{"record":{"id":"65af2a4e8068ccc9","repo":"hashicorp/terraform","slug":"secret-suffix-must-not-end-with-number-got","errorCode":null,"errorMessage":"secret_suffix must not end with '-<number>', got %q","messagePattern":"secret_suffix must not end with '-<number>', got %q","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/kubernetes/backend.go","lineNumber":334,"sourceCode":"\t\t\tkV, vV := it.Element()\n\t\t\tif vV.IsNull() {\n\t\t\t\tvV = cty.StringVal(\"\")\n\t\t\t}\n\t\t\tlabels[kV.AsString()] = vV.AsString()\n\t\t}\n\t\tb.labels = labels\n\t}\n\n\tns := data.String(\"namespace\")\n\tb.namespace = ns\n\n\tb.nameSuffix = data.String(\"secret_suffix\")\n\tif hasNumericSuffix(b.nameSuffix, \"-\") {\n\t\t// If the last segment is a number, it's considered invalid.\n\t\t// The backend automatically appends its own numeric suffix when chunking large state files into multiple secrets.\n\t\t// Allowing a user-defined numeric suffix could cause conflicts with this mechanism.\n\t\treturn backendbase.ErrorAsDiagnostics(\n\t\t\tfmt.Errorf(\"secret_suffix must not end with '-<number>', got %q\", b.nameSuffix),\n\t\t)\n\t}\n\n\tb.config = cfg\n\n\treturn nil\n}\n\nfunc getInitialConfig(data backendbase.SDKLikeData) (*restclient.Config, error) {\n\tvar cfg *restclient.Config\n\tvar err error\n\n\tinCluster := data.Bool(\"in_cluster_config\")\n\tif inCluster {\n\t\tcfg, err = restclient.InClusterConfig()\n\t\tif err != nil {\n\t\t\treturn nil, err\n\t\t}","sourceCodeStart":316,"sourceCodeEnd":352,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/kubernetes/backend.go#L316-L352","documentation":"Validation error during backend Configure: secret_suffix ends with a '-<number>' segment (backend.go:328-336). The k8s backend appends its own '-part-N' numeric suffix when chunking large state across multiple Secrets; a user-supplied numeric suffix would collide with that scheme, so it is rejected up front.","triggerScenarios":"Setting secret_suffix = \"foo-1\" or secret_suffix = \"team-42\" — anything where the final '-'-delimited segment is purely numeric. The check hasNumericSuffix(b.nameSuffix, \"-\") returns true.","commonSituations":"Copying a numeric convention from another backend; auto-generating suffixes with a numeric ID; renaming a workspace and appending a number.","solutions":["Change secret_suffix so its last '-' segment is non-numeric, e.g., \"foo-state\" instead of \"foo-1\".","If you need uniqueness, use letters/words in the final segment.","After fixing, re-run terraform init to re-configure the backend."],"exampleFix":"// before\nterraform {\n  backend \"kubernetes\" {\n    secret_suffix = \"myteam-7\"\n  }\n}\n// after\nterraform {\n  backend \"kubernetes\" {\n    secret_suffix = \"myteam-prod\"\n  }\n}","handlingStrategy":"validation","validationCode":"// Validate secret_suffix before applying the backend:\n// if hasNumericSuffix(suffix, \"-\") {\n//   return fmt.Errorf(\"secret_suffix must not end with '-<number>', got %q\", suffix)\n// }","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Choose alphabetic suffixes; never end secret_suffix in '-<number>'.","When migrating workspaces, rename to non-numeric suffixes.","Add this rule to your backend-config linting/review checklist."],"tags":["kubernetes-backend","validation","secret-suffix","config"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}