{"record":{"id":"5d05cf02725e65aa","repo":"hashicorp/terraform","slug":"at-most-1-action-can-be-invoked-per-operation","errorCode":null,"errorMessage":"at most 1 action can be invoked per operation","messagePattern":"at most 1 action can be invoked per operation","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/cloud/backend_plan.go","lineNumber":186,"sourceCode":"\tif len(op.Targets) != 0 {\n\t\trunOptions.TargetAddrs = make([]string, 0, len(op.Targets))\n\t\tfor _, addr := range op.Targets {\n\t\t\trunOptions.TargetAddrs = append(runOptions.TargetAddrs, addr.String())\n\t\t}\n\t}\n\n\tif len(op.ActionTargets) != 0 {\n\t\tif len(op.ActionTargets) > 1 {\n\t\t\t// For now, we only support a single action from the command line.\n\t\t\t// We've future proofed the API and inputs so we can send multiple\n\t\t\t// but versions of Terraform will enforce this both here, and\n\t\t\t// on the other side.\n\t\t\t//\n\t\t\t// It shouldn't actually be possible to reach here anyway - we're\n\t\t\t// validating at the point the flag is read that it only has a\n\t\t\t// single entry. But, we'll check again to be safe.\n\t\t\treturn nil, b.generalError(\"Invalid arguments\",\n\t\t\t\terrors.New(\"at most 1 action can be invoked per operation\"))\n\t\t}\n\n\t\tfor _, target := range op.ActionTargets {\n\t\t\trunOptions.InvokeActionAddrs = append(runOptions.InvokeActionAddrs, target.String())\n\t\t}\n\n\t}\n\n\tif len(op.ForceReplace) != 0 {\n\t\trunOptions.ReplaceAddrs = make([]string, 0, len(op.ForceReplace))\n\t\tfor _, addr := range op.ForceReplace {\n\t\t\trunOptions.ReplaceAddrs = append(runOptions.ReplaceAddrs, addr.String())\n\t\t}\n\t}\n\n\tif len(op.PolicyPaths) != 0 {\n\t\trunOptions.PolicyPaths = append(runOptions.PolicyPaths, op.PolicyPaths...)\n\t}","sourceCodeStart":168,"sourceCodeEnd":204,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/cloud/backend_plan.go#L168-L204","documentation":"Returned by the cloud backend plan path (cloud/backend_plan.go:186) when op.ActionTargets contains more than one entry. The -invoke-action CLI flag is currently limited to a single action address per operation; the backend re-checks this even though flag parsing already limits it, and emits a generalError('Invalid arguments', ...) wrapping this message.","triggerScenarios":"Invoking terraform plan/apply with `-invoke-action` supplied more than once (or a future caller populating op.ActionTargets with >1 entry) so len(op.ActionTargets) > 1 at cloud/backend_plan.go:184-188.","commonSituations":"Passing `-invoke-action addr1 -invoke-action addr2`. A wrapper/tool constructing an Operation with multiple action targets.","solutions":["Pass exactly one -invoke-action target per invocation.","If you need multiple actions, run separate terraform plan/apply commands for each."],"exampleFix":"# before\nterraform plan -invoke-action module.a -invoke-action module.b\n# after\nterraform plan -invoke-action module.a","handlingStrategy":"validation","validationCode":"// Enforce single-action rule before building the operation.\nif len(actionTargets) > 1 {\n    return errors.New(\"at most 1 action can be invoked per operation\")\n}\nrunOptions.InvokeActionAddrs = actionTargets[:1]","typeGuard":"func singleAction(xs []string) bool { return len(xs) <= 1 }","tryCatchPattern":null,"preventionTips":["Pass -invoke-action at most once per command.","Run separate plan/apply invocations for multiple actions.","Validate the flag count in any wrapper before delegating to terraform."],"tags":["terraform","cloud-backend","cli","validation","plan","actions"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}