Clear it in 3 steps
Start the environment
Investigate the target
Submit the flag

Analyze a generated tfstate artifact without initializing a Terraform provider. Recover the flag from the audit_only resource recovery payload.
Inspect terraform/terraform.tfstate
Find the recovery_payload_b64 attribute
Base64-decode its value