Declined feature verdict · build Solution request
210 searches/mo+84% ↑breakout

Terraform state encryption layer for sensitive values

Built for DevOps engineers and infrastructure teams using Terraform in collaborative or version-controlled environments who need to protect secrets in state files..

“[declined by hashicorp/terraform: closed as not planned] Currently we have several resources that retrieve or generate secrets, and for any where these secrets …”

The receipts — real demand

“[declined by hashicorp/terraform: closed as not planned] Currently we have several resources that retrieve or generate secrets, and for any where these secrets are used to populate other resources or configure other providers these secrets must necessarily be stored in the state. Such resources include: - `aws_db_cluster` (password attribute) - `azurerm_virtual_machine` (machine login passwords) - `tls_private_key` …”
Declined feature · view original →

Full dossier

Unlock the full dossier — free

Every corroborating quote, the source receipts, and the community echo. One email, no payment.

5.8 / 10 · demand score
Pain 8
Willingness to pay 3
Feasibility 4
Specificity 7
Audience 8
Competition 8

Why this is a gap

Surfaced from a high-intensity complaint with clear willingness to pay and a specific, reachable audience.

The market

DevOps engineers and infrastructure teams using Terraform in shared version control who need to protect secrets in state files. No search volume, but HashiCorp's explicit closure of this as 'not planned' signals unmet demand they won't solve.

Competition & the opening

Category giants · 8/10

Terraform Cloud (remote state), HashiCorp Vault, and git-secrets exist; the gap is a lightweight, drop-in encryption layer that works with local or shared state without replacing Terraform's native state workflow.

What's hard to build

Integrating with Terraform's state locking and remote backends requires deep understanding of Terraform internals and state file format. Key rotation, backup/recovery, and audit logging add complexity. One wrong implementation compromises all secrets.

Why now

Terraform state file leaks and compliance requirements for encrypted secrets at rest remain unsolved after HashiCorp declined the feature.

How you'd monetize

$49/mo SaaS or per-state-file usage-based