{"record":{"id":"2c9a76d2b5c5507d","repo":"hashicorp/terraform","slug":"acl-value-invalid-expected-s-or-s-got-s","errorCode":null,"errorMessage":"acl value invalid, expected %s or %s, got %s","messagePattern":"acl value invalid, expected (.+?) or (.+?), got (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/cos/backend.go","lineNumber":167,"sourceCode":"\t\t\t\t\t}\n\t\t\t\t\treturn nil, nil\n\t\t\t\t},\n\t\t\t},\n\t\t\t\"encrypt\": {\n\t\t\t\tType:        schema.TypeBool,\n\t\t\t\tOptional:    true,\n\t\t\t\tDescription: \"Whether to enable server side encryption of the state file\",\n\t\t\t\tDefault:     true,\n\t\t\t},\n\t\t\t\"acl\": {\n\t\t\t\tType:        schema.TypeString,\n\t\t\t\tOptional:    true,\n\t\t\t\tDescription: \"Object ACL to be applied to the state file\",\n\t\t\t\tDefault:     \"private\",\n\t\t\t\tValidateFunc: func(v interface{}, s string) ([]string, []error) {\n\t\t\t\t\tvalue := v.(string)\n\t\t\t\t\tif value != \"private\" && value != \"public-read\" {\n\t\t\t\t\t\treturn nil, []error{fmt.Errorf(\n\t\t\t\t\t\t\t\"acl value invalid, expected %s or %s, got %s\",\n\t\t\t\t\t\t\t\"private\", \"public-read\", value)}\n\t\t\t\t\t}\n\t\t\t\t\treturn nil, nil\n\t\t\t\t},\n\t\t\t},\n\t\t\t\"accelerate\": {\n\t\t\t\tType:        schema.TypeBool,\n\t\t\t\tOptional:    true,\n\t\t\t\tDescription: \"Whether to enable global Acceleration\",\n\t\t\t\tDefault:     false,\n\t\t\t},\n\t\t\t\"assume_role\": {\n\t\t\t\tType:        schema.TypeSet,\n\t\t\t\tOptional:    true,\n\t\t\t\tMaxItems:    1,\n\t\t\t\tDescription: \"The `assume_role` block. If provided, terraform will attempt to assume this role using the supplied credentials.\",\n\t\t\t\tElem: &schema.Resource{","sourceCodeStart":149,"sourceCodeEnd":185,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/cos/backend.go#L149-L185","documentation":"Schema-level ValidateFunc for the COS backend 'acl' attribute applied to the state object. Only 'private' and 'public-read' are accepted; any other value is rejected at terraform init time. State files should normally be 'private'.","triggerScenarios":"terraform init with acl set to anything other than 'private' or 'public-read' (e.g. 'public-read-write', 'bucket-owner-full-control', etc.).","commonSituations":"User copies an S3 ACL value not supported by COS; tries to use a bucket-level canned ACL; sets 'public-read-write' intending wide access.","solutions":["Set acl = 'private' (the default and recommended for state) or acl = 'public-read'.","Re-run terraform init."],"exampleFix":"// before\nterraform {\n  backend \"cos\" {\n    acl = \"public-read-write\"\n  }\n}\n\n// after\nterraform {\n  backend \"cos\" {\n    acl = \"private\"\n  }\n}","handlingStrategy":"validation","validationCode":"// Validate the COS backend acl value before terraform init.\nfunc validateCOSACL(acl string) error {\n    if acl != \"private\" && acl != \"public-read\" {\n        return fmt.Errorf(\"acl value invalid, expected %s or %s, got %s\", \"private\", \"public-read\", acl)\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Keep acl = 'private' (the default) for state files; never expose state publicly.","Don't assume S3 canned-ACL values map 1:1 to COS.","Lint backend blocks in CI to catch unsupported ACL strings early.","Audit bucket policies separately from object ACLs."],"tags":["cos","tencent-cloud","config-validation","acl","backend"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}