{"record":{"id":"023ed4c28180cf48","repo":"hashicorp/terraform","slug":"failed-to-access-object-s-in-bucket-s-w","errorCode":null,"errorMessage":"failed to access object '%s' in bucket '%s': %w","messagePattern":"failed to access object '(.+?)' in bucket '(.+?)': %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/oci/client.go","lineNumber":74,"sourceCode":"\t\tBucketName:    common.String(c.bucketName),\n\t\tRequestMetadata: common.RequestMetadata{\n\t\t\tRetryPolicy: getDefaultRetryPolicy(),\n\t\t},\n\t}\n\tif c.SSECustomerKey != \"\" && c.SSECustomerKeySHA256 != \"\" {\n\t\theadRequest.OpcSseCustomerKey = common.String(c.SSECustomerKey)\n\t\theadRequest.OpcSseCustomerKeySha256 = common.String(c.SSECustomerKeySHA256)\n\t\theadRequest.OpcSseCustomerAlgorithm = common.String(c.SSECustomerAlgorithm)\n\t}\n\t// Get object from OCI\n\theadResponse, headErr := c.objectStorageClient.HeadObject(ctx, headRequest)\n\tif headErr != nil {\n\t\tvar ociHeadErr common.ServiceError\n\t\tif errors.As(headErr, &ociHeadErr) && ociHeadErr.GetHTTPStatusCode() == 404 {\n\t\t\tlogger.Debug(\" State file '%s' not found. Initializing Terraform state...\", c.path)\n\t\t\treturn &remote.Payload{}, nil\n\t\t} else {\n\t\t\treturn nil, fmt.Errorf(\"failed to access object '%s' in bucket '%s': %w\", c.path, c.bucketName, headErr)\n\t\t}\n\t}\n\n\tgetRequest := objectstorage.GetObjectRequest{\n\t\tNamespaceName: common.String(c.namespace),\n\t\tObjectName:    common.String(c.path),\n\t\tBucketName:    common.String(c.bucketName),\n\t\tIfMatch:       headResponse.ETag,\n\t\tRequestMetadata: common.RequestMetadata{\n\t\t\tRetryPolicy: getDefaultRetryPolicy(),\n\t\t},\n\t}\n\tif c.SSECustomerKey != \"\" && c.SSECustomerKeySHA256 != \"\" {\n\t\tgetRequest.OpcSseCustomerKey = common.String(c.SSECustomerKey)\n\t\tgetRequest.OpcSseCustomerKeySha256 = common.String(c.SSECustomerKeySHA256)\n\t\tgetRequest.OpcSseCustomerAlgorithm = common.String(c.SSECustomerAlgorithm)\n\t}\n\t// Get object from OCI","sourceCodeStart":56,"sourceCodeEnd":92,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/oci/client.go#L56-L92","documentation":"HeadObject returned a non-nil error that is not a 404 ServiceError, so the backend surfaces a wrapped generic access error. This is the metadata-fetch step of getObject; only 404 is treated as 'state not found, initialize'. Any other failure (auth, 403, 412, 5xx, transport, SSE-C mismatch) lands here.","triggerScenarios":"Wrong SSE-C customer key/sha256 supplied (403/412 on a customer-encrypted object); IAM policy missing OBJECT_READ on the bucket; wrong namespace or bucket name; transient OCI 5xx; bucket deleted or in a different region.","commonSituations":"SSE-C key rotated and backend config not updated; instance principal missing the dynamic group/role; wrong `namespace` in backend config (namespace is tenancy-specific, not region); bucket renamed.","solutions":["If using SSE-C, confirm `sse_customer_key`, `sse_customer_key_sha256`, and `sse_customer_algorithm` match the key used to write the object.","Verify the IAM principal has OBJECT_READ/OBJECT_INSPECT on the bucket and that namespace/bucket names are correct.","For transient 5xx, retry — getDefaultRetryPolicy already retries idempotent reads but custom transport or non-retryable codes may bypass it.","Check OCI service health for the objectstorage service in the region."],"exampleFix":"// before: misconfigured SSE-C (key rotated, sha256 stale)\nterraform {\n  backend \"oci\" {\n    bucket               = \"tf-state\"\n    namespace            = \"idxx\"\n    key                  = \"prod.tfstate\"\n    sse_customer_key     = var.key     // rotated\n    sse_customer_key_sha256 = var.old_sha // stale -> 303\n  }\n}\n// after: regenerate sha256 from the same key and pass both\nterraform {\n  backend \"oci\" {\n    bucket               = \"tf-state\"\n    namespace            = \"idxx\"\n    key                  = \"prod.tfstate\"\n    sse_customer_key     = var.key\n    sse_customer_key_sha256 = filesha256(\"sse.key\") // matches\n  }\n}","handlingStrategy":"try-catch","validationCode":"// Validate SSE-C config symmetry before any read\nfunc validateSSEC(c *RemoteClient) error {\n    hasKey := c.SSECustomerKey != \"\"\n    hasSha := c.SSECustomerKeySHA256 != \"\"\n    if hasKey != hasSha {\n        return fmt.Errorf(\"SSE-C requires both sse_customer_key and sse_customer_key_sha256\")\n    }\n    return nil\n}","typeGuard":"func isServiceError(err error) (common.ServiceError, bool) {\n    var se common.ServiceError\n    return se, errors.As(err, &se)\n}","tryCatchPattern":"if _, err := c.objectStorageClient.HeadObject(ctx, headRequest); err != nil {\n    var se common.ServiceError\n    if errors.As(err, &se) {\n        switch se.GetHTTPStatusCode() {\n        case 403: // fix IAM/SSE-C\n        case 404: // treat as not-found\n        }\n    }\n    // non-OCI transport error -> retry/backoff\n}","preventionTips":["Keep SSE-C key and sha256 in sync (store both as a pair in your secret manager).","Validate namespace and bucket name at backend config load.","Grant the principal OBJECT_INSPECT/OBJECT_READ on the bucket.","Use OCI service gateways to avoid public-internet transport failures."],"tags":["oci","object-storage","encryption","iam","network"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}