Terraform state encryption layer for sensitive values
Built for DevOps engineers and infrastructure teams using Terraform in collaborative or version-controlled environments who need to protect secrets in state files..
“[declined by hashicorp/terraform: closed as not planned] Currently we have several resources that retrieve or generate secrets, and for any where these secrets …”
The receipts — real demand
“[declined by hashicorp/terraform: closed as not planned] Currently we have several resources that retrieve or generate secrets, and for any where these secrets are used to populate other resources or configure other providers these secrets must necessarily be stored in the state. Such resources include: - `aws_db_cluster` (password attribute) - `azurerm_virtual_machine` (machine login passwords) - `tls_private_key` …”
Full dossier
Unlock the full dossier — free
Every corroborating quote, the source receipts, and the community echo. One email, no payment.
Why this is a gap
Surfaced from a high-intensity complaint with clear willingness to pay and a specific, reachable audience.
The market
DevOps engineers and infrastructure teams using Terraform in shared version control who need to protect secrets in state files. No search volume, but HashiCorp's explicit closure of this as 'not planned' signals unmet demand they won't solve.
Competition & the opening
Terraform Cloud (remote state), HashiCorp Vault, and git-secrets exist; the gap is a lightweight, drop-in encryption layer that works with local or shared state without replacing Terraform's native state workflow.
What's hard to build
Integrating with Terraform's state locking and remote backends requires deep understanding of Terraform internals and state file format. Key rotation, backup/recovery, and audit logging add complexity. One wrong implementation compromises all secrets.
Why now
Terraform state file leaks and compliance requirements for encrypted secrets at rest remain unsolved after HashiCorp declined the feature.
How you'd monetize
$49/mo SaaS or per-state-file usage-based