{"record":{"id":"54c2100889e75fbc","repo":"hashicorp/terraform","slug":"failed-to-load-state-w","errorCode":null,"errorMessage":"failed to load state: %w","messagePattern":"failed to load state: %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/cloud/state.go","lineNumber":586,"sourceCode":"\t\t\treturn nil, fmt.Errorf(\"current outputs were not ready to be read within the deadline. Please try again\")\n\t\tcase context.Canceled:\n\t\t\treturn nil, fmt.Errorf(\"canceled reading current outputs\")\n\t\t}\n\t\treturn nil, fmt.Errorf(\"could not read state version outputs: %w\", err)\n\t}\n\n\tresult := make(map[string]*states.OutputValue)\n\n\tfor _, output := range so.Items {\n\t\tif output.DetailedType == nil {\n\t\t\t// If there is no detailed type information available, this state was probably created\n\t\t\t// with a version of terraform < 1.3.0. In this case, we'll eject completely from this\n\t\t\t// function and fall back to the old behavior of reading the entire state file, which\n\t\t\t// requires a higher level of authorization.\n\t\t\tlog.Printf(\"[DEBUG] falling back to reading full state\")\n\n\t\t\tif err := s.RefreshState(); err != nil {\n\t\t\t\treturn nil, fmt.Errorf(\"failed to load state: %w\", err)\n\t\t\t}\n\n\t\t\tstate := s.State()\n\t\t\tif state == nil {\n\t\t\t\t// We know that there is supposed to be state (and this is not simply a new workspace\n\t\t\t\t// without state) because the fallback is only invoked when outputs are present but\n\t\t\t\t// detailed types are not available.\n\t\t\t\treturn nil, ErrStateVersionUnauthorizedUpgradeState\n\t\t\t}\n\n\t\t\treturn state.RootOutputValues, nil\n\t\t}\n\n\t\tif output.Sensitive {\n\t\t\t// Since this is a sensitive value, the output must be requested explicitly in order to\n\t\t\t// read its value, which is assumed to be present by callers\n\t\t\tsensitiveOutput, err := s.tfeClient.StateVersionOutputs.Read(ctx, output.ID)\n\t\t\tif err != nil {","sourceCodeStart":568,"sourceCodeEnd":604,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/cloud/state.go#L568-L604","documentation":"Thrown by GetRootOutputValues during the fallback path: when an output lacks DetailedType (indicating pre-terraform-1.3.0 state), the code calls s.RefreshState() to read the full state and extract outputs the old way. This error wraps a RefreshState failure, meaning the full state could not be downloaded and parsed. The %w preserves the underlying refresh error (which itself may be a getStatePayload/read failure).","triggerScenarios":"A workspace whose state was last written by terraform < 1.3.0 (no DetailedType on outputs) AND the current RefreshState call fails due to network, auth, or download issues; the fallback path compounds any getStatePayload error (errors 525/526) with this wrapper.","commonSituations":"Legacy workspace never upgraded since pre-1.3.0, combined with a transient network issue or token expiry; migrating an old workspace to a new TFE instance where the service account lacks full-state-read permission needed by the fallback.","solutions":["Address the underlying RefreshState error first (check the wrapped error for network/auth/download details)","Upgrade the workspace state to a modern format by running terraform apply once successfully with terraform >= 1.3.0 to populate DetailedType and eliminate the fallback path","Verify the authenticated identity has permission to read the full state (the fallback requires higher authorization than the outputs-only path)"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Before calling GetRootOutputValues on a legacy workspace, refresh state once\n// to confirm the full-state-read path works:\nif err := state.RefreshState(); err != nil {\n    return fmt.Errorf(\"full state read will fail for legacy output fallback: %w\", err)\n}","typeGuard":null,"tryCatchPattern":"outputs, err := state.GetRootOutputValues(ctx)\nif err != nil && strings.Contains(err.Error(), \"failed to load state\") {\n    // The fallback path failed; the underlying RefreshState error is wrapped.\n    // Address the root cause (network/auth) then retry.\n    return nil, fmt.Errorf(\"legacy output fallback failed during state load: %w\", err)\n}\nreturn outputs, err","preventionTips":["Upgrade legacy workspaces (pre-1.3.0 state) by running a successful apply with terraform >= 1.3.0 to populate DetailedType","Ensure the service account has full-state-read permission since the legacy fallback requires it","Avoid mixing very old state formats with modern terraform versions without an intermediate upgrade apply"],"tags":["outputs","state-refresh","legacy-state","fallback","tfe","terraform"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}