Skip to main content

Allow sensitive values to be read from stack

Currently the only way to read sensitive values from a stack is to running a task that runs tofu output <output name> . This works - but has a major flaw, it exposes the sensitive output value to anyone who has read only on the stack.

We’d like a way to directly view sensitive outputs in the stack UI (and potentially via tools like spacectl) which is locked behind a more privileged permission than Read only. This could be stack write or (better) a specific, new permission for viewing sensitive outputs.

Workaround
Problem

Log in to comment and vote

No comments yet

Be the first to share your thoughts.