{"record":{"id":"241acdadeb158434","repo":"hashicorp/terraform","slug":"retrieving-s-v","errorCode":null,"errorMessage":"retrieving %s: %+v","messagePattern":"retrieving (.+?): %\\+v","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/azure/api_client.go","lineNumber":106,"sourceCode":"\t\t\t\t}\n\t\t\t}\n\t\t}\n\t\tif config.SubscriptionID == \"\" {\n\t\t\treturn nil, fmt.Errorf(\"subscription id not specified\")\n\t\t}\n\n\t\t// Setup the SA client.\n\t\tclient.storageAccountsClient, err = storageaccounts.NewStorageAccountsClientWithBaseURI(config.AuthConfig.Environment.ResourceManager)\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"building Storage Accounts client: %+v\", err)\n\t\t}\n\t\tclient.configureClient(client.storageAccountsClient.Client, resourceManagerAuth)\n\n\t\t// Populating the storage account detail\n\t\tstorageAccountId := commonids.NewStorageAccountID(config.SubscriptionID, config.ResourceGroupName, client.storageAccountName)\n\t\tresp, err := client.storageAccountsClient.GetProperties(ctx, storageAccountId, storageaccounts.DefaultGetPropertiesOperationOptions())\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"retrieving %s: %+v\", storageAccountId, err)\n\t\t}\n\t\tif resp.Model == nil {\n\t\t\treturn nil, fmt.Errorf(\"retrieving %s: model was nil\", storageAccountId)\n\t\t}\n\t\tclient.accountDetail, err = populateAccountDetails(storageAccountId, *resp.Model)\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"populating details for %s: %+v\", storageAccountId, err)\n\t\t}\n\t}\n\n\treturn &client, nil\n}\n\nfunc (c *Client) getBlobClient(ctx context.Context) (bc *blobs.Client, err error) {\n\tif c.blobsClient != nil {\n\t\treturn c.blobsClient, nil\n\t}\n","sourceCodeStart":88,"sourceCodeEnd":124,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/azure/api_client.go#L88-L124","documentation":"Thrown by Azure buildClient when storageAccountsClient.GetProperties returns an error reading the storage account via ARM. The %s is the full storage account Resource ID (/subscriptions/.../resourceGroups/.../providers/Microsoft.Storage/storageAccounts/<name>); %+v is the ARM/SDK error. This is the most common Azure backend init failure because it depends on the account existing and the SP having Reader access.","triggerScenarios":"armAuthRequired is true and the ARM GET on the storage account resource fails: account does not exist, wrong resource_group_name, wrong subscription, the authenticated principal lacks Microsoft.Storage/storageAccounts/read, ARM throttled the request, or a transient network/ARM-service error.","commonSituations":"Typo in storage_account_name or resource_group_name; SP with no RBAC role on the storage account or resource group; account lives in a different subscription than subscription_id; ARM service incident or throttling; private networking blocking the ARM endpoint.","solutions":["Read the wrapped %+v: 404 means wrong name/group/subscription, 403 means missing Reader role, 429 means throttle, 5xx means retry.","Confirm storage_account_name and resource_group_name match a real account (cross-check with `az storage account show`).","Grant the SP 'Storage Account Contributor' or 'Reader' on the resource group or account.","For transient errors (429/5xx/network), retry after a short backoff; for persistent failures, fix the underlying permission/existence problem.","Verify the account is in the subscription_id you supplied."],"exampleFix":"# grant the SP read access so GetProperties succeeds\naz role assignment create \\\n  --assignee $ARM_CLIENT_ID \\\n  --role \"Storage Account Contributor\" \\\n  --scope /subscriptions/$ARM_SUBSCRIPTION_ID/resourceGroups/$RG/providers/Microsoft.Storage/storageAccounts/$ACCOUNT","handlingStrategy":"retry","validationCode":"// Preflight: confirm the account exists and is readable.\nfunc accountReadable(sub, rg, name string) error {\n    // wrap an `az storage account show --subscription $sub -g $rg -n $name` call\n    return nil\n}","typeGuard":"null","tryCatchPattern":"client, err := azure.NewClient(ctx, cfg)\nif err != nil && strings.Contains(err.Error(), \"retrieving\") {\n    code := azureArmCode(err)\n    switch code {\n    case 404: // wrong name/group/sub\n    case 403: // grant Reader/Contributor\n    case 429, 500, 502, 503: // retry with backoff\n    }\n}","preventionTips":["Grant the SP 'Storage Account Contributor' (or Reader + key-listing rights) on the account or resource group.","Double-check storage_account_name and resource_group_name spellings and the subscription they live in.","For transient ARM failures, retry with exponential backoff; for 403/404 fix permissions/existence first."],"tags":["azure","backend","arm","storage-account","permissions","network","retryable"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}