{"record":{"id":"70daa666867a5b53","repo":"hashicorp/terraform","slug":"failed-to-create-tag-s-s-s","errorCode":null,"errorMessage":"failed to create tag: %s -> %s: %s","messagePattern":"failed to create tag: (.+?) -> (.+?): (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/cos/client.go","lineNumber":431,"sourceCode":"\n\ttagKey := response.Response.Tags[0].TagKey\n\ttagValue := response.Response.Tags[0].TagValue\n\n\texists = key == *tagKey && value == *tagValue\n\n\treturn\n}\n\n// CreateTag create tag by key and value\nfunc (c *remoteClient) CreateTag(key, value string) error {\n\trequest := tag.NewCreateTagRequest()\n\trequest.TagKey = &key\n\trequest.TagValue = &value\n\n\t_, err := c.tagClient.CreateTag(request)\n\tlog.Printf(\"[DEBUG] create tag %s:%s: error: %v\", key, value, err)\n\tif err != nil {\n\t\treturn fmt.Errorf(\"failed to create tag: %s -> %s: %s\", key, value, err)\n\t}\n\n\treturn nil\n}\n\n// DeleteTag create tag by key and value\nfunc (c *remoteClient) DeleteTag(key, value string) error {\n\trequest := tag.NewDeleteTagRequest()\n\trequest.TagKey = &key\n\trequest.TagValue = &value\n\n\t_, err := c.tagClient.DeleteTag(request)\n\tlog.Printf(\"[DEBUG] delete tag %s:%s: error: %v\", key, value, err)\n\tif err != nil {\n\t\treturn fmt.Errorf(\"failed to delete tag: %s -> %s: %s\", key, value, err)\n\t}\n\n\treturn nil","sourceCodeStart":413,"sourceCodeEnd":449,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/cos/client.go#L413-L449","documentation":"Returned by CreateTag() when the Tencent Cloud Tag service (tag v20180813) rejects the CreateTag call. The COS backend uses a Tencent tag on the bucket to implement distributed state locking; creating that lock tag failed. The key, value, and the underlying API error are included.","triggerScenarios":"c.tagClient.CreateTag(request) returns a non-nil error. Causes: missing/denied `tag:CreateTag` permission, the tag key/value pair already exists (duplicate), tag quota exceeded for the account/region, or a transient Tag API failure.","commonSituations":"Sub-account used for the COS backend lacks Tag service permissions; the lock tag from a crashed previous run already exists; the account hit the Tencent Cloud tag-key/value quota; the Tag service endpoint region mismatch.","solutions":["Inspect the wrapped API error string for the Tencent error code (e.g. ResourceInUse for duplicate, AuthFailure for perms).","Grant `tag:CreateTag` (and `tag:DeleteTag`, `tag:DescribeTags`) to the principal in CAM.","If the tag already exists from a stale lock, run `terraform force-unlock <ID>` or delete the `tencentcloud-terraform-lock` tag manually, then retry.","For quota errors, remove unused tags or request a quota increase."],"exampleFix":"// before: principal lacks tag permissions, lock acquisition fails\n// after: attach CAM policy granting the Tag actions\n{\n  \"version\":\"2.0\",\n  \"statement\":[{\"effect\":\"allow\",\"action\":[\"tag:CreateTag\",\"tag:DeleteTag\",\"tag:DescribeTags\"],\"resource\":\"*\"}]\n}","handlingStrategy":"validation","validationCode":"// Before locking, confirm Tag service permissions\nfunc canCreateLockTag(ctx context.Context, tagClient *tag.Client, key, value string) error {\n    req := tag.NewCreateTagRequest()\n    k, v := key+\".probe\", value\n    req.TagKey, req.TagValue = &k, &v\n    _, err := tagClient.CreateTag(req)\n    if err != nil {\n        if strings.Contains(err.Error(), \"Unauthorized\") || strings.Contains(err.Error(), \"AuthFailure\") {\n            return fmt.Errorf(\"principal lacks tag:CreateTag: %w\", err)\n        }\n        return err\n    }\n    // clean up probe\n    del := tag.NewDeleteTagRequest(); del.TagKey, del.TagValue = &k, &v\n    tagClient.DeleteTag(del)\n    return nil\n}","typeGuard":"func isTagPermissionError(err error) bool {\n    s := err.Error()\n    return strings.Contains(s, \"AuthFailure\") || strings.Contains(s, \"UnauthorizedOperation\")\n}\nfunc isTagDuplicate(err error) bool { return strings.Contains(err.Error(), \"ResourceInUse\") || strings.Contains(err.Error(), \"already exist\") }","tryCatchPattern":"// Duplicate-tag and permission errors are not retryable; only transient 5xx is\nif isTagDuplicate(err) { return backoff.Permanent(fmt.Errorf(\"stale lock tag exists; force-unlock: %w\", err)) }\nif isTagPermissionError(err) { return backoff.Permanent(fmt.Errorf(\"grant tag:CreateTag: %w\", err)) }","preventionTips":["Grant `tag:CreateTag`, `tag:DeleteTag`, `tag:DescribeTags` to the COS backend principal.","Always release locks through Terraform; do not manually remove the lock tag mid-run.","After a crashed apply, force-unlock before the next run to clear stale lock tags.","Monitor tag quota usage for the account/region."],"tags":["terraform","cos","tencent-cloud","tag","permissions","state-lock","remote-state","go"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}