{"record":{"id":"5b01dcff16081db2","repo":"hashicorp/terraform","slug":"failed-to-upload-object-w","errorCode":null,"errorMessage":"failed to upload object: %w","messagePattern":"failed to upload object: %w","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/oci/client.go","lineNumber":195,"sourceCode":"\t\tRequestMetadata: common.RequestMetadata{\n\t\t\tRetryPolicy: getDefaultRetryPolicy(),\n\t\t},\n\t}\n\n\t// Handle encryption settings\n\tif c.kmsKeyID != \"\" {\n\t\tputRequest.OpcSseKmsKeyId = common.String(c.kmsKeyID)\n\t} else if c.SSECustomerKey != \"\" && c.SSECustomerKeySHA256 != \"\" {\n\t\tputRequest.OpcSseCustomerKey = common.String(c.SSECustomerKey)\n\t\tputRequest.OpcSseCustomerKeySha256 = common.String(c.SSECustomerKeySHA256)\n\t\tputRequest.OpcSseCustomerAlgorithm = common.String(c.SSECustomerAlgorithm)\n\t}\n\n\tlogger.Info(fmt.Sprintf(\"Uploading remote state: %s\", c.path))\n\n\tputResponse, err := c.objectStorageClient.PutObject(ctx, putRequest)\n\tif err != nil {\n\t\treturn fmt.Errorf(\"failed to upload object: %w\", err)\n\t}\n\n\tlogger.Info(\"Uploaded state file response: %+v\\n\", putResponse)\n\treturn nil\n}\n\nfunc (c *RemoteClient) Delete() tfdiags.Diagnostics {\n\tvar diags tfdiags.Diagnostics\n\n\treturn diags.Append(c.DeleteAllObjectVersions())\n}\nfunc (c *RemoteClient) DeleteAllObjectVersions() error {\n\trequest := objectstorage.ListObjectVersionsRequest{\n\t\tBucketName:    common.String(c.bucketName),\n\t\tNamespaceName: common.String(c.namespace),\n\t\tPrefix:        common.String(c.path),\n\t\tRequestMetadata: common.RequestMetadata{\n\t\t\tRetryPolicy: getDefaultRetryPolicy(),","sourceCodeStart":177,"sourceCodeEnd":213,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/oci/client.go#L177-L213","documentation":"PutObject (single-part state upload) failed; the error is wrapped verbatim. Common OCI causes: 403 (no OBJECT_CREATE/OBJECT_OVERWRITE), invalid or inaccessible KMS key, SSE-C customer key mismatch against the bucket's default encryption, quota exceeded, or 5xx.","triggerScenarios":"IAM principal lacks OBJECT_CREATE/OBJECT_OVERWRITE; KMS key ID wrong, revoked, or in a different compartment the principal cannot use; SSE-C key rotated so writes now conflict with bucket default; object versioning/quota limits hit.","commonSituations":"Cross-team IAM change removed write permission; KMS key rotated but kms_key_id in backend config not updated; SSE-C and SSE-KMS both partially configured; bucket hard quota reached.","solutions":["Verify the principal has OBJECT_CREATE and (for overwrite) OBJECT_OVERWRITE on the bucket.","If using KMS, confirm kms_key_id points to an active key in an accessible compartment and that the principal can use it (inspectKey, encrypt/decrypt).","If using SSE-C, confirm key/sha256/algorithm are consistent across reads and writes.","Retry transient 5xx; the existing retry policy handles idempotent PutObject failures."],"exampleFix":"// before: backend uses a KMS key the runner principal cannot use\nterraform {\n  backend \"oci\" { kms_key_id = \"ocid1.key.oc1...old\" }\n}\n// after: point at the active key the principal has encrypt/decrypt on\nterraform {\n  backend \"oci\" { kms_key_id = var.active_kms_key_ocid }\n}","handlingStrategy":"retry","validationCode":"// Verify write + KMS permissions before the first apply\nfunc canWrite(c *RemoteClient) error {\n    probe := objectstorage.PutObjectRequest{\n        NamespaceName: common.String(c.namespace),\n        BucketName:    common.String(c.bucketName),\n        ObjectName:    common.String(c.path + \".probe\"),\n        PutObjectBody: io.NopCloser(bytes.NewReader([]byte(\"probe\"))),\n    }\n    if c.kmsKeyID != \"\" { probe.OpcSseKmsKeyId = common.String(c.kmsKeyID) }\n    _, err := c.objectStorageClient.PutObject(context.Background(), probe)\n    if err != nil { _ = c.objectStorageClient.DeleteObject(context.Background(), objectstorage.DeleteObjectRequest{NamespaceName: probe.NamespaceName, BucketName: probe.BucketName, ObjectName: probe.ObjectName}) }\n    return err\n}","typeGuard":"func isOCIError(err error) (common.ServiceError, bool) {\n    var se common.ServiceError\n    return se, errors.As(err, &se)\n}","tryCatchPattern":"// Retry transient 5xx/429 on PutObject; surface 4xx for config fixes\nfor i := 0; i < 3; i++ {\n    err := c.uploadSinglePartObject(ctx, data, sum)\n    if err == nil { break }\n    var se common.ServiceError\n    if errors.As(err, &se) && (se.GetHTTPStatusCode() == 429 || se.GetHTTPStatusCode() >= 500) {\n        time.Sleep(backoff(i)); continue\n    }\n    return err\n}","preventionTips":["Grant the principal OBJECT_CREATE and OBJECT_OVERWRITE on the state bucket.","Keep kms_key_id pointing at an active key the principal can use (encrypt/decrypt/inspectKey).","Pin SSE-C keys as key+sha256 pairs in your secret manager.","Watch for IAM/KMS changes that break the principal mid-pipeline."],"tags":["oci","object-storage","encryption","iam"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}