Potential command injection vulnerability when using yq with user-controlled cluster config.
Unquoted variable substitution could lead to command injection if cluster name contains special characters.
Command substitution with 'tofu output' could fail silently; add error handling or validation for the fallback values.
Command substitution with 'tofu output' could fail silently; add error handling or validation for the fallback values.
Command substitution with 'tofu output' could fail silently; add error handling or validation for the fallback values.
Using exec with user-provided arguments ($@) before --destroy creates a command injection risk if malicious arguments are passed.
Authentication credentials should be explicitly documented or validated to ensure they're properly set via environment variables.
Document the required environment variables in a README or use Terraform variables with descriptions instead of relying solely on comments.
Control plane API is exposed to the entire internet with 0.0.0.0/0 CIDR which creates a security risk.