{"record":{"id":"002c9a50cb092f70","repo":"hashicorp/terraform","slug":"could-not-decode-output-s-id-s","errorCode":null,"errorMessage":"could not decode output %s (ID %s)","messagePattern":"could not decode output (.+?) \\(ID (.+?)\\)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/cloud/state.go","lineNumber":612,"sourceCode":"\t\t\t\treturn nil, ErrStateVersionUnauthorizedUpgradeState\n\t\t\t}\n\n\t\t\treturn state.RootOutputValues, nil\n\t\t}\n\n\t\tif output.Sensitive {\n\t\t\t// Since this is a sensitive value, the output must be requested explicitly in order to\n\t\t\t// read its value, which is assumed to be present by callers\n\t\t\tsensitiveOutput, err := s.tfeClient.StateVersionOutputs.Read(ctx, output.ID)\n\t\t\tif err != nil {\n\t\t\t\treturn nil, fmt.Errorf(\"could not read state version output %s: %w\", output.ID, err)\n\t\t\t}\n\t\t\toutput.Value = sensitiveOutput.Value\n\t\t}\n\n\t\tcval, err := tfeOutputToCtyValue(*output)\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"could not decode output %s (ID %s)\", output.Name, output.ID)\n\t\t}\n\n\t\tresult[output.Name] = &states.OutputValue{\n\t\t\tValue:     cval,\n\t\t\tSensitive: output.Sensitive,\n\t\t}\n\t}\n\n\treturn result, nil\n}\n\nfunc clamp(val, min, max int64) int64 {\n\tif val < min {\n\t\treturn min\n\t} else if val > max {\n\t\treturn max\n\t}\n\treturn val","sourceCodeStart":594,"sourceCodeEnd":630,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/cloud/state.go#L594-L630","documentation":"Thrown by GetRootOutputValues when tfeOutputToCtyValue fails to convert a TFE state version output into a cty.Value. Note this error does NOT use %w — the underlying cause (marshal failure, type-interpret failure, or value-coercion failure from errors 536/537/538) is intentionally dropped, showing only the output name and ID. This makes root-cause diagnosis harder without terraform debug logs.","triggerScenarios":"Any failure inside tfeOutputToCtyValue: json.Marshal of DetailedType fails, cty.Type.UnmarshalJSON cannot parse the type, or gocty.ToCtyValue cannot coerce the value to the type; a corrupted or schema-incompatible output in the remote state.","commonSituations":"State written by one terraform/provider version being read by an incompatible version; an output whose type schema changed across provider versions; corrupted state version output data from a partial/failed upload.","solutions":["Enable TF_LOG=DEBUG to see which sub-error (536/537/538) triggered inside tfeOutputToCtyValue, since this wrapper drops the cause","Upgrade terraform and all providers to compatible, current versions","If one output is identified, remove or correct it in configuration and re-apply to overwrite the bad output","As a last resort, use terraform state pull, manually inspect the offending output, and terraform state push a corrected state"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":"// Before calling GetRootOutputValues, probe-decode each output if you have the raw data:\n// (Not always feasible since tfeOutputToCtyValue is internal; rely on TF_LOG=DEBUG instead.)\nos.Setenv(\"TF_LOG\", \"DEBUG\") // surface which sub-error (536/537/538) caused the decode failure","typeGuard":null,"tryCatchPattern":"outputs, err := state.GetRootOutputValues(ctx)\nif err != nil && strings.Contains(err.Error(), \"could not decode output\") {\n    // The underlying cause is dropped (no %w). Enable TF_LOG=DEBUG to get details.\n    return nil, fmt.Errorf(\"output decode failed (enable TF_LOG=DEBUG for root cause): %s\", err.Error())\n}\nreturn outputs, err","preventionTips":["Keep terraform and provider versions aligned and current to avoid type-encoding incompatibilities","When this error appears, immediately enable TF_LOG=DEBUG since the wrapper drops the underlying cause","After provider upgrades, test output decoding on a staging workspace before production"],"tags":["outputs","cty","type-decoding","tfe","terraform"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}