Your security team scanned some Terraform workspaces and found secrets stored in plaintext in state files. How can you protect that data?