{"record":{"id":"404bb1d757d14bc2","repo":"hashicorp/terraform","slug":"error-loading-credentials-s","errorCode":null,"errorMessage":"Error loading credentials: %s","messagePattern":"Error loading credentials: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/gcs/backend.go","lineNumber":198,"sourceCode":"\t\t\tAccessToken: v,\n\t\t})\n\t} else if v := data.String(\"credentials\"); v != \"\" {\n\t\tcreds = v\n\t} else if v := os.Getenv(\"GOOGLE_BACKEND_CREDENTIALS\"); v != \"\" {\n\t\tcreds = v\n\t} else {\n\t\tcreds = os.Getenv(\"GOOGLE_CREDENTIALS\")\n\t}\n\n\tif tokenSource != nil {\n\t\tcredOptions = append(credOptions, option.WithTokenSource(tokenSource))\n\t} else if creds != \"\" {\n\n\t\t// to mirror how the provider works, we accept the file path or the contents\n\t\tcontents, err := readPathOrContents(creds)\n\t\tif err != nil {\n\t\t\treturn backendbase.ErrorAsDiagnostics(\n\t\t\t\tfmt.Errorf(\"Error loading credentials: %s\", err),\n\t\t\t)\n\t\t}\n\n\t\tif !json.Valid([]byte(contents)) {\n\t\t\treturn backendbase.ErrorAsDiagnostics(\n\t\t\t\tfmt.Errorf(\"the string provided in credentials is neither valid json nor a valid file path\"),\n\t\t\t)\n\t\t}\n\n\t\tcredOptions = append(credOptions, option.WithCredentialsJSON([]byte(contents)))\n\t}\n\n\t// Service Account Impersonation\n\tif v := data.String(\"impersonate_service_account\"); v != \"\" {\n\t\tServiceAccount := v\n\t\tvar delegates []string\n\n\t\tdelegatesVal := data.GetAttr(\"impersonate_service_account_delegates\", cty.List(cty.String))","sourceCodeStart":180,"sourceCodeEnd":216,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/gcs/backend.go#L180-L216","documentation":"Thrown when the GOOGLE_CREDENTIALS value (or the credentials config attribute) points to a path or literal content that readPathOrContents cannot resolve. readPathOrContents accepts either a filesystem path or raw content, and this error means neither interpretation succeeded (e.g., the file does not exist or is unreadable).","triggerScenarios":"Configure runs, creds is non-empty, and readPathOrContents(creds) returns an error — typically a missing file, a permission denied on the file, or a malformed path string.","commonSituations":"GOOGLE_CREDENTIALS points to a relative path resolved from the wrong working directory; the service account JSON was deleted; the file has restrictive permissions; the value is a typo'd path rather than JSON content.","solutions":["Verify the path exists: check the value of GOOGLE_CREDENTIALS and stat the file it names.","If passing inline JSON, paste the full service-account JSON rather than a path.","Fix file permissions so the process running terraform can read it (e.g., chmod 600 service-account.json).","Use an absolute path to avoid working-directory resolution issues."],"exampleFix":"// before\nexport GOOGLE_CREDENTIALS=./creds/sa.json   # relative, wrong cwd\n// after\nexport GOOGLE_CREDENTIALS=/absolute/path/to/sa.json","handlingStrategy":"validation","validationCode":"// Validate the credentials source resolves before Configure.\ncreds := os.Getenv(\"GOOGLE_CREDENTIALS\")\nif creds == \"\" {\n    creds = /* config attr */ \"\"\n}\nif creds != \"\" {\n    if _, err := readPathOrContents(creds); err != nil {\n        return fmt.Errorf(\"credentials source is not a readable path or content: %w\", err)\n    }\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Always use absolute paths for GOOGLE_CREDENTIALS.","Materialize the key file via a secret manager step in CI before running terraform.","Test the credential file with `gcloud auth activate-service-account --key-file` first."],"tags":["gcs","backend","credentials","authentication","configuration"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}