{"record":{"id":"7397cc94ccdb7ff3","repo":"hashicorp/terraform","slug":"s-soft-failed-s","errorCode":null,"errorMessage":"%s soft failed.\n%s","messagePattern":"(.+?) soft failed\\.\n(.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote/backend_common.go","lineNumber":451,"sourceCode":"\t\t\t}\n\t\t}\n\n\t\tswitch pc.Status {\n\t\tcase tfe.PolicyPasses:\n\t\t\tif (r.HasChanges && op.Type == backendrun.OperationTypeApply || i < len(r.PolicyChecks)-1) && b.CLI != nil {\n\t\t\t\tb.CLI.Output(\"\\n------------------------------------------------------------------------\")\n\t\t\t}\n\t\t\tcontinue\n\t\tcase tfe.PolicyErrored:\n\t\t\treturn fmt.Errorf(\"%s errored.\", msgPrefix)\n\t\tcase tfe.PolicyHardFailed:\n\t\t\treturn fmt.Errorf(\"%s hard failed.\", msgPrefix)\n\t\tcase tfe.PolicySoftFailed:\n\t\t\trunURL := fmt.Sprintf(runHeaderErr, b.hostname, b.organization, op.Workspace, r.ID)\n\n\t\t\tif op.Type == backendrun.OperationTypePlan || op.UIOut == nil || op.UIIn == nil ||\n\t\t\t\t!pc.Actions.IsOverridable || !pc.Permissions.CanOverride {\n\t\t\t\treturn fmt.Errorf(\"%s soft failed.\\n%s\", msgPrefix, runURL)\n\t\t\t}\n\n\t\t\tif op.AutoApprove {\n\t\t\t\tif _, err = b.client.PolicyChecks.Override(stopCtx, pc.ID); err != nil {\n\t\t\t\t\treturn generalError(fmt.Sprintf(\"Failed to override policy check.\\n%s\", runURL), err)\n\t\t\t\t}\n\t\t\t} else {\n\t\t\t\topts := &terraform.InputOpts{\n\t\t\t\t\tId:          \"override\",\n\t\t\t\t\tQuery:       \"\\nDo you want to override the soft failed policy check?\",\n\t\t\t\t\tDescription: \"Only 'override' will be accepted to override.\",\n\t\t\t\t}\n\t\t\t\terr = b.confirm(stopCtx, op, opts, r, \"override\")\n\t\t\t\tif err != nil && err != errRunOverridden {\n\t\t\t\t\treturn fmt.Errorf(\"Failed to override: %w\\n%s\\n\", err, runURL)\n\t\t\t\t}\n\n\t\t\t\tif err != errRunOverridden {","sourceCodeStart":433,"sourceCodeEnd":469,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote/backend_common.go#L433-L469","documentation":"Returned for a soft-failed policy check (tfe.PolicySoftFailed) when interactive override is not possible. The conditions are: the operation is a plan, OR no UI input/output is available, OR the policy is not overridable, OR the token lacks CanOverride permission. The message appends the run URL for manual action.","triggerScenarios":"pc.Status == tfe.PolicySoftFailed AND (op.Type == plan OR op.UIOut/UIIn == nil OR !pc.Actions.IsOverridable OR !pc.Permissions.CanOverride). The soft-mandatory policy failed but the current context cannot prompt or is not authorized to override.","commonSituations":"CI/automated run with no TTY where a soft policy fails; plan-stage policy check (override is only offered at apply); token's team lacks 'Override Soft Failed Policies' permission; policy set marked non-overridable.","solutions":["Fix the configuration to comply with the policy rather than overriding.","If override is legitimate, grant the token's team 'Override Soft Failed Policies' permission and run interactively at apply time.","Override the run manually via the run URL shown in the error (TFC UI or API).","Adjust the policy enforcement from soft-mandatory to advisory if the violation is acceptable by design."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Ensure override capability before relying on interactive override at apply time.\nfunc canOverride(pc *tfe.PolicyCheck, op *backendrun.Operation) bool {\n    return op.Type != backendrun.OperationTypePlan &&\n        op.UIOut != nil && op.UIIn != nil &&\n        pc.Actions.IsOverridable && pc.Permissions.CanOverride\n}","typeGuard":null,"tryCatchPattern":"// When soft-fail is expected in CI, pre-check override permission and fail with guidance.\nif pc.Status == tfe.PolicySoftFailed && !canOverride(pc, op) {\n    return fmt.Errorf(\"soft policy failed and override unavailable; fix config or grant override permission\")\n}","preventionTips":["If CI must override, grant the service token's team 'Override Soft Failed Policies' and use -auto-approve at apply.","Prefer fixing configs over overriding; reserve override for break-glass scenarios.","Run policy checks early (plan stage) so soft failures surface before apply-time pressure."],"tags":["backend","remote-backend","policy","sentinel","soft-fail","override","permissions","go"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}