Skip to main content

MAZENG-FT-26 · Manage Terraform input variables

Feature intent

Users need a safe way to manage revisioned secret and non-secret project inputs used consistently by generated code and infrastructure actions.

Why it matters

Users need a safe way to manage revisioned secret and non-secret project inputs used consistently by generated code and infrastructure actions.

Expected outcome

Authorized project members can manage Terraform variable definitions without exposing secrets and can rely on generation and execution using the same revision.

In scope

  • List, create, update, and delete project variable definitions with required and secret semantics.
  • Prevent secret values from being returned as ordinary clear-text list data or emitted in command output.
  • Derive generated variable declarations and execution inputs from the same revisioned definitions.
  • Treat the legacy implementation as evidence of intent only; completion requires an explicit product decision and safe end-to-end design.
Delivery status
IN_BACKLOG
Owner
RootAtSkic (product lead)
Parent Epic
MAZENG-EP-7
Solution approval
PENDING

Acceptance

Acceptance outcomes

  1. 01

    Authorized project members can list, create, update, and delete variable definitions, with required and secret semantics enforced.

  2. 02

    Secret values are never returned as ordinary clear-text list data or exposed in generated command output.

  3. 03

    Generated variables.tf declarations and execution inputs are derived from the same revisioned definitions.

Dependencies and risks

Dependencies

None recorded.

Risks

  • The legacy toolbar and generated variable declarations are incomplete, so no complete user experience is proven.
  • Insufficient project-role authorization or ordinary clear-text responses can expose secret values.

Authoritative Architecture tasks

No authoritative Architecture tasks are linked.

Original source