{"record":{"id":"25d09300dc159c03","repo":"hashicorp/terraform","slug":"resource-group-name-is-required-when-lookup-blo","errorCode":null,"errorMessage":"`resource_group_name` is required when `lookup_blob_endpoint` is set","messagePattern":"`resource_group_name` is required when `lookup_blob_endpoint` is set","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/azure/backend.go","lineNumber":459,"sourceCode":"\n\tbackendConfig := BackendConfig{\n\t\tAuthConfig:               authConfig,\n\t\tSubscriptionID:           data.String(\"subscription_id\"),\n\t\tResourceGroupName:        data.String(\"resource_group_name\"),\n\t\tStorageAccountName:       data.String(\"storage_account_name\"),\n\t\tLookupBlobEndpoint:       data.Bool(\"lookup_blob_endpoint\"),\n\t\tAccessKey:                data.String(\"access_key\"),\n\t\tSasToken:                 data.String(\"sas_token\"),\n\t\tUseAzureADAuthentication: data.Bool(\"use_azuread_auth\"),\n\t}\n\n\tneedToLookupAccessKey := backendConfig.AccessKey == \"\" && backendConfig.SasToken == \"\" && !backendConfig.UseAzureADAuthentication\n\tif backendConfig.ResourceGroupName == \"\" {\n\t\tif needToLookupAccessKey {\n\t\t\treturn backendbase.ErrorAsDiagnostics(fmt.Errorf(\"One of `access_key`, `sas_token`, `use_azuread_auth` and `resource_group_name` must be specified\"))\n\t\t}\n\t\tif backendConfig.LookupBlobEndpoint {\n\t\t\treturn backendbase.ErrorAsDiagnostics(fmt.Errorf(\"`resource_group_name` is required when `lookup_blob_endpoint` is set\"))\n\t\t}\n\t}\n\n\tclient, err := buildClient(ctx, backendConfig)\n\tif err != nil {\n\t\treturn backendbase.ErrorAsDiagnostics(err)\n\t}\n\n\tb.apiClient = client\n\treturn nil\n}\n","sourceCodeStart":441,"sourceCodeEnd":471,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/azure/backend.go#L441-L471","documentation":"Validation error in Backend.Configure when resource_group_name is empty AND lookup_blob_endpoint = true, but the user did supply an auth method (so error 149 did not fire). lookup_blob_endpoint forces an ARM call to discover the real blob endpoint, and that ARM call needs the resource group to address the storage account; without it, the lookup cannot happen.","triggerScenarios":"Backend block sets lookup_blob_endpoint = true plus an auth method (access_key/sas/aad) but omits resource_group_name.","commonSituations":"Operator using private DNS or non-default endpoint needs the real endpoint discovered from ARM, but forgot the resource group; copied a config with lookup_blob_endpoint left enabled.","solutions":["Add resource_group_name to the backend block.","If naive URL is acceptable, remove lookup_blob_endpoint (or set it false).","Re-run `terraform init -reconfigure` after fixing."],"exampleFix":"// before\nterraform {\n  backend \"azurerm\" {\n    storage_account_name = \"acct\"\n    container_name       = \"tfstate\"\n    key                  = \"prod.tfstate\"\n    access_key           = \"<key>\"\n    lookup_blob_endpoint = true\n  }\n}\n// after\nterraform {\n  backend \"azurerm\" {\n    resource_group_name  = \"rg-tfstate\"\n    storage_account_name = \"acct\"\n    container_name       = \"tfstate\"\n    key                  = \"prod.tfstate\"\n    access_key           = \"<key>\"\n    lookup_blob_endpoint = true\n  }\n}","handlingStrategy":"validation","validationCode":"// Validate: lookup_blob_endpoint requires resource_group_name regardless of auth method.\nfunc validateLookupEndpoint(b BackendConfig) error {\n    if b.LookupBlobEndpoint && b.ResourceGroupName == \"\" {\n        return fmt.Errorf(\"`resource_group_name` is required when `lookup_blob_endpoint` is set\")\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["When enabling lookup_blob_endpoint, also set resource_group_name by default.","Document the dependency between lookup_blob_endpoint and resource_group_name in the backend module README.","Use a config-lint rule (e.g. conftest/OPA) to flag lookup_blob_endpoint without resource_group_name."],"tags":["azure","configuration","validation","lookup-endpoint"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}