{"record":{"id":"492d238357a0758d","repo":"hashicorp/terraform","slug":"s-errored-492d23","errorCode":null,"errorMessage":"%s errored.","messagePattern":"(.+?) errored\\.","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/cloud/backend_common.go","lineNumber":393,"sourceCode":"\t\t\t\t\t\tnext = false\n\t\t\t\t\t}\n\t\t\t\t\tline = append(line, l...)\n\t\t\t\t}\n\n\t\t\t\tif next || len(line) > 0 {\n\t\t\t\t\tb.CLI.Output(b.Colorize().Color(string(line)))\n\t\t\t\t}\n\t\t\t}\n\t\t}\n\n\t\tswitch pc.Status {\n\t\tcase tfe.PolicyPasses:\n\t\t\tif (r.HasChanges && op.Type == backendrun.OperationTypeApply || i < len(r.PolicyChecks)-1) && b.CLI != nil {\n\t\t\t\tb.CLI.Output(\"\\n------------------------------------------------------------------------\")\n\t\t\t}\n\t\t\tcontinue\n\t\tcase tfe.PolicyErrored:\n\t\t\treturn fmt.Errorf(\"%s errored.\", msgPrefix)\n\t\tcase tfe.PolicyHardFailed:\n\t\t\treturn fmt.Errorf(\"%s hard failed.\", msgPrefix)\n\t\tcase tfe.PolicySoftFailed:\n\t\t\trunURL := fmt.Sprintf(runHeaderErr, b.Hostname, b.Organization, op.Workspace, r.ID)\n\n\t\t\tif op.Type == backendrun.OperationTypePlan || op.UIOut == nil || op.UIIn == nil ||\n\t\t\t\t!pc.Actions.IsOverridable || !pc.Permissions.CanOverride {\n\t\t\t\treturn fmt.Errorf(\"%s soft failed.\\n%s\", msgPrefix, runURL)\n\t\t\t}\n\n\t\t\tif op.AutoApprove {\n\t\t\t\tif _, err = b.client.PolicyChecks.Override(stopCtx, pc.ID); err != nil {\n\t\t\t\t\treturn b.generalError(fmt.Sprintf(\"Failed to override policy check.\\n%s\", runURL), err)\n\t\t\t\t}\n\t\t\t} else if !b.input {\n\t\t\t\treturn errPolicyOverrideNeedsUIConfirmation\n\t\t\t} else {\n\t\t\t\topts := &terraform.InputOpts{","sourceCodeStart":375,"sourceCodeEnd":411,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/cloud/backend_common.go#L375-L411","documentation":"Policy check entered tfe.PolicyErrored: the policy worker itself crashed/timed out without producing pass/fail. Unlike soft/hard failed, 'errored' means the policy engine could not evaluate, so the backend treats the run as failed without offering override.","triggerScenarios":"pc.Status == tfe.PolicyErrored after the policy check completes: policy container OOM/killed; sentinel/opa runtime panic; policy worker timeout; misconfigured policy set referencing a missing module.","commonSituations":"Policy set points at a private VCS repo whose key rotated; sentinel policy syntax error; policy worker pod restarted during evaluation; large plan exceeded policy eval memory.","solutions":["Inspect the policy check logs in the TFE UI for the underlying runtime error.","Fix policy syntax/module references and re-run.","Increase policy worker resources / timeout if the cause is memory or time.","Temporarily disable the broken policy set to unblock, then restore."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// surface policy errors before they abort the run\nfunc policySetHealthy(client *tfe.Client, org string) error {\n    sets, err := client.PolicySets.List(ctx, org, nil)\n    if err != nil { return err }\n    for _, ps := range sets.Items {\n        if ps.Status == \"error\" || ps.Status == \"errored\" {\n            return fmt.Errorf(\"policy set %s errored; check logs\", ps.Name)\n        }\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Test policies in an advisory policy set before promoting to mandatory.","Keep VCS keys for policy sets current.","Monitor policy worker resources; raise limits on OOM.","Validate sentinel syntax in CI before pushing."],"tags":["tfe","hcp","cloud-backend","policy","sentinel"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}