{"record":{"id":"2778a7260d684342","repo":"hashicorp/terraform","slug":"invalid-tfvars-content-s","errorCode":null,"errorMessage":"invalid tfvars content: %s","messagePattern":"invalid tfvars content: (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/builtin/providers/terraform/functions.go","lineNumber":125,"sourceCode":"\n\t// If we get here then we know that:\n\t// - there's exactly one element in args\n\t// - it's a string\n\t// - it is known and non-null\n\t// So therefore the following is guaranteed to succeed.\n\tsrc := []byte(args[0].AsString())\n\n\t// As usual when we wrap HCL stuff up in functions, we end up needing to\n\t// stuff HCL diagnostics into plain string error messages. This produces\n\t// a non-ideal result but is still better than hiding the HCL-provided\n\t// diagnosis altogether.\n\tf, hclDiags := hclsyntax.ParseConfig(src, \"<decode_tfvars argument>\", hcl.InitialPos)\n\tif hclDiags.HasErrors() {\n\t\treturn cty.NilVal, fmt.Errorf(\"invalid tfvars syntax: %s\", hclDiags.Error())\n\t}\n\tattrs, hclDiags := f.Body.JustAttributes()\n\tif hclDiags.HasErrors() {\n\t\treturn cty.NilVal, fmt.Errorf(\"invalid tfvars content: %s\", hclDiags.Error())\n\t}\n\tretAttrs := make(map[string]cty.Value, len(attrs))\n\tfor name, attr := range attrs {\n\t\t// Evaluating the expression with no EvalContext achieves the same\n\t\t// interpretation as Terraform CLI makes of .tfvars files, rejecting\n\t\t// any function calls or references to symbols.\n\t\tv, hclDiags := attr.Expr.Value(nil)\n\t\tif hclDiags.HasErrors() {\n\t\t\treturn cty.NilVal, fmt.Errorf(\"invalid expression for variable %q: %s\", name, hclDiags.Error())\n\t\t}\n\t\tretAttrs[name] = v\n\t}\n\n\treturn cty.ObjectVal(retAttrs), nil\n}\n\nfunc encodeExprFunc(args []cty.Value) (cty.Value, error) {\n\t// These error checks should not be hit in practice because the language","sourceCodeStart":107,"sourceCodeEnd":143,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/builtin/providers/terraform/functions.go#L107-L143","documentation":"After a successful parse, decode_tfvars calls Body.JustAttributes(), which fails if the body contains nested blocks rather than only top-level attribute = value assignments. tfvars semantics allow only flat attribute assignments, so a structurally valid HCL body of the wrong shape is rejected here.","triggerScenarios":"decode_tfvars(\"nested { x = 1 }\") where the body declares a block; decode_tfvars with a full Terraform configuration string containing resource/provider blocks instead of tfvars content.","commonSituations":"Passing a complete .tf configuration to decode_tfvars by mistake; confusing decode_tfvars with jsondecode/yamldecode and feeding structured config; building a tfvars string that nests objects via blocks instead of object literal syntax.","solutions":["Flatten the input to top-level attribute = value pairs only, using object literal syntax (key = { a = 1 }) rather than blocks for nested values","Use the appropriate decoder (jsondecode, yamldecode) if the input is not tfvars-shaped","Strip any resource/provider/variable blocks from the string before passing it"],"exampleFix":"// before\ndecode_tfvars(\"nested { x = 1 }\")\n// after\ndecode_tfvars(\"nested = { x = 1 }\")","handlingStrategy":"validation","validationCode":"// After parsing, confirm the body is attribute-only before calling decode_tfvars.\n// In Go:\nif _, diags := f.Body.JustAttributes(); diags.HasErrors() {\n    // reject the input as not tfvars-shaped; it contains blocks\n    return diags\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Distinguish .tfvars (flat attributes only) from .tf (blocks allowed); never feed a full config to decode_tfvars","Express nested values as object literals (key = { a = 1 }), never as blocks, inside tfvars strings","If you need to decode structured config, use jsondecode/yamldecode on a JSON/YAML representation instead"],"tags":["terraform","hcl","decode-tfvars","content-shape"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}