{"record":{"id":"577941cb2aa026b2","repo":"hashicorp/terraform","slug":"your-version-of-terraform-enterprise-does-not-supp","errorCode":null,"errorMessage":"your version of Terraform Enterprise does not support key-value tags. Please upgrade Terraform Enterprise to a version that supports this feature or use set type tags instead.","messagePattern":"your version of Terraform Enterprise does not support key-value tags\\. Please upgrade Terraform Enterprise to a version that supports this feature or use set type tags instead\\.","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/cloud/backend.go","lineNumber":50,"sourceCode":"\t\"github.com/hashicorp/terraform/internal/plans\"\n\t\"github.com/hashicorp/terraform/internal/states/statemgr\"\n\t\"github.com/hashicorp/terraform/internal/terraform\"\n\t\"github.com/hashicorp/terraform/internal/tfdiags\"\n\ttfversion \"github.com/hashicorp/terraform/version\"\n\n\tbackendLocal \"github.com/hashicorp/terraform/internal/backend/local\"\n)\n\nconst (\n\tdefaultHostname    = \"app.terraform.io\"\n\tdefaultParallelism = 10\n\ttfeServiceID       = \"tfe.v2\"\n\theaderSourceKey    = \"X-Terraform-Integration\"\n\theaderSourceValue  = \"cloud\"\n\tgenericHostname    = \"localterraform.com\"\n)\n\nvar ErrCloudDoesNotSupportKVTags = errors.New(\"your version of Terraform Enterprise does not support key-value tags. Please upgrade Terraform Enterprise to a version that supports this feature or use set type tags instead.\")\n\n// Cloud is an implementation of backendrun.OperationsBackend in service of the HCP Terraform or Terraform Enterprise\n// integration for Terraform CLI. This backend is not intended to be surfaced at the user level and\n// is instead an implementation detail of cloud.Cloud.\ntype Cloud struct {\n\t// CLI and Colorize control the CLI output. If CLI is nil then no CLI\n\t// output will be done. If CLIColor is nil then no coloring will be done.\n\tCLI      cli.Ui\n\tCLIColor *colorstring.Colorize\n\n\t// ContextOpts are the base context options to set when initializing a\n\t// new Terraform context. Many of these will be overridden or merged by\n\t// Operation. See Operation for more details.\n\tContextOpts *terraform.ContextOpts\n\n\t// client is the HCP Terraform or Terraform Enterprise API client.\n\tclient *tfe.Client\n","sourceCodeStart":32,"sourceCodeEnd":68,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/cloud/backend.go#L32-L68","documentation":"Exported sentinel ErrCloudDoesNotSupportKVTags (cloud/backend.go:50). The cloud backend's workspaceTagsRequireUpdate (cloud/backend.go:1233-1237) returns it when the configured workspace tags include a key=value pair but the connected TFE server does not support tag bindings (supportsKVTags == false) — i.e. an older Terraform Enterprise. backend.go:841 wraps it with the suggestion to use key-only tags or upgrade TFE.","triggerScenarios":"Using the 'cloud' backend with `workspaces { tags = { Environment = \"prod\" } }` (key-value form) against a Terraform Enterprise installation older than the version that introduced tag bindings. workspaceTagsRequireUpdate detects a non-empty value with supportsKVTags==false and sets err = ErrCloudDoesNotSupportKVTags.","commonSituations":"Self-hosted TFE behind the supported feature set. Pointing the cloud backend at an older TFE while your config uses modern KV tags. Migrating a workspace from HCP Terraform to an older TFE.","solutions":["Upgrade your Terraform Enterprise to a version that supports key-value tag bindings.","Switch the backend tag config to set-type (key-only) tags: `workspaces { tags = [\"env:prod\"] }`.","Remove the value portion of the offending tags so only keys remain."],"exampleFix":"# before\nworkspaces {\n  name = \"app\"\n  tags = { Environment = \"prod\" }\n}\n# after (set-type tags)\nworkspaces {\n  name = \"app\"\n  tags = [\"Environment:prod\"]\n}","handlingStrategy":"type-guard","validationCode":"// Before apply, confirm TFE supports tag bindings if you use KV tags.\n// Check server version >= the tag-bindings release, or keep tags key-only.\nws, err := b.client.Workspaces.Read(ctx, org, name)\nif !supportsKVTags(ws) && hasKVTags(config.Tags) {\n    return ErrCloudDoesNotSupportKVTags\n}","typeGuard":"// Use set-type (key-only) tags when TFE version is unknown/old.\nworkspaces { tags = [\"env:prod\"] } // string set form, no values","tryCatchPattern":"if errors.Is(err, cloud.ErrCloudDoesNotSupportKVTags) {\n    // downgrade config to set-type tags and re-plan, or upgrade TFE\n}","preventionTips":["Use set-type (key-only) tags unless you know your TFE supports tag bindings.","Keep TFE on a supported version before adopting KV tags.","Branch on errors.Is(err, ErrCloudDoesNotSupportKVTags)."],"tags":["terraform","cloud-backend","tfe","terraform-enterprise","tags","version-mismatch","config"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}