{"record":{"id":"3b6edc6701ca1480","repo":"hashicorp/terraform","slug":"identity-schema-not-found-for-type-s","errorCode":null,"errorMessage":"identity schema not found for type %s","messagePattern":"identity schema not found for type (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/grpcwrap/provider.go","lineNumber":288,"sourceCode":"\tty := resSchema.Body.ImpliedType()\n\n\tstateVal, err := decodeDynamicValue(req.CurrentState, ty)\n\tif err != nil {\n\t\tresp.Diagnostics = convert.AppendProtoDiag(resp.Diagnostics, err)\n\t\treturn resp, nil\n\t}\n\n\tmetaTy := p.schema.ProviderMeta.Body.ImpliedType()\n\tmetaVal, err := decodeDynamicValue(req.ProviderMeta, metaTy)\n\tif err != nil {\n\t\tresp.Diagnostics = convert.AppendProtoDiag(resp.Diagnostics, err)\n\t\treturn resp, nil\n\t}\n\n\tvar currentIdentity cty.Value\n\tif req.CurrentIdentity != nil && req.CurrentIdentity.IdentityData != nil {\n\t\tif resSchema.Identity == nil {\n\t\t\treturn resp, fmt.Errorf(\"identity schema not found for type %s\", req.TypeName)\n\t\t}\n\t\tcurrentIdentity, err = decodeDynamicValue(req.CurrentIdentity.IdentityData, resSchema.Identity.ImpliedType())\n\t\tif err != nil {\n\t\t\tresp.Diagnostics = convert.AppendProtoDiag(resp.Diagnostics, err)\n\t\t\treturn resp, nil\n\t\t}\n\t}\n\n\treadResp := p.provider.ReadResource(providers.ReadResourceRequest{\n\t\tTypeName:        req.TypeName,\n\t\tPriorState:      stateVal,\n\t\tPrivate:         req.Private,\n\t\tProviderMeta:    metaVal,\n\t\tCurrentIdentity: currentIdentity,\n\t})\n\tresp.Diagnostics = convert.AppendProtoDiag(resp.Diagnostics, readResp.Diagnostics)\n\tif readResp.Diagnostics.HasErrors() {\n\t\treturn resp, nil","sourceCodeStart":270,"sourceCodeEnd":306,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/grpcwrap/provider.go#L270-L306","documentation":"Returned inside the grpcwrap ReadResource handler when the gRPC request carries CurrentIdentity data but the resource type's schema has no Identity block (resSchema.Identity == nil). The wrapper cannot decode identity bytes without a target type, so it refuses rather than guessing. '%s' is the resource type name.","triggerScenarios":"A provider plugin receives a ReadResourceRequest with req.CurrentIdentity.IdentityData populated for a resource type that did not declare an identity schema in GetProviderSchema. Indicates schema/request mismatch between Terraform core and the provider.","commonSituations":"Provider version skew: Terraform core (with identity support) talks to an older provider build whose schema predates identity; a provider incorrectly omits the identity block for a resource that core believes has identity; test harness sending identity without configuring schema.","solutions":["Upgrade the provider to a build that declares identity schemas for the named resource type.","If writing a provider, ensure SchemaResponse.ResourceTypes[].Identity is populated for that type in GetProviderSchema.","Downgrade Terraform core to a version that does not send identity for this resource type if a provider upgrade is not possible.","Verify the resource type name in the request matches a schema key that has Identity defined."],"exampleFix":"// before: provider schema missing identity for 'example_thing'\nschema.ResourceTypes[\"example_thing\"] = &configschema.Block{Attributes: ...} // no Identity\n// after (provider-side framework)\nschema.ResourceTypes[\"example_thing\"] = &configschema.Block{\n    Attributes: ...,\n    Identity:   identitySchema,\n}","handlingStrategy":"type-guard","validationCode":"// Provider-side: ensure identity schema exists before sending CurrentIdentity.\nif schema, ok := p.schema.ResourceTypes[req.TypeName]; ok && schema.Identity != nil {\n    // safe to send CurrentIdentity\n} else {\n    // omit identity from the request\n}","typeGuard":"// Check identity schema presence before issuing the request.\nfunc hasIdentitySchema(schemas map[string]*configschema.Block, t string) bool {\n    b, ok := schemas[t]\n    return ok && b.Identity != nil\n}","tryCatchPattern":"// Caller-side: tolerate schema mismatch during upgrades.\nif err != nil && strings.Contains(err.Error(), \"identity schema not found\") {\n    log.Printf(\"identity not supported on %s yet; upgrade provider\", t)\n}","preventionTips":["Keep Terraform core and provider versions aligned when using identity features.","Declare identity schemas for all resources that may receive identity data.","Use 'terraform providers schema' to confirm identity blocks before operations."],"tags":["grpcwrap","identity","schema","provider","terraform"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}