Hedronite · Cert Lesson · Cert-Prep / HashiCorp · Wed 2026-09-17

Terraform Associate: ephemeral, sensitive, write-only — versions that signal rotation

Sensitive hides. Ephemeral borrows. Write-only forgets.

Lesson Class: Cert-prep (Associate 003 / Pro-depth)
Map: sensitive vs ephemeral vs write-only + *_wo_version
Ops Referent: Azure Key Vault value_wo / MySQL administrator_password_wo
Grounding: Lab 24 · HashiCorp Developer docs · Brikman Ch.6 referenced
Sensitive
Redacts UI; may still persist in state.
Ephemeral
Operation-local source values.
Write-only
Provider sinks omitted from artifacts; version rotates.
Do not collapse the three layers. Name which store still holds the secret.

<!-- hal:authoritative:yaml -->

The exam still asks about sensitive. Pro-depth now asks what never enters state. Name the three layers without collapsing them.

§I — Frame

09-14 Cert practiced declarative import and moved blocks. 09-08 Cert practiced validation, checks, and tests. Keep those.

Ops today uses ephemeral random_password, Key Vault value_wo, and MySQL administrator_password_wo. Lab 24 still drills sensitive variables and outputs. Your job is the vocabulary map Associate and Pro-depth expect when those tools sit side by side.

§II — Objective map

Sensitive attributes and outputs. Marking sensitive redacts CLI and UI presentation. Values can still persist in state. Lab 24 is the muscle memory. Exam traps often confuse "hidden in output" with "absent from state."

Ephemeral values. Ephemeral resources (and related ephemeral constructs) exist for the current Terraform operation. They are not ordinary managed state citizens. They are ideal sources for secrets you intend to hand to write-only sinks.

Write-only arguments. Provider schema flags (often _wo) accept values during the operation and do not persist them in plan or state artifacts. Terraform cannot diff what it never stored, so providers pair a version argument (_wo_version) you increment to force an update.

Version companions. When the exam or a scenario asks "how do you rotate a write-only password," the answer is bump the version argument and supply the new write-only value, not expect a plaintext state diff.

§III — Discriminators (memorize)

  1. If the value must remain available to later Terraform runs as state data, sensitive may apply, but write-only is the wrong tool.
  2. If the value must configure a remote API once per operation and must not remain in Terraform artifacts, prefer write-only (Terraform >= 1.11, provider support required).
  3. If the value is generated only to feed such a sink, prefer an ephemeral resource as the source.
  4. nonsensitive() is a deliberate reveal for composition, not a substitute for write-only absence.
  5. Provider support matters: write-only is not a core language keyword you can attach to arbitrary arguments.

§III.b — Version argument mechanics (Pro-depth)

Terraform cannot create a plan diff for a write-only value it never stored. Providers therefore expose a normal, stored integer (or similar) version argument. Incrementing that integer is how practitioners declare "send the write-only value again as an intentional update."

Exam phrasing to expect: "Which argument should you change to rotate a database password configured with a write-only argument?" Prefer the version companion over "replace the resource" or "terraform taint" folklore unless the scenario forces replace.

Requirements reminder: Terraform 1.11 or later, and a resource schema that actually declares write-only arguments. Associate may ask the conceptual distinction; Pro-depth can require recognizing Registry _wo / _wo_version pairs.

§IV — Azure concrete referent (Ops refraction)

HashiCorp documents:

Associate may stay conceptual. Pro-depth can ask which attribute is absent from state after apply. Answer with write-only, not sensitive.

§IV.b — Sample stems (self-check)

Stem A: A password is marked sensitive = true on a variable and passed to azurerm_key_vault_secret.value. After apply, where can the value still exist? Answer shape: remote Key Vault and Terraform state (possibly redacted in UI).

Stem B: Same password passed to value_wo with value_wo_version = 1. After apply, which store should lack the plaintext attribute? Answer shape: Terraform plan/state artifacts for that argument.

Stem C: You must rotate the write-only password. Which configuration change does Terraform plan on? Answer shape: the version companion (and provider update behavior), not a stored old/new secret diff.

Drill these aloud before Maghrib. Ops supplies the Azure nouns. Lab 24 supplies the sensitive counterexample.

§V — Trap set

§VI — Close

Sensitive hides. Ephemeral borrows. Write-only forgets. Lab 24 proves the first. Ops Azure path proves the second and third. Dev census asserts the forget in JSON.

Re-authored on the lab Mac SoT 2026-09-18 after vault mirror clobber of Bot-only #123.