{"record":{"id":"3ed6555f4002ca15","repo":"hashicorp/terraform","slug":"s-soft-failed-s-3ed655","errorCode":null,"errorMessage":"%s soft failed.\n%s","messagePattern":"(.+?) soft failed\\.\n(.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/cloud/backend_common.go","lineNumber":401,"sourceCode":"\t\t\t}\n\t\t}\n\n\t\tswitch pc.Status {\n\t\tcase tfe.PolicyPasses:\n\t\t\tif (r.HasChanges && op.Type == backendrun.OperationTypeApply || i < len(r.PolicyChecks)-1) && b.CLI != nil {\n\t\t\t\tb.CLI.Output(\"\\n------------------------------------------------------------------------\")\n\t\t\t}\n\t\t\tcontinue\n\t\tcase tfe.PolicyErrored:\n\t\t\treturn fmt.Errorf(\"%s errored.\", msgPrefix)\n\t\tcase tfe.PolicyHardFailed:\n\t\t\treturn fmt.Errorf(\"%s hard failed.\", msgPrefix)\n\t\tcase tfe.PolicySoftFailed:\n\t\t\trunURL := fmt.Sprintf(runHeaderErr, b.Hostname, b.Organization, op.Workspace, r.ID)\n\n\t\t\tif op.Type == backendrun.OperationTypePlan || op.UIOut == nil || op.UIIn == nil ||\n\t\t\t\t!pc.Actions.IsOverridable || !pc.Permissions.CanOverride {\n\t\t\t\treturn fmt.Errorf(\"%s soft failed.\\n%s\", msgPrefix, runURL)\n\t\t\t}\n\n\t\t\tif op.AutoApprove {\n\t\t\t\tif _, err = b.client.PolicyChecks.Override(stopCtx, pc.ID); err != nil {\n\t\t\t\t\treturn b.generalError(fmt.Sprintf(\"Failed to override policy check.\\n%s\", runURL), err)\n\t\t\t\t}\n\t\t\t} else if !b.input {\n\t\t\t\treturn errPolicyOverrideNeedsUIConfirmation\n\t\t\t} else {\n\t\t\t\topts := &terraform.InputOpts{\n\t\t\t\t\tId:          \"override\",\n\t\t\t\t\tQuery:       \"\\nDo you want to override the soft failed policy check?\",\n\t\t\t\t\tDescription: \"Only 'override' will be accepted to override.\",\n\t\t\t\t}\n\t\t\t\terr = b.confirm(stopCtx, op, opts, r, \"override\")\n\t\t\t\tif err != nil && err != errRunOverridden {\n\t\t\t\t\treturn fmt.Errorf(\"Failed to override: %w\\n%s\\n\", err, runURL)\n\t\t\t\t}","sourceCodeStart":383,"sourceCodeEnd":419,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/cloud/backend_common.go#L383-L419","documentation":"Policy soft-failed (tfe.PolicySoftFailed) AND the run cannot show the interactive override prompt: the op is a plan, there is no UI, or the policy/workspace lacks override permissions. Soft failures are overridable, but only when UIIn/UIOut exist and the user has CanOverride; otherwise this error fires with the run URL.","triggerScenarios":"pc.Status == tfe.PolicySoftFailed AND (op.Type == plan OR op.UIOut == nil OR op.UIIn == nil OR !pc.Actions.IsOverridable OR !pc.Permissions.CanOverride). Typical in non-interactive CI: no TTY, no override permission, or running `plan` only.","commonSituations":"CI runner without interactive input hits a soft-mandatory policy; the token's team lacks 'Override Soft Failed Policies' permission; running a plan-only check that surfaces a soft policy violation.","solutions":["Grant the token's team the 'Override Soft Failed Policies' workspace permission and pass --auto-approve if overrides are desired.","Fix the configuration to satisfy the soft policy rather than overriding.","Run the apply interactively on a workstation to be prompted for override.","Adjust the policy enforcement level from soft-mandatory to advisory if override should be routine."],"exampleFix":"# before: CI token lacks override permission, run blocks on soft policy\n# Workspace -> Settings -> Permissions -> grant team 'Override Soft Failed Policies'\n# then run with auto-approve:\nterraform apply -auto-approve","handlingStrategy":"validation","validationCode":"// before running apply in CI, ensure override capability or fix policies\nfunc canOverrideSoftFail(client *tfe.Client, ws *tfe.Workspace) bool {\n    return ws.Permissions.CanOverride && ws.Actions.IsOverridable\n}\n// if false and you need override, grant the team 'Override Soft Failed Policies'","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Grant the CI token's team 'Override Soft Failed Policies' when override is intended.","Use --auto-approve in CI when override is desired and permitted.","Prefer fixing the config over overriding soft policies.","Lower enforcement to 'advisory' for policies you routinely override."],"tags":["tfe","hcp","cloud-backend","policy","sentinel","override"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}