{"record":{"id":"71f373a0e037482a","repo":"hashicorp/terraform","slug":"q-must-be-a-valid-acl-value-expected-s-s-or","errorCode":null,"errorMessage":"%q must be a valid ACL value , expected %s, %s or %s, got %q","messagePattern":"%q must be a valid ACL value , expected (.+?), (.+?) or (.+?), got %q","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/oss/backend.go","lineNumber":209,"sourceCode":"\t\t\t},\n\n\t\t\t\"encrypt\": {\n\t\t\t\tType:        schema.TypeBool,\n\t\t\t\tOptional:    true,\n\t\t\t\tDescription: \"Whether to enable server side encryption of the state file\",\n\t\t\t\tDefault:     false,\n\t\t\t},\n\n\t\t\t\"acl\": {\n\t\t\t\tType:        schema.TypeString,\n\t\t\t\tOptional:    true,\n\t\t\t\tDescription: \"Object ACL to be applied to the state file\",\n\t\t\t\tDefault:     \"\",\n\t\t\t\tValidateFunc: func(v interface{}, k string) ([]string, []error) {\n\t\t\t\t\tif value := v.(string); value != \"\" {\n\t\t\t\t\t\tacls := oss.ACLType(value)\n\t\t\t\t\t\tif acls != oss.ACLPrivate && acls != oss.ACLPublicRead && acls != oss.ACLPublicReadWrite {\n\t\t\t\t\t\t\treturn nil, []error{fmt.Errorf(\n\t\t\t\t\t\t\t\t\"%q must be a valid ACL value , expected %s, %s or %s, got %q\",\n\t\t\t\t\t\t\t\tk, oss.ACLPrivate, oss.ACLPublicRead, oss.ACLPublicReadWrite, acls)}\n\t\t\t\t\t\t}\n\t\t\t\t\t}\n\t\t\t\t\treturn nil, nil\n\t\t\t\t},\n\t\t\t},\n\t\t\t\"shared_credentials_file\": {\n\t\t\t\tType:        schema.TypeString,\n\t\t\t\tOptional:    true,\n\t\t\t\tDefaultFunc: schema.MultiEnvDefaultFunc([]string{\"ALICLOUD_SHARED_CREDENTIALS_FILE\", \"ALIBABA_CLOUD_CREDENTIALS_FILE\"}, \"\"),\n\t\t\t\tDescription: \"This is the path to the shared credentials file. If this is not set and a profile is specified, `~/.aliyun/config.json` will be used.\",\n\t\t\t},\n\t\t\t\"profile\": {\n\t\t\t\tType:        schema.TypeString,\n\t\t\t\tOptional:    true,\n\t\t\t\tDescription: \"This is the Alibaba Cloud profile name as set in the shared credentials file. It can also be sourced from the `ALICLOUD_PROFILE` environment variable.\",\n\t\t\t\tDefaultFunc: schema.MultiEnvDefaultFunc([]string{\"ALICLOUD_PROFILE\", \"ALIBABA_CLOUD_PROFILE\"}, \"\"),","sourceCodeStart":191,"sourceCodeEnd":227,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/oss/backend.go#L191-L227","documentation":"Thrown by the ValidateFunc for the 'acl' field in the OSS backend when the provided ACL string is not one of the three valid values: oss.ACLPrivate, oss.ACLPublicRead, or oss.ACLPublicReadWrite. The error interpolates the valid values and the invalid value received.","triggerScenarios":"ValidateFunc checks if value is non-empty, casts to oss.ACLType, and compares against the three valid constants. Fails when the user provides an unrecognized string like 'public', 'read-only', 'bucket-owner-read', or an AWS-style ACL like 'bucket-owner-full-control'.","commonSituations":"Developer uses an AWS S3 ACL name ('public-read-write' with different casing, or 'authenticated-read'). Developer uses a vague value like 'public' instead of 'public-read'. Copy-paste from S3 backend where ACL vocabulary differs. Case sensitivity issues ('Private' vs 'private').","solutions":["Use one of the exact constant string values: oss.ACLPrivate, oss.ACLPublicRead, or oss.ACLPublicReadWrite.","Leave the acl field empty (default is empty string, which skips the check) if you want bucket-default ACL.","Check the aliyun-oss-go-sdk source or docs for the exact string values of these constants."],"exampleFix":"// before (invalid ACL name)\nterraform {\n  backend \"oss\" {\n    acl = \"authenticated-read\"\n  }\n}\n// after\nterraform {\n  backend \"oss\" {\n    acl = \"private\"\n  }\n}","handlingStrategy":"validation","validationCode":"// Validate OSS ACL value before Terraform init\nfunc validateOSSACL(acl string) error {\n    if acl == \"\" {\n        return nil // empty is allowed, uses bucket default\n    }\n    validACLs := map[string]bool{\n        \"private\":            true,\n        \"public-read\":        true,\n        \"public-read-write\":  true,\n    }\n    if !validACLs[acl] {\n        return fmt.Errorf(\"invalid ACL %q; must be one of: private, public-read, public-read-write\", acl)\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Use lowercase ACL values exactly as defined by OSS: 'private', 'public-read', 'public-read-write'.","Leave the acl field empty to inherit the bucket's default ACL.","Do not use AWS S3 ACL names like 'authenticated-read' or 'bucket-owner-read'."],"tags":["oss","validation","acl","permissions"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}