{"record":{"id":"3fb53880a0a206fa","repo":"hashicorp/terraform","slug":"state-store-provider-q-s-was-not-approved-so","errorCode":null,"errorMessage":"State store provider %q (%s) was not approved, so init cannot continue.","messagePattern":"State store provider %q \\((.+?)\\) was not approved, so init cannot continue\\.","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/command/meta_backend.go","lineNumber":3239,"sourceCode":"Hashes:\n%s\n`,\n\t\t\tlock.Provider().Type,\n\t\t\tlock.Provider(),\n\t\t\tlock.Version(),\n\t\t\tgetproviders.CurrentPlatform.String(),\n\t\t\tauthentication,\n\t\t\thashList.String(),\n\t\t),\n\t\tDescription: fmt.Sprintf(`Check the details above for provider %q and confirm that you trust the provider.\n\tOnly 'yes' will be accepted to confirm.`, lock.Provider().Type),\n\t})\n\tif err != nil {\n\t\treturn diags.Append(fmt.Errorf(\"Failed to approve use of state storage provider: %s\", err))\n\t}\n\tif v != \"yes\" {\n\t\treturn diags.Append(\n\t\t\tfmt.Errorf(\"State store provider %q (%s) was not approved, so init cannot continue.\",\n\t\t\t\tlock.Provider().Type,\n\t\t\t\tlock.Provider(),\n\t\t\t),\n\t\t)\n\t}\n\treturn diags\n}\n\n//-------------------------------------------------------------------\n// Output constants and initialization code\n//-------------------------------------------------------------------\n\nconst inputCloudInitCreateWorkspace = `\nThere are no workspaces with the configured tags (%s)\nin your HCP Terraform organization. To finish initializing, Terraform needs at\nleast one workspace available.\n\nTerraform can create a properly tagged workspace for you now. Please enter a","sourceCodeStart":3221,"sourceCodeEnd":3257,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/command/meta_backend.go#L3221-L3257","documentation":"Thrown during `terraform init` after a state-storage provider is installed but before it is trusted. The CLI prompts the user to approve the provider; any response other than the literal string \"yes\" aborts initialization. It protects against silently delegating state management to an unvetted provider.","triggerScenarios":"Reached only when `terraform init` configures a state storage provider that is not yet in the trusted set, input is enabled, and `m.UIInput().Input(...)` returns a value != \"yes\". The prompt Id is `approve-provider-<type>-<version>`.","commonSituations":"CI pipelines or scripts where stdin is not a TTY (input returns empty), a user typing \"y\" or \"Y\" instead of \"yes\", declining an unknown provider whose hashes do not match expectations, or a wrapper that answers the prompt with the wrong value.","solutions":["Enter exactly `yes` (lowercase, full word) at the interactive prompt.","In non-interactive runs, echo the approval: `echo yes | terraform init`, or set `-input=false` and pre-pin the provider in the dependency lock file so approval is bypassed.","Verify the provider's platform, authentication, and hash list shown in the prompt match an officially distributed build before approving.","If the provider is genuinely untrusted, remove or correct the `provider` block referencing it as a state store in the backend configuration."],"exampleFix":"# before (CI hangs / returns empty stdin)\nterraform init\n# after\necho yes | terraform init -input=false","handlingStrategy":"validation","validationCode":"# Before terraform init, ensure the provider is pre-approved or supply approval.\n# Pre-pin the state-storage provider in .terraform.lock.hcl so no prompt fires:\nterraform providers lock -platform=linux_amd64\n# In CI, provide the exact approval and disable the prompt:\necho yes | terraform init -input=false","typeGuard":null,"tryCatchPattern":"# In a wrapper script, detect the approval-required condition and fail fast:\nif ! terraform init -input=false >/tmp/init.log 2>&1; then\n  if grep -q 'was not approved, so init cannot continue' /tmp/init.log; then\n    echo \"State-store provider needs approval; rerun with 'echo yes | terraform init'\" >&2\n    exit 2\n  fi\n  cat /tmp/init.log; exit 1\nfi","preventionTips":["Commit .terraform.lock.hcl so provider hashes are pinned and trusted up front.","Run init with -input=false in automation and supply explicit approval via stdin.","Document which provider manages state so reviewers recognize the approval prompt."],"tags":["init","provider","state-store","interactive-prompt","approval"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}