{"record":{"id":"3bfcc6bd56a12f72","repo":"hashicorp/terraform","slug":"error-retrieving-state-v","errorCode":null,"errorMessage":"Error retrieving state: %v","messagePattern":"Error retrieving state: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote/backend_state.go","lineNumber":62,"sourceCode":"\nfunc (e errorUnlockFailed) Error() string {\n\treturn e.innerError.Error()\n}\n\nvar _ Fatal = errorUnlockFailed{}\n\n// Get the remote state.\nfunc (r *remoteClient) Get() (*remote.Payload, tfdiags.Diagnostics) {\n\tvar diags tfdiags.Diagnostics\n\tctx := context.Background()\n\n\tsv, err := r.client.StateVersions.ReadCurrent(ctx, r.workspace.ID)\n\tif err != nil {\n\t\tif err == tfe.ErrResourceNotFound {\n\t\t\t// If no state exists, then return nil.\n\t\t\treturn nil, nil\n\t\t}\n\t\treturn nil, diags.Append(fmt.Errorf(\"Error retrieving state: %v\", err))\n\t}\n\n\tstate, err := r.client.StateVersions.Download(ctx, sv.DownloadURL)\n\tif err != nil {\n\t\treturn nil, diags.Append(fmt.Errorf(\"Error downloading state: %v\", err))\n\t}\n\n\t// If the state is empty, then return nil.\n\tif len(state) == 0 {\n\t\treturn nil, nil\n\t}\n\n\t// Get the MD5 checksum of the state.\n\tsum := md5.Sum(state)\n\n\treturn &remote.Payload{\n\t\tData: state,\n\t\tMD5:  sum[:],","sourceCodeStart":44,"sourceCodeEnd":80,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote/backend_state.go#L44-L80","documentation":"remoteClient.Get reads the current state version for the workspace via StateVersions.ReadCurrent. ErrResourceNotFound is treated as 'no state yet' and returns nil; every other failure (auth, permissions, API 5xx, network) becomes this error. This runs during RefreshState before plan/apply/pull.","triggerScenarios":"StateVersions.ReadCurrent(ctx, workspace.ID) fails with a non-NotFound error: 401/403 (token can't read state versions in this workspace), 404 on the workspace itself after ID was cached, 5xx, or transport error.","commonSituations":"Token downgraded to a team without 'Read State' access; workspace recreated with a new ID while the backend held the old one; TFC state backend degraded; network blip during `terraform init`/`plan`.","solutions":["Verify the token has 'Read State' (or higher) permission on the workspace.","Re-run `terraform init` to refresh cached workspace metadata if the workspace was recreated.","Retry on transient 5xx/network errors after confirming TFC status.","If self-hosted TFE, check that the workspace still exists and the state backend (e.g. S3) is healthy."],"exampleFix":null,"handlingStrategy":"retry","validationCode":"// Pre-flight read-state check\n_, err := c.StateVersions.ReadCurrent(ctx, wsID)\nif err != nil && err != tfe.ErrResourceNotFound { return err }","typeGuard":null,"tryCatchPattern":"// Retry non-NotFound errors from ReadCurrent\nerr := retryOnHTTP(3, func() error {\n    e := c.StateVersions.ReadCurrent(ctx, wsID)\n    if e == tfe.ErrResourceNotFound { return nil }\n    return e\n})","preventionTips":["Grant 'Read State' permission to the operating token.","Re-run `terraform init` after workspace recreation to refresh cached IDs.","Monitor TFC status during heavy plan windows."],"tags":["terraform","remote-backend","tfe","state","permissions","network"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}