Suggest an existing issue in legacy Terraform to fix in OpenTF.
I already made a PR for full client side state encryption for all backends except the extended backends 2 years ago.
I would be more than happy to either submit it as a stale PR, or just make a PR. Whichever works better for you. I actually have a local patch based on 1.5.5 which I'd just need to commit.
Technical description / Proposal - see comments below - to be added here when at least some consensus is achieved and people have had a chance to comment.
Draft PR see in the comments below, but note that the implementation will likely differ from this PR. I have tried it extensively with state stored on Azure storage accounts, and it is known to work in this scenario. The PR includes documentation as an experimental feature and extensive unit tests.
I would love not to have to maintain an internal fork for this any more :)
Suggest an existing issue in legacy Terraform to fix in OpenTF.
I already made a PR for full client side state encryption for all backends except the extended backends 2 years ago.
I would be more than happy to either submit it as a stale PR, or just make a PR. Whichever works better for you. I actually have a local patch based on 1.5.5 which I'd just need to commit.
Technical description / Proposal - see comments below - to be added here when at least some consensus is achieved and people have had a chance to comment.
Draft PR see in the comments below, but note that the implementation will likely differ from this PR. I have tried it extensively with state stored on Azure storage accounts, and it is known to work in this scenario. The PR includes documentation as an experimental feature and extensive unit tests.
I would love not to have to maintain an internal fork for this any more :)