{"record":{"id":"1351a1f37bca348b","repo":"hashicorp/terraform","slug":"key-can-not-start-and-end-with-1351a1","errorCode":null,"errorMessage":"key can not start and end with '/'","messagePattern":"key can not start and end with '/'","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/oss/backend.go","lineNumber":173,"sourceCode":"\t\t\t\tOptional:    true,\n\t\t\t\tDescription: \"The directory where state files will be saved inside the bucket\",\n\t\t\t\tDefault:     \"env:\",\n\t\t\t\tValidateFunc: func(v interface{}, s string) ([]string, []error) {\n\t\t\t\t\tprefix := v.(string)\n\t\t\t\t\tif strings.HasPrefix(prefix, \"/\") || strings.HasPrefix(prefix, \"./\") {\n\t\t\t\t\t\treturn nil, []error{fmt.Errorf(\"workspace_key_prefix must not start with '/' or './'\")}\n\t\t\t\t\t}\n\t\t\t\t\treturn nil, nil\n\t\t\t\t},\n\t\t\t},\n\n\t\t\t\"key\": {\n\t\t\t\tType:        schema.TypeString,\n\t\t\t\tOptional:    true,\n\t\t\t\tDescription: \"The path of the state file inside the bucket\",\n\t\t\t\tValidateFunc: func(v interface{}, s string) ([]string, []error) {\n\t\t\t\t\tif strings.HasPrefix(v.(string), \"/\") || strings.HasSuffix(v.(string), \"/\") {\n\t\t\t\t\t\treturn nil, []error{fmt.Errorf(\"key can not start and end with '/'\")}\n\t\t\t\t\t}\n\t\t\t\t\treturn nil, nil\n\t\t\t\t},\n\t\t\t\tDefault: \"terraform.tfstate\",\n\t\t\t},\n\t\t\t\"tablestore_instance_name\": {\n\t\t\t\tType:        schema.TypeString,\n\t\t\t\tOptional:    true,\n\t\t\t\tDescription: \"The instance name of tableStore table belongs\",\n\t\t\t\tDefault:     \"\",\n\t\t\t},\n\n\t\t\t\"tablestore_table\": {\n\t\t\t\tType:        schema.TypeString,\n\t\t\t\tOptional:    true,\n\t\t\t\tDescription: \"TableStore table for state locking and consistency\",\n\t\t\t\tDefault:     \"\",\n\t\t\t},","sourceCodeStart":155,"sourceCodeEnd":191,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/oss/backend.go#L155-L191","documentation":"Thrown by the ValidateFunc for the 'key' field in the OSS backend when the state file key starts with '/' or ends with '/'. Note the error message says 'can not start AND end' but the code uses OR logic (HasPrefix OR HasSuffix), so either condition triggers it. This prevents malformed OSS object keys that would create ambiguous state paths.","triggerScenarios":"ValidateFunc checks strings.HasPrefix(v, \"/\") or strings.HasSuffix(v, \"/\"). The user sets 'key' to '/terraform.tfstate', 'terraform/', or '/state/'. The default value is 'terraform.tfstate'.","commonSituations":"Developer uses leading '/' thinking of absolute paths ('/project/state.tfstate'). Developer uses trailing '/' treating key as a directory ('project/'). Copy-paste from S3 backend where key conventions differ. Confusion between OSS object keys and filesystem paths.","solutions":["Ensure the key does not start or end with '/' — use 'project/state.tfstate' instead of '/project/state.tfstate'.","Verify the key includes the filename, not just a path prefix.","Keep the default 'terraform.tfstate' if you don't need custom paths."],"exampleFix":"// before\nterraform {\n  backend \"oss\" {\n    key = \"/project/terraform.tfstate\"\n  }\n}\n// after\nterraform {\n  backend \"oss\" {\n    key = \"project/terraform.tfstate\"\n  }\n}","handlingStrategy":"validation","validationCode":"// Validate OSS backend key before Terraform init\nfunc validateOSSKey(key string) error {\n    if strings.HasPrefix(key, \"/\") {\n        return fmt.Errorf(\"key must not start with '/'; got %q\", key)\n    }\n    if strings.HasSuffix(key, \"/\") {\n        return fmt.Errorf(\"key must not end with '/'; got %q (include a filename, not a directory)\", key)\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Always include a filename in the key (e.g. 'project/terraform.tfstate'), never just a path.","Avoid leading/trailing slashes — the key is an OSS object name, not a filesystem path.","Keep the default 'terraform.tfstate' for simple single-workspace setups."],"tags":["oss","validation","key","path"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}