{"record":{"id":"11b927aa90dfc86c","repo":"hashicorp/terraform","slug":"failed-to-create-project-s-v","errorCode":null,"errorMessage":"failed to create project %s: %v","messagePattern":"failed to create project (.+?): (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/cloud/backend.go","lineNumber":799,"sourceCode":"\n\t\tif b.WorkspaceMapping.Strategy() == WorkspaceTagsStrategy {\n\t\t\tworkspaceCreateOptions.Tags = b.WorkspaceMapping.tfeTags()\n\t\t} else if b.WorkspaceMapping.Strategy() == WorkspaceKVTagsStrategy {\n\t\t\tworkspaceCreateOptions.TagBindings = b.WorkspaceMapping.asTFETagBindings()\n\t\t}\n\n\t\t// Create project if not exists, otherwise use it\n\t\tif workspaceCreateOptions.Project == nil && b.WorkspaceMapping.Project != \"\" {\n\t\t\t// If we didn't find the project, try to create it\n\t\t\tif workspaceCreateOptions.Project == nil {\n\t\t\t\tcreateOpts := tfe.ProjectCreateOptions{\n\t\t\t\t\tName: b.WorkspaceMapping.Project,\n\t\t\t\t}\n\t\t\t\t// didn't find project, create it instead\n\t\t\t\tlog.Printf(\"[TRACE] cloud: Creating %s project %s/%s\", b.appName, b.Organization, b.WorkspaceMapping.Project)\n\t\t\t\tproject, err := b.client.Projects.Create(context.Background(), b.Organization, createOpts)\n\t\t\t\tif err != nil && err != tfe.ErrResourceNotFound {\n\t\t\t\t\treturn nil, diags.Append(fmt.Errorf(\"failed to create project %s: %v\", b.WorkspaceMapping.Project, err))\n\t\t\t\t}\n\t\t\t\tconfiguredProject = project\n\t\t\t\tworkspaceCreateOptions.Project = configuredProject\n\t\t\t}\n\t\t}\n\n\t\t// Create a workspace\n\t\tlog.Printf(\"[TRACE] cloud: Creating %s workspace %s/%s\", b.appName, b.Organization, name)\n\t\tworkspace, err = b.client.Workspaces.Create(context.Background(), b.Organization, workspaceCreateOptions)\n\t\tif err != nil {\n\t\t\treturn nil, diags.Append(fmt.Errorf(\"error creating workspace %s: %v\", name, err))\n\t\t}\n\n\t\tremoteTFVersion = workspace.TerraformVersion\n\n\t\t// Attempt to set the new workspace to use this version of Terraform. This\n\t\t// can fail if there's no enabled tool_version whose name matches our\n\t\t// version string, but that's expected sometimes -- just warn and continue.","sourceCodeStart":781,"sourceCodeEnd":817,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/cloud/backend.go#L781-L817","documentation":"Thrown by the Cloud backend when auto-creating a TFE/HCP project named in the `cloud { project = ... }` block. The backend first attempted a lookup that returned nothing, then called Projects.Create; any failure other than tfe.ErrResourceNotFound is surfaced here. ErrResourceNotFound from Create is intentionally swallowed (it signals the projects feature is absent), but every other API failure (auth, name conflict, validation, transport) propagates.","triggerScenarios":"b.client.Projects.Create(ctx, b.Organization, createOpts) returns err != nil AND err != tfe.ErrResourceNotFound. Concretely: 401/403 when the token lacks org-level project-management scope; 409 if a project with that name appears between the lookup and the create (race); 422 for names with illegal characters; 5xx or network/timeout from the TFE/TFE-instance host.","commonSituations":"A user adds `project = \"team-a\"` to a cloud block expecting auto-creation, but the API token only has workspace-level permissions. Or two developers running `terraform init` simultaneously against a fresh project name. Or a project name containing spaces/slashes that the API rejects.","solutions":["Pre-create the project in the TFE/HCP UI (or via API) and keep the cloud block referencing its name so Create is never attempted.","Grant the service token organization-level 'Manage Projects' (or admin) permission so Projects.Create succeeds.","Sanitize the project name to [A-Za-z0-9_-] and stay within length limits before running init.","For concurrent pipelines racing on a new project, gate project creation behind a single job or use an external provisioner."],"exampleFix":"// before\ncloud {\n  organization = \"acme\"\n  project      = \"Team A Workspace!\"\n  workspaces { name = \"prod\" }\n}\n\n// after\ncloud {\n  organization = \"acme\"\n  project      = \"team-a\"\n  workspaces { name = \"prod\" }\n}","handlingStrategy":"validation","validationCode":"// before init, preflight project creation prerequisites\nfunc canCreateProject(client *tfe.Client, org, project string) error {\n    if !regexp.MustCompile(`^[A-Za-z0-9_-]+$`).MatchString(project) {\n        return fmt.Errorf(\"project name %q has invalid characters\", project)\n    }\n    // verify org is reachable and token has admin scope\n    if _, err := client.Organizations.Read(ctx, org); err != nil {\n        return fmt.Errorf(\"cannot read org %s: %w\", org, err)\n    }\n    // if project already exists, Create won't be attempted\n    if p, err := client.Projects.Read(ctx, org, project); err == nil {\n        _ = p // exists, safe\n    } else if err != tfe.ErrResourceNotFound {\n        return err\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Pre-create projects out-of-band so the auto-create path never runs.","Give the init token org-level project-management scope, or none and pre-create.","Validate project names against [A-Za-z0-9_-] before applying.","Serialize concurrent `init` runs that target a brand-new project name."],"tags":["tfe","hcp","cloud-backend","project","permissions"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}