- The HCP deploy contract: names Terraform writes and GitHub Actions reads (`/<repo>/deploy/*` in each account). See [hcp-terraform.md](hcp-terraform.md#deploy-contract-ssm).
Do not put build identity (`GIT_SHA`, release labels) in Terraform-managed Lambda environment variables. Inline it at build time in GitHub Actions so an apply cannot regress the reported version.
- **Never use Lambda environment variables for sensitive values.** Even with `NoEcho` CloudFormation parameters, the values end up as plaintext in the Lambda console and are readable by anyone with `GetFunctionConfiguration` access.
- **Never commit `.env` files** containing real values to a repository.
- **Never store sensitive values** in Notion, Slack messages, or other plaintext documents.