Generate secure random bytes in Terraform?

Viewed 78

I know that I can generate random bytes in Terraform easily enough:

resource "random_id" "foo" {
  byte_length = 32
}

resource "something_else" "foo" {
  secret = sensitive(random_id.foo.b64std)
}

However, the output of the random_id resource is not marked sensitive, and the value is exposed in logs as the resource id, even though its use in something_else is redacted by the sensitive() function.

I know that random_password is treated as secure, but it doesn't provide the ability to generate raw random bytes.

Is there a good way to generate a secure bunch of random bytes as a Terraform-managed resource?

(I'm aware that the value will always be visible in the state file, but we manage that already. I'm worried about output log files that will much more widely visible.)

EDIT: I found a request to mark random_id secure but the idea was rejected as outside the intended use.

2 Answers

Why don't you use the base64encode function instead? Unfortunately Terraform doesn't support this yet(see link I posted below). Something like this might give you some ideas you could use -

resource "random_string" "this" {
length = 32
}

output "random_string_output" {
value = "'${base64encode(random_string.this.result)}'"
}

This GitHub issue talks about this limitation/workaround quite a bit

There is no such resource or data source in terraform. But you could develop your own custom data source that would produce those "truly random bytes" to your satisfaction.

Related