{"record":{"id":"3f3ae4087e79f4fc","repo":"hashicorp/terraform","slug":"failed-to-get-existing-workspaces-s","errorCode":null,"errorMessage":"Failed to get existing workspaces: %s","messagePattern":"Failed to get existing workspaces: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/command/meta_backend.go","lineNumber":246,"sourceCode":"\t\tm.backendConfigState = &workdir.BackendConfigState{\n\t\t\tType:      \"local\",\n\t\t\tConfigRaw: json.RawMessage(\"{}\"),\n\t\t}\n\t}\n\n\treturn local, diags\n}\n\n// selectWorkspace gets a list of existing workspaces and then checks\n// if the currently selected workspace is valid. If not, it will ask\n// the user to select a workspace from the list.\nfunc (m *Meta) selectWorkspace(b backend.Backend) error {\n\tworkspaces, diags := b.Workspaces()\n\tif diags.HasErrors() && diags.Err().Error() == backend.ErrWorkspacesNotSupported.Error() {\n\t\treturn nil\n\t}\n\tif diags.HasErrors() {\n\t\treturn fmt.Errorf(\"Failed to get existing workspaces: %s\", diags.Err())\n\t}\n\tif diags.HasWarnings() {\n\t\tlog.Printf(\"[WARN] selectWorkspace: warning(s) returned when getting workspaces: %s\", diags.ErrWithWarnings())\n\t}\n\tif len(workspaces) == 0 {\n\t\tif c, ok := b.(*cloud.Cloud); ok && m.input {\n\t\t\t// len is always 1 if using Name; 0 means we're using Tags and there\n\t\t\t// aren't any matching workspaces. Which might be normal and fine, so\n\t\t\t// let's just ask:\n\t\t\tname, err := m.UIInput().Input(context.Background(), &terraform.InputOpts{\n\t\t\t\tId:          \"create-workspace\",\n\t\t\t\tQuery:       \"\\n[reset][bold][yellow]No workspaces found.[reset]\",\n\t\t\t\tDescription: fmt.Sprintf(inputCloudInitCreateWorkspace, c.WorkspaceMapping.DescribeTags()),\n\t\t\t})\n\t\t\tif err != nil {\n\t\t\t\treturn fmt.Errorf(\"Couldn't create initial workspace: %w\", err)\n\t\t\t}\n\t\t\tname = strings.TrimSpace(name)","sourceCodeStart":228,"sourceCodeEnd":264,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/command/meta_backend.go#L228-L264","documentation":"Returned from `Meta.selectWorkspace` when `b.Workspaces()` returns diagnostics that have errors AND the error string is not the `backend.ErrWorkspacesNotSupported` sentinel. The backend was asked to enumerate workspaces and failed for a reason other than not supporting the concept at all.","triggerScenarios":"`b.Workspaces()` issues the backend's workspace-listing routine — for the cloud backend this is an API call filtered by `workspaces.tags`/`workspaces.name`; for the local backend it is a directory read. Failures include API 5xx/4xx, permission errors, network failures, or a local filesystem read error. The early `ErrWorkspacesNotSupported` short-circuit means this only fires for backends that DO support workspaces but failed to list them.","commonSituations":"HCP Terraform API token lacks permission to list workspaces in the organization; `workspaces.tags` filter references tags that cause a server error; network blip to `app.terraform.io`; local backend cannot read `.terraform/terraform.tfstate.d/` due to permissions; organization name typo in the `cloud` block.","solutions":["Inspect the wrapped `%s` (the diagnostics error) for the HTTP status or filesystem error.","For cloud backends, verify the token has at least `read-workspaces` permission on the organization.","Confirm the `organization` and `hostname` in the `cloud` block are correct.","Run `terraform init` to re-establish connectivity and re-authenticate if needed.","For local backends, check permissions on the state directory."],"exampleFix":"// before: token lacks read permission\ncloud { organization = \"acme\" workspaces { name = \"prod\" } }\n# grant 'Read Workspaces' to the token's team in HCP Terraform org settings,\n# then\nterraform init\nterraform plan","handlingStrategy":"try-catch","validationCode":"// For cloud backends, pre-check token permissions / org access.\n// Ensure the token can list workspaces before running selectWorkspace.\nclient, _ := tfe.NewClient(&tfe.Config{Token: tok, Address: addr})\nif _, err := client.Organizations.Read(ctx, org); err != nil {\n    return fmt.Errorf(\"token cannot access org %s: %w\", org, err)\n}","typeGuard":"// Skip the error if the backend simply lacks workspace support.\nif diags.Err().Error() == backend.ErrWorkspacesNotSupported.Error() { return nil }","tryCatchPattern":"// Distinguish 'not supported' (benign) from real listing failures.\nif diags.HasErrors() && diags.Err().Error() != backend.ErrWorkspacesNotSupported.Error() {\n    return fmt.Errorf(\"Failed to get existing workspaces: %s\", diags.Err())\n}","preventionTips":["Grant the API token `read-workspaces` permission on the org.","Verify `organization` spelling in the `cloud` block.","Run `terraform init` to surface connectivity/auth issues before operations."],"tags":["terraform","backend","workspace","cloud","permissions","api"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}