{"record":{"id":"6d5ffd8a7ac9e6db","repo":"hashicorp/terraform","slug":"can-not-get-s-from-terraform-backend-configuratio","errorCode":null,"errorMessage":"can not get %s from Terraform backend configuration","messagePattern":"can not get (.+?) from Terraform backend configuration","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/oci/auth.go","lineNumber":95,"sourceCode":"\t\tp.privateKeyPassword = privateKeyPasswordVal.AsString()\n\t}\n\n\treturn p\n}\nfunc (p ociAuthConfigProvider) AuthType() (common.AuthConfig, error) {\n\treturn common.AuthConfig{\n\t\t\tAuthType:         common.UnknownAuthenticationType,\n\t\t\tIsFromConfigFile: false,\n\t\t\tOboToken:         nil,\n\t\t},\n\t\tfmt.Errorf(\"unsupported, keep the interface\")\n}\n\nfunc (p ociAuthConfigProvider) TenancyOCID() (string, error) {\n\tif p.tenancyOcid != \"\" {\n\t\treturn p.tenancyOcid, nil\n\t}\n\treturn \"\", fmt.Errorf(\"can not get %s from Terraform backend configuration\", TenancyOcidAttrName)\n}\n\nfunc (p ociAuthConfigProvider) UserOCID() (string, error) {\n\tif p.userOcid != \"\" {\n\t\treturn p.userOcid, nil\n\t}\n\treturn \"\", fmt.Errorf(\"can not get %s from Terraform backend configuration\", UserOcidAttrName)\n}\n\nfunc (p ociAuthConfigProvider) KeyFingerprint() (string, error) {\n\tif p.fingerprint != \"\" {\n\t\treturn p.fingerprint, nil\n\t}\n\treturn \"\", fmt.Errorf(\"can not get %s from Terraform backend configuration\", FingerprintAttrName)\n}\n\nfunc (p ociAuthConfigProvider) Region() (string, error) {\n\tif p.region != \"\" {","sourceCodeStart":77,"sourceCodeEnd":113,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/oci/auth.go#L77-L113","documentation":"Thrown by the OCI auth config provider's accessor methods (TenancyOCID, UserOCID, KeyFingerprint, etc.) when the corresponding attribute was not set in the backend configuration (auth.go:91-110). The %s is the attribute name constant (e.g., 'tenancy_ocid'). These methods implement the OCI SDK's ConfigurationProvider interface and are called lazily when the SDK needs each credential piece.","triggerScenarios":"The OCI backend is configured with auth=api_key but omits one or more required attributes (tenancy_ocid, user_ocid, fingerprint, private_key/private_key_path). When the SDK requests the missing value during signing, the accessor returns this error.","commonSituations":"Switching auth mode to api_key without providing all five API-key attributes; typo in an attribute name so it is not read; relying on env vars that the backend does not consume (the OCI backend reads from its own block, not OCI_* env vars, for these fields); partial config left over from an instance-principal setup.","solutions":["Provide all required API-key attributes in the backend block: tenancy_ocid, user_ocid, fingerprint, and either private_key or private_key_path (plus private_key_password if the key is encrypted).","Match attribute names exactly to the schema (e.g., tenancy_ocid, not tenancyId).","If running on an OCI instance, use auth='instance_principal' instead of supplying API-key fields.","If using a config file profile, set auth='config_file_profile' with config_file_profile name rather than individual attributes."],"exampleFix":"// before\nterraform {\n  backend \"oci\" {\n    auth         = \"api_key\"\n    tenancy_ocid = \"ocid1.tenancy.oc1..aaa\"\n    # user_ocid, fingerprint, key missing\n  }\n}\n// after\nterraform {\n  backend \"oci\" {\n    auth                 = \"api_key\"\n    tenancy_ocid         = \"ocid1.tenancy.oc1..aaa\"\n    user_ocid            = \"ocid1.user.oc1..aaa\"\n    fingerprint          = \"aa:bb:cc:...\"\n    private_key_path     = \"/path/to/key.pem\"\n    private_key_password = \"passphrase\"\n  }\n}","handlingStrategy":"validation","validationCode":"// Validate all required API-key attributes are set before init:\n// required := []string{tenancyOcid, userOcid, fingerprint, privateKeyOrPath}\n// for _, v := range required { if v == \"\" { return fmt.Errorf(\"missing OCI backend attr\") } }","typeGuard":null,"tryCatchPattern":"// _, err := provider.TenancyOCID()\n// if err != nil && strings.Contains(err.Error(), \"can not get\") {\n//   // missing attribute; surface which one and add to backend block\n// }","preventionTips":["When auth=api_key, always set tenancy_ocid, user_ocid, fingerprint, and a private key (path or value).","Use auth=instance_principal on OCI compute instances to avoid API-key sprawl.","Use auth=config_file_profile to reference an existing OCI config profile instead of repeating attributes."],"tags":["oci-backend","auth","credentials","config"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}