State of Affairs

You've gained access to a container running some infrastructure automation. A cron job executes Terraform every minute to keep certificates fresh.

The flag is stored in a privileged user's home directory - but you're just a regular user with no direct access.

Can you find a way to make Terraform work for you?

Good luck!

Pasha Resnianski Avatar

Author

Pasha Resnianski

"Terraform state files are often overlooked as a security boundary. Supply chain security applies to your IaC tooling too."

Terminal