workarounds include inspecting raw state JSON or reverse-engineering module code; a companion tool could address several of these needs, though some require changes to Terraform itself.

For terraform infrastructure operators. Mentioned from Apr 2017 to Dec 2022 on GitHub.

6 different people described this problem in 5 separate discussions.

Week of 2026-07-13: 0Week of 2026-07-20: 0Week of 2026-07-27: 0Week of 2026-08-03: 0Week of 2026-08-10: 0Week of 2026-08-17: 0Week of 2026-08-24: 0Week of 2026-08-31: 0Week of 2026-09-07: 0Week of 2026-09-14: 0Week of 2026-09-21: 0Week of 2026-09-28: 0
0 mentions in the last 12 weeks
Indie fit
4.0/10
Pain
6.0/10
Frequency
7.0/10
Willingness to pay
0.0/10
Momentum
5.0/10
Who pays
Professionals
Competition
Medium
Build difficulty
Medium

What people said

Quoted word for word. Follow a link to read the whole discussion.

  1. For instance, you have a kubernetes configmap managed by terraform, but the field gets updated by something outside terraform. Even if is listed in , during the refresh stage, it outputs any changes that have occurred. This could expose things the user doesn't want exposed
  2. right now extracting a sensitive value is unnecessarily complicated. 1. the sensitive values are easily viewable in the state file. a simple terraform state pull will let anyone see them
    james-lawrence on GitHub (hashicorp/terraform)Dec 2022+89 upvotesHas a workaroundAsked for a tool
Build brief

See what to build and who will buy it

  • 2 product ideas with the smallest useful version and pricing
  • 4 places to find your first customers
  • 4 more quotes from people who have this problem
  • Current workarounds, existing solutions and risks