{"record":{"id":"18e69fa96a869340","repo":"hashicorp/terraform","slug":"prefix-must-not-start-with-or","errorCode":null,"errorMessage":"prefix must not start with '/' or './'","messagePattern":"prefix must not start with '/' or '\\./'","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/cos/backend.go","lineNumber":136,"sourceCode":"\t\t\t\tType:        schema.TypeString,\n\t\t\t\tOptional:    true,\n\t\t\t\tDescription: \"The custom endpoint for the COS API, e.g. http://cos-internal.{Region}.tencentcos.cn. Both HTTP and HTTPS are accepted.\",\n\t\t\t\tDefaultFunc: schema.EnvDefaultFunc(PROVIDER_ENDPOINT, nil),\n\t\t\t},\n\t\t\t\"domain\": {\n\t\t\t\tType:        schema.TypeString,\n\t\t\t\tOptional:    true,\n\t\t\t\tDefaultFunc: schema.EnvDefaultFunc(PROVIDER_DOMAIN, nil),\n\t\t\t\tDescription: \"The root domain of the API request. Default is tencentcloudapi.com.\",\n\t\t\t},\n\t\t\t\"prefix\": {\n\t\t\t\tType:        schema.TypeString,\n\t\t\t\tOptional:    true,\n\t\t\t\tDescription: \"The directory for saving the state file in bucket\",\n\t\t\t\tValidateFunc: func(v interface{}, s string) ([]string, []error) {\n\t\t\t\t\tprefix := v.(string)\n\t\t\t\t\tif strings.HasPrefix(prefix, \"/\") || strings.HasPrefix(prefix, \"./\") {\n\t\t\t\t\t\treturn nil, []error{fmt.Errorf(\"prefix must not start with '/' or './'\")}\n\t\t\t\t\t}\n\t\t\t\t\treturn nil, nil\n\t\t\t\t},\n\t\t\t},\n\t\t\t\"key\": {\n\t\t\t\tType:        schema.TypeString,\n\t\t\t\tOptional:    true,\n\t\t\t\tDescription: \"The path for saving the state file in bucket\",\n\t\t\t\tDefault:     \"terraform.tfstate\",\n\t\t\t\tValidateFunc: func(v interface{}, s string) ([]string, []error) {\n\t\t\t\t\tif strings.HasPrefix(v.(string), \"/\") || strings.HasSuffix(v.(string), \"/\") {\n\t\t\t\t\t\treturn nil, []error{fmt.Errorf(\"key can not start and end with '/'\")}\n\t\t\t\t\t}\n\t\t\t\t\treturn nil, nil\n\t\t\t\t},\n\t\t\t},\n\t\t\t\"encrypt\": {\n\t\t\t\tType:        schema.TypeBool,","sourceCodeStart":118,"sourceCodeEnd":154,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/cos/backend.go#L118-L154","documentation":"Schema-level ValidateFunc for the COS backend 'prefix' attribute. The prefix is joined with the key to form the object key (path.Join(b.prefix, b.key)), so a leading '/' or './' would produce unintended object keys. The validator rejects those prefixes at terraform init time.","triggerScenarios":"terraform init with a `prefix` value whose first character is '/' or whose first two characters are './'.","commonSituations":"User copy-pastes an absolute path like '/terraform/prod' from an S3 backend config; uses POSIX-relative notation './envs'; assumes leading slash is required like AWS S3.","solutions":["Set prefix to a bare path with no leading slash or './', e.g. 'terraform/prod'.","Re-run terraform init with the corrected backend configuration."],"exampleFix":"// before\nterraform {\n  backend \"cos\" {\n    prefix = \"/terraform/prod\"\n  }\n}\n\n// after\nterraform {\n  backend \"cos\" {\n    prefix = \"terraform/prod\"\n  }\n}","handlingStrategy":"validation","validationCode":"// Validate the COS backend prefix before terraform init.\nfunc validateCOSPrefix(prefix string) error {\n    if strings.HasPrefix(prefix, \"/\") || strings.HasPrefix(prefix, \"./\") {\n        return fmt.Errorf(\"prefix must not start with '/' or './'\")\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Treat COS prefix as a bare relative path (e.g. 'terraform/prod'), not an absolute one.","Validate backend blocks in CI with `terraform init -backend=false` then a config-lint pass.","Don't copy S3 backend paths verbatim; S3 tolerates a leading slash, COS does not.","Document the prefix convention in the team's backend module."],"tags":["cos","tencent-cloud","config-validation","backend"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}