- Functions
- nonsensitive
nonsensitive
Function
nonsensitive
takes a sensitive value and returns a copy of that value with
the sensitive marking removed, thereby exposing the sensitive value.
Using this function indiscriminately will cause values that OpenTofu would normally have considered as sensitive to be treated as normal values and shown clearly in OpenTofu's output. Use this function only when you've derived a new value from a sensitive value in a way that eliminates the sensitive portions of the value.
Normally OpenTofu tracks when you use expressions to derive a new value from a value that is marked as sensitive, so that the result can also be marked as sensitive.
However, you may wish to write expressions that derive non-sensitive results
from sensitive values. For example, if you know based on details of your
particular system and its threat model that a SHA256 hash of a particular
sensitive value is safe to include clearly in OpenTofu output, you could use
the nonsensitive
function to indicate that, overriding OpenTofu's normal
conservative behavior:
Another example might be if the original value is only partially sensitive and you've written expressions to separate the sensitive and non-sensitive parts:
When you use this function, it's your responsibility to ensure that the
expression passed as its argument will remove all sensitive content from
the sensitive value it depends on. By passing a value to nonsensitive
you are
declaring to OpenTofu that you have done all that is necessary to ensure that
the resulting value has no sensitive content, even though it was derived
from sensitive content. If a sensitive value appears in OpenTofu's output
due to an inappropriate call to nonsensitive
in your module, that's a bug in
your module and not a bug in OpenTofu itself.
Use this function sparingly and only with due care.
nonsensitive
allows passing a value that isn't marked as sensitive,
even though such a call may be redundant and potentially confusing
or misleading to a future maintainer of your module.
Consider including a comment adjacent to your call to explain to future maintainers what makes the usage safe and thus what invariants they must take care to preserve under future modifications.
Examples
The following examples are from tofu console
when running in the
context of the example above with variable "mixed_content_json"
and
the local value mixed_content
, with a valid JSON string assigned to
var.mixed_content_json
.
Note though that it's always your responsibility to use nonsensitive
only
when it's safe to do so. If you use nonsensitive
with content that
ought to be considered sensitive then that content will be disclosed: