zitadel_application_v2zitadel_application_v2 resource with an OIDC or API configuration, the generated client_secretclient_secret is currently persisted as a computed attribute in Terraform state. Since Terraform state is often stored in shared backends and may not always be encrypted, this means the secret ends up at rest in a place that may receive less scrutiny than a dedicated secrets store.client_secretclient_secret attribute on zitadel_application_v2zitadel_application_v2 itself should be removed, so there is no longer any path by which the secret ends up in state.Join the Discord to ask follow-up questions and connect with the community