{"record":{"id":"409683487110dfc6","repo":"hashicorp/terraform","slug":"error-loading-workspace-w","errorCode":null,"errorMessage":"error loading workspace: %w","messagePattern":"error loading workspace: %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote/backend_context.go","lineNumber":108,"sourceCode":"\tif op.AllowUnsetVariables {\n\t\t// If we're not going to use the variables in an operation we'll be\n\t\t// more lax about them, stubbing out any unset ones as unknown.\n\t\t// This gives us enough information to produce a consistent context,\n\t\t// but not enough information to run a real operation (plan, apply, etc)\n\t\tret.PlanOpts.SetVariables = stubAllVariables(op.Variables, rootMod.Variables)\n\t} else {\n\t\t// The underlying API expects us to use the opaque workspace id to request\n\t\t// variables, so we'll need to look that up using our organization name\n\t\t// and workspace name.\n\t\tremoteWorkspaceID, err := b.getRemoteWorkspaceID(context.Background(), op.Workspace)\n\t\tif err != nil {\n\t\t\tdiags = diags.Append(fmt.Errorf(\"error finding remote workspace: %w\", err))\n\t\t\treturn nil, nil, diags\n\t\t}\n\n\t\tw, err := b.fetchWorkspace(context.Background(), b.organization, op.Workspace)\n\t\tif err != nil {\n\t\t\tdiags = diags.Append(fmt.Errorf(\"error loading workspace: %w\", err))\n\t\t\treturn nil, nil, diags\n\t\t}\n\n\t\tif isLocalExecutionMode(w.ExecutionMode) {\n\t\t\tlog.Printf(\"[TRACE] skipping retrieving variables from workspace %s/%s (%s), workspace is in Local Execution mode\", remoteWorkspaceName, b.organization, remoteWorkspaceID)\n\t\t} else {\n\t\t\tlog.Printf(\"[TRACE] backend/remote: retrieving variables from workspace %s/%s (%s)\", remoteWorkspaceName, b.organization, remoteWorkspaceID)\n\t\t\ttfeVariables, err := b.client.Variables.ListAll(context.Background(), remoteWorkspaceID, nil)\n\t\t\tif err != nil && err != tfe.ErrResourceNotFound {\n\t\t\t\tdiags = diags.Append(fmt.Errorf(\"error loading variables: %w\", err))\n\t\t\t\treturn nil, nil, diags\n\t\t\t}\n\t\t\tif tfeVariables != nil {\n\t\t\t\tif op.Variables == nil {\n\t\t\t\t\top.Variables = make(map[string]arguments.UnparsedVariableValue)\n\t\t\t\t}\n\t\t\t\tfor _, v := range tfeVariables.Items {\n\t\t\t\t\tif v.Category == tfe.CategoryTerraform {","sourceCodeStart":90,"sourceCodeEnd":126,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote/backend_context.go#L90-L126","documentation":"Thrown by the remote (Terraform Cloud / Enterprise) backend while constructing the operation context: it needs the workspace object to check ExecutionMode and decide whether to pull variables. b.fetchWorkspace wraps the TFC/TFE Workspaces.Read RPC and surfaces any non-success response here. The %w is the underlying tfe client / HTTP error.","triggerScenarios":"b.fetchWorkspace(ctx, b.organization, op.Workspace) returns a non-nil error: the workspace name does not exist in the org, the organization is wrong, the API token is invalid/expired/scoped to another org, TFC/TFE returned 5xx, or the HTTP layer failed (DNS, TLS, proxy, timeout).","commonSituations":"Typo in workspaces.name/prefix in the backend block; organization renamed in TFC after backend config was written; terraform login token expired or revoked; self-hosted TFE hostname unreachable; corporate proxy blocking api.terraform.io; TFC incident.","solutions":["Confirm the workspace name and organization in the backend config block match an existing TFC/TFE workspace (check exact casing).","Verify the credential: re-run `terraform login <hostname>` or refresh TF_TOKEN_<hostname> / TFE_TOKEN; ensure the token belongs to the configured organization.","Check network reachability to the TFC/TFE hostname (curl, TLS, proxy env vars HTTPS_PROXY / NO_PROXY).","Consult status.hashicorp.com (or your TFE admin) for an active platform incident and retry."],"exampleFix":"// before\nworkspaces { name = \"prod-web\" }   // typo: real workspace is prod-webapp\n// after\nworkspaces { name = \"prod-webapp\" }","handlingStrategy":"validation","validationCode":"// Pre-flight: verify workspace exists before running plan/apply\nimport tfe \"github.com/hashicorp/go-tfe\"\n\nfunc workspaceExists(token, hostname, org, ws string) error {\n    cfg := &tfe.Config{Token: token, BaseURL: hostname}\n    c, err := tfe.NewClient(cfg)\n    if err != nil { return err }\n    _, err = c.Workspaces.Read(ctx, org, ws)\n    return err // nil == found\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Keep backend 'workspaces.name'/'prefix' and 'organization' in version control and CI-validated against the TFC org.","Use a dedicated CI token and rotate it; fail fast on 401 instead of letting fetchWorkspace bubble up.","Add a `terraform init` step in CI that exercises the backend config before plan."],"tags":["terraform","remote-backend","tfe","workspace","auth","network"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}