{"record":{"id":"381ab1fa23ec3251","repo":"hashicorp/terraform","slug":"can-t-delete-default-state-381ab1","errorCode":null,"errorMessage":"can't delete default state","messagePattern":"can't delete default state","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"internal/backend/remote-state/oss/backend_state.go","lineNumber":109,"sourceCode":"\t\t\t\toptions = append(options, oss.Marker(lastObj))\n\t\t\t}\n\t\t\tresp, err = bucket.ListObjects(options...)\n\t\t\tif err != nil {\n\t\t\t\treturn nil, diags.Append(err)\n\t\t\t}\n\t\t} else {\n\t\t\tbreak\n\t\t}\n\t}\n\tsort.Strings(result[1:])\n\treturn result, diags\n}\n\nfunc (b *Backend) DeleteWorkspace(name string, _ bool) tfdiags.Diagnostics {\n\tvar diags tfdiags.Diagnostics\n\n\tif name == backend.DefaultStateName || name == \"\" {\n\t\treturn diags.Append(fmt.Errorf(\"can't delete default state\"))\n\t}\n\n\tclient, err := b.remoteClient(name)\n\tif err != nil {\n\t\treturn diags.Append(err)\n\t}\n\treturn diags.Append(client.Delete())\n}\n\nfunc (b *Backend) StateMgr(name string) (statemgr.Full, tfdiags.Diagnostics) {\n\tvar diags tfdiags.Diagnostics\n\n\tclient, err := b.remoteClient(name)\n\tif err != nil {\n\t\treturn nil, diags.Append(err)\n\t}\n\tstateMgr := &remote.State{Client: client}\n","sourceCodeStart":91,"sourceCodeEnd":127,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/oss/backend_state.go#L91-L127","documentation":"Thrown by DeleteWorkspace when the requested workspace name is the default workspace (or empty). Terraform backends protect the default state from deletion because it is the bootstrap state; deleting it would orphan all resources tracked only in default.","triggerScenarios":"Calling 'terraform workspace delete default' (or any name resolving to backend.DefaultStateName / \"\") against the OSS backend. The backend refuses before attempting any remote operation.","commonSituations":"User误-runs 'terraform workspace delete default' or scripts that loop over workspaces deleting each without excluding default. Also scripts passing an empty string workspace name.","solutions":["Exclude 'default' from any scripted workspace deletion loop.","To remove default state, manually delete the underlying OSS state object after confirming no resources are tracked.","Pass a non-default, non-empty workspace name to DeleteWorkspace."],"exampleFix":"// before\nterraform workspace delete default\n\n// after\n# default is protected; delete a named workspace instead\nterraform workspace delete my-feature-env","handlingStrategy":"validation","validationCode":"// Never call DeleteWorkspace with the default name.\nconst defaultWS = \"default\"\nif name == defaultWS || name == \"\" {\n    return fmt.Errorf(\"refusing to delete protected workspace %q\", name)\n}","typeGuard":"func isProtectedWorkspace(name string) bool {\n    return name == \"\" || name == \"default\"\n}","tryCatchPattern":null,"preventionTips":["In workspace-cleanup scripts, always filter out 'default'.","Document that default state is intentionally protected.","Use a named workspace per branch/environment instead of repurposing default."],"tags":["alibaba-cloud","oss","terraform","workspace","default-state","guard"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}