{"record":{"id":"777c783df43bcba2","repo":"hashicorp/terraform","slug":"listing-blobs-v","errorCode":null,"errorMessage":"listing blobs: %v","messagePattern":"listing blobs: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/azure/backend_state.go","lineNumber":41,"sourceCode":"\t// reduce the chance of name conflicts with existing objects.\n\tkeyEnvPrefix = \"env:\"\n)\n\nfunc (b *Backend) Workspaces() ([]string, tfdiags.Diagnostics) {\n\tvar diags tfdiags.Diagnostics\n\tprefix := b.keyName + keyEnvPrefix\n\tparams := containers.ListBlobsInput{\n\t\tPrefix: &prefix,\n\t}\n\n\tctx := newCtx()\n\tclient, err := b.apiClient.getContainersClient(ctx)\n\tif err != nil {\n\t\treturn nil, diags.Append(fmt.Errorf(\"retrieving container client: %v\", err))\n\t}\n\tresp, err := client.ListBlobs(ctx, b.containerName, params)\n\tif err != nil {\n\t\treturn nil, diags.Append(fmt.Errorf(\"listing blobs: %v\", err))\n\t}\n\n\tenvs := map[string]struct{}{}\n\tfor _, obj := range resp.Blobs.Blobs {\n\t\tkey := obj.Name\n\t\tif strings.HasPrefix(key, prefix) {\n\t\t\tname := strings.TrimPrefix(key, prefix)\n\t\t\t// we store the state in a key, not a directory\n\t\t\tif strings.Contains(name, \"/\") {\n\t\t\t\tcontinue\n\t\t\t}\n\n\t\t\tenvs[name] = struct{}{}\n\t\t}\n\t}\n\n\tresult := []string{backend.DefaultStateName}\n\tfor name := range envs {","sourceCodeStart":23,"sourceCodeEnd":59,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/azure/backend_state.go#L23-L59","documentation":"Thrown by Workspaces() when client.ListBlobs(ctx, containerName, params) fails after the container client was successfully built. ListBlobs calls the Azure Blob REST List operation against the container to enumerate state files under the env: prefix. Fails on auth, container-not-found, network/firewall, or RBAC.","triggerScenarios":"(a) container_name does not exist in the storage account. (b) Identity can authenticate but cannot list blobs (data-plane RBAC missing). (c) Storage account firewall / private endpoint blocks the request. (d) Container was deleted.","commonSituations":"Typo in container_name; storage account network firewall set to deny without your IP allowed; principal has Storage Account Contributor (control plane) but not Storage Blob Data Reader (data plane) when using AAD; container deleted out-of-band.","solutions":["Verify container_name with `az storage container list --account-name <acct>`.","With use_azuread_auth, grant Storage Blob Data Reader (list) / Data Contributor (read-write) to the identity.","Check storage account Networking: allow your client IP or set AzureServices bypass.","Reproduce with `az storage blob list -c <container> --account-name <acct> --auth-mode login` to isolate Terraform vs Azure.","Confirm the container was not deleted; recreate if needed."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Pre-flight: confirm the container exists and the identity can list blobs.\nfunc canListBlobs(ctx context.Context, acct, container string) error {\n    cmd := exec.CommandContext(ctx, \"az\", \"storage\", \"blob\", \"list\",\n        \"--account-name\", acct, \"-c\", container, \"--auth-mode\", \"login\", \"--query\", \"[0].name\", \"-o\", \"tsv\")\n    out, err := cmd.CombinedOutput()\n    if err != nil { return fmt.Errorf(\"cannot list blobs in %s/%s: %w (%s)\", acct, container, err, out) }\n    return nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["With AAD, grant Storage Blob Data Reader (list) / Data Contributor (read-write).","Allow your client IP in the storage account firewall or enable AzureServices bypass.","Smoke-test `az storage blob list` from the same identity before terraform workspace list.","Use a config-lint rule to flag container names that don't match ^[a-z0-9]([a-z0-9-]{1,61}[a-z0-9])?$."],"tags":["azure","blob","container","rbac","network","data-plane"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}