{"record":{"id":"64a7c2ef8b3d2189","repo":"hashicorp/terraform","slug":"error-creating-workspace-s-v-64a7c2","errorCode":null,"errorMessage":"error creating workspace %s: %v","messagePattern":"error creating workspace (.+?): (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/cloud/backend.go","lineNumber":810,"sourceCode":"\t\t\t\tcreateOpts := tfe.ProjectCreateOptions{\n\t\t\t\t\tName: b.WorkspaceMapping.Project,\n\t\t\t\t}\n\t\t\t\t// didn't find project, create it instead\n\t\t\t\tlog.Printf(\"[TRACE] cloud: Creating %s project %s/%s\", b.appName, b.Organization, b.WorkspaceMapping.Project)\n\t\t\t\tproject, err := b.client.Projects.Create(context.Background(), b.Organization, createOpts)\n\t\t\t\tif err != nil && err != tfe.ErrResourceNotFound {\n\t\t\t\t\treturn nil, diags.Append(fmt.Errorf(\"failed to create project %s: %v\", b.WorkspaceMapping.Project, err))\n\t\t\t\t}\n\t\t\t\tconfiguredProject = project\n\t\t\t\tworkspaceCreateOptions.Project = configuredProject\n\t\t\t}\n\t\t}\n\n\t\t// Create a workspace\n\t\tlog.Printf(\"[TRACE] cloud: Creating %s workspace %s/%s\", b.appName, b.Organization, name)\n\t\tworkspace, err = b.client.Workspaces.Create(context.Background(), b.Organization, workspaceCreateOptions)\n\t\tif err != nil {\n\t\t\treturn nil, diags.Append(fmt.Errorf(\"error creating workspace %s: %v\", name, err))\n\t\t}\n\n\t\tremoteTFVersion = workspace.TerraformVersion\n\n\t\t// Attempt to set the new workspace to use this version of Terraform. This\n\t\t// can fail if there's no enabled tool_version whose name matches our\n\t\t// version string, but that's expected sometimes -- just warn and continue.\n\t\tversionOptions := tfe.WorkspaceUpdateOptions{\n\t\t\tTerraformVersion: tfe.String(tfversion.String()),\n\t\t}\n\t\t_, err := b.client.Workspaces.UpdateByID(context.Background(), workspace.ID, versionOptions)\n\t\tif err == nil {\n\t\t\tremoteTFVersion = tfversion.String()\n\t\t} else {\n\t\t\t// TODO: Ideally we could rely on the client to tell us what the actual\n\t\t\t// problem was, but we currently can't get enough context from the error\n\t\t\t// object to do a nicely formatted message, so we're just assuming the\n\t\t\t// issue was that the version wasn't available since that's probably what","sourceCodeStart":792,"sourceCodeEnd":828,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/cloud/backend.go#L792-L828","documentation":"Returned when b.client.Workspaces.Create fails for the resolved workspace name. This is the terminal step of the create-workspace path: project (if any) was resolved above, then the workspace POST itself errored. The wrapped %v is the raw TFE client error, so HTTP status and API message travel with it.","triggerScenarios":"Workspaces.Create(ctx, org, workspaceCreateOptions) returns non-nil err: 409 workspace name already exists in the org; 422 for invalid name or duplicate-when-not-allowed; 401/403 if the token cannot create workspaces; 404 if the organization itself is wrong; transport/timeout against the TFE host.","commonSituations":"TF_WORKSPACE points at a name with uppercase letters or spaces; the cloud block's `name` collides with an existing workspace the token can read but not write; the organization string is misspelled so the org lookup 404s into a create failure; an auto-create race between two `terraform init` runs.","solutions":["Verify the workspace name matches TFE naming rules (lowercase alphanumerics, _, -, max 90 chars) and rerun.","Confirm the API token has 'Workspaces: Admin' / create scope on the target organization.","Check the organization spelling in the cloud block and the hostname in `hostname`.","If the workspace already exists, do not rely on auto-create—reference it explicitly and ensure the token can read it.","For races, serialize `init` across CI agents or pre-create the workspace."],"exampleFix":"// before\ncloud {\n  organization = \"acme\"\n  workspaces { name = \"Prod Env\" }\n}\n\n// after\ncloud {\n  organization = \"acme\"\n  workspaces { name = \"prod-env\" }\n}","handlingStrategy":"validation","validationCode":"func validWorkspaceName(name string) error {\n    if name == \"\" || len(name) > 90 {\n        return fmt.Errorf(\"workspace name length invalid\")\n    }\n    if !regexp.MustCompile(`^[a-z0-9][a-z0-9_-]*$`).MatchString(name) {\n        return fmt.Errorf(\"workspace name %q must be lowercase alnum/-/_\", name)\n    }\n    return nil\n}\n// also confirm token scope:\n//   Workspaces: Admin on the target organization","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Verify workspace name conforms to TFE rules before init.","Ensure the token has workspace-create scope on the org.","If the workspace exists, reference it rather than relying on auto-create.","Serialize concurrent inits against a new workspace name."],"tags":["tfe","hcp","cloud-backend","workspace","permissions"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}