API secrets in Tencent Cloud CVM user data

Keep long-lived API keys out of instance user data.

Description

API secrets in user_data or user_data_raw can be exposed through initialization data, Terraform state, or logs. Base64 encoding does not encrypt secrets.

Potential impact

Anyone obtaining the keys may access Tencent Cloud resources permitted by those credentials.

Remediation

Remove long-lived keys and attach a least-privilege role with cam_role_name. Configure applications to use the role’s temporary credentials and revoke any exposed keys.

Examples

The illustrated keys are placeholders, not real credentials. The revised excerpt attaches a previously created role and removes keys from the initialization script. Other instance settings are omitted.

Before

hcl
resource "tencentcloud_instance" "example" {
  instance_name = "cvm-postpaid"

  user_data = base64encode("#!/bin/sh\nexport TENCENTCLOUD_SECRET_ID=example-id; export TENCENTCLOUD_SECRET_KEY=example-key")
}

After

hcl
resource "tencentcloud_instance" "example" {
  instance_name = "cvm-postpaid"
  cam_role_name = "cvm-access-role"

  user_data = base64encode("#!/bin/sh\necho instance bootstrap")
}

References