Description
API secrets in user_data or user_data_raw can be exposed through initialization data, Terraform state, or logs. Base64 encoding does not encrypt secrets.
Potential impact
Anyone obtaining the keys may access Tencent Cloud resources permitted by those credentials.
Remediation
Remove long-lived keys and attach a least-privilege role with cam_role_name. Configure applications to use the role’s temporary credentials and revoke any exposed keys.
Examples
The illustrated keys are placeholders, not real credentials. The revised excerpt attaches a previously created role and removes keys from the initialization script. Other instance settings are omitted.
Before
hcl
resource "tencentcloud_instance" "example" {
instance_name = "cvm-postpaid"
user_data = base64encode("#!/bin/sh\nexport TENCENTCLOUD_SECRET_ID=example-id; export TENCENTCLOUD_SECRET_KEY=example-key")
}
After
hcl
resource "tencentcloud_instance" "example" {
instance_name = "cvm-postpaid"
cam_role_name = "cvm-access-role"
user_data = base64encode("#!/bin/sh\necho instance bootstrap")
}