{"record":{"id":"7c37c8c83d0fc61a","repo":"hashicorp/terraform","slug":"invalid-expression-for-variable-q-s","errorCode":null,"errorMessage":"invalid expression for variable %q: %s","messagePattern":"invalid expression for variable %q: (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/builtin/providers/terraform/functions.go","lineNumber":134,"sourceCode":"\t// stuff HCL diagnostics into plain string error messages. This produces\n\t// a non-ideal result but is still better than hiding the HCL-provided\n\t// diagnosis altogether.\n\tf, hclDiags := hclsyntax.ParseConfig(src, \"<decode_tfvars argument>\", hcl.InitialPos)\n\tif hclDiags.HasErrors() {\n\t\treturn cty.NilVal, fmt.Errorf(\"invalid tfvars syntax: %s\", hclDiags.Error())\n\t}\n\tattrs, hclDiags := f.Body.JustAttributes()\n\tif hclDiags.HasErrors() {\n\t\treturn cty.NilVal, fmt.Errorf(\"invalid tfvars content: %s\", hclDiags.Error())\n\t}\n\tretAttrs := make(map[string]cty.Value, len(attrs))\n\tfor name, attr := range attrs {\n\t\t// Evaluating the expression with no EvalContext achieves the same\n\t\t// interpretation as Terraform CLI makes of .tfvars files, rejecting\n\t\t// any function calls or references to symbols.\n\t\tv, hclDiags := attr.Expr.Value(nil)\n\t\tif hclDiags.HasErrors() {\n\t\t\treturn cty.NilVal, fmt.Errorf(\"invalid expression for variable %q: %s\", name, hclDiags.Error())\n\t\t}\n\t\tretAttrs[name] = v\n\t}\n\n\treturn cty.ObjectVal(retAttrs), nil\n}\n\nfunc encodeExprFunc(args []cty.Value) (cty.Value, error) {\n\t// These error checks should not be hit in practice because the language\n\t// runtime should check them before calling, so this is just for robustness\n\t// and completeness.\n\tif len(args) > 1 {\n\t\treturn cty.NilVal, function.NewArgErrorf(1, \"too many arguments; only one expected\")\n\t}\n\tif len(args) == 0 {\n\t\treturn cty.NilVal, fmt.Errorf(\"exactly one argument is required\")\n\t}\n","sourceCodeStart":116,"sourceCodeEnd":152,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/builtin/providers/terraform/functions.go#L116-L152","documentation":"After extracting attributes, decode_tfvars evaluates each value expression with a nil EvalContext, matching Terraform CLI's .tfvars semantics which reject function calls and references to symbols. If an individual value expression references a symbol or invokes a function, this error names the offending variable.","triggerScenarios":"decode_tfvars(\"a = somefunc()\") with a function call in a value; decode_tfvars(\"a = var.other\") with a reference; decode_tfvars(\"a = local.x\") referencing a local.","commonSituations":"Building a tfvars string dynamically that accidentally interpolates references; assuming tfvars values can reference other variables or call functions (they cannot); migrating a config snippet into a tfvars string without stripping references.","solutions":["Use only literal values in the tfvars string (numbers, strings, lists, objects) — no references and no function calls","Compute derived values in Terraform first, then pass the literal result into the string","If references are required, switch from a tfvars string to a proper module input or a different encoding"],"exampleFix":"// before\ndecode_tfvars(\"a = upper(\\\"x\\\")\")\n// after\ndecode_tfvars(\"a = \\\"X\\\"\")","handlingStrategy":"validation","validationCode":"// Evaluate each attribute expression with a nil EvalContext to surface reference/call errors early.\n// In Go (mirrors decode_tfvars semantics):\nattrs, _ := f.Body.JustAttributes()\nfor name, attr := range attrs {\n    if _, diags := attr.Expr.Value(nil); diags.HasErrors() {\n        // variable 'name' contains an illegal reference or call; report it\n    }\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Treat tfvars values as literals only — no var., local., or function calls","Pre-compute any derived value in Terraform and inline the literal result","When generating tfvars strings from templates, scan for ${...} or unquoted references before use"],"tags":["terraform","hcl","decode-tfvars","expression","user-input"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}