use opentofu encrypted state feature https://opentofu.org/docs/language/state/encryption/#new-project
backend, only TRITON_KEY_ID required in env now. Also add .terraform to gitignore and add terraform lock file