Don't commit secrets.
Where should the AWS access key for Terraform live?
A) Hard-coded in main.tf (committed to git).
B) In a secrets manager (AWS Secrets Manager, Vault, SOPS, env vars
injected at runtime, OIDC for CI). Never plain text in the repo.
C) Pasted into Slack so the team can find them.
D) On a sticky note on the monitor.Sign in to save your code and track progress across devices.