Stop Encrypting tfstate. Start Expiring the Secrets Inside It.
Encrypting Terraform state doesn't solve the problem. It delays it. Every IAM key and database password in your tfstate is a long-lived credential waiting to be found. Here's what to do instead.