{"record":{"id":"83f146b3a6f5692d","repo":"hashicorp/terraform","slug":"can-t-locate-credentials-file-s","errorCode":null,"errorMessage":"can't locate credentials file: %s","messagePattern":"can't locate credentials file: (.+?)","errorType":"console","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/command/cliconfig/credentials.go","lineNumber":45,"sourceCode":"// that the credentials source will use when asked to save or forget credentials\n// and when a \"credentials helper\" program is not active.\nfunc CredentialsConfigFile() (string, error) {\n\tconfigDir, err := ConfigDir()\n\tif err != nil {\n\t\treturn \"\", err\n\t}\n\treturn filepath.Join(configDir, \"credentials.tfrc.json\"), nil\n}\n\n// CredentialsSource creates and returns a service credentials source whose\n// behavior depends on which \"credentials\" and \"credentials_helper\" blocks,\n// if any, are present in the receiving config.\nfunc (c *Config) CredentialsSource(helperPlugins pluginDiscovery.PluginMetaSet) (*CredentialsSource, error) {\n\tcredentialsFilePath, err := CredentialsConfigFile()\n\tif err != nil {\n\t\t// If we managed to load a Config object at all then we would already\n\t\t// have located this file, so this error is very unlikely.\n\t\treturn nil, fmt.Errorf(\"can't locate credentials file: %s\", err)\n\t}\n\n\tvar helper svcauth.CredentialsSource\n\tvar helperType string\n\tfor givenType, givenConfig := range c.CredentialsHelpers {\n\t\tavailable := helperPlugins.WithName(givenType)\n\t\tif available.Count() == 0 {\n\t\t\tlog.Printf(\"[ERROR] Unable to find credentials helper %q; ignoring\", givenType)\n\t\t\tbreak\n\t\t}\n\n\t\tselected := available.Newest()\n\n\t\thelperSource := svcauth.HelperProgramCredentialsSource(selected.Path, givenConfig.Args...)\n\t\thelper = svcauth.CachingCredentialsSource(helperSource) // cached because external operation may be slow/expensive\n\t\thelperType = givenType\n\n\t\t// There should only be zero or one \"credentials_helper\" blocks. We","sourceCodeStart":27,"sourceCodeEnd":63,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/command/cliconfig/credentials.go#L27-L63","documentation":"Thrown when CredentialsConfigFile() fails to determine the path to the credentials file, and this error propagates when building the credentials source in CredentialsSource(). CredentialsConfigFile() internally calls ConfigDir() which resolves the user's config/home directory; if that fails, the credentials file path cannot be constructed. The source comment notes this is very unlikely since a Config object was already loaded.","triggerScenarios":"CredentialsConfigFile() returns an error because ConfigDir() cannot resolve the user's home or config directory. This propagates from CredentialsSource() which needs the credentials file path to set up local credential storage.","commonSituations":"HOME or USERPROFILE environment variable not set (common in containers, systemd services, or CI runners without proper env); running Terraform as a service account without a home directory; exotic platform without standard home directory resolution.","solutions":["Set the HOME environment variable: export HOME=/home/user","Use TF_CLI_CONFIG_FILE to specify an explicit config file path","For containers, ensure the user has a home directory set: docker run -e HOME=/root ...","Set up credentials via terraform login after fixing the HOME environment"],"exampleFix":"# before (container without HOME)\ndocker run hashicorp/terraform plan\n\n# after\ndocker run -e HOME=/root hashicorp/terraform plan","handlingStrategy":"try-catch","validationCode":"// Verify HOME is resolvable before running terraform\nfunc checkHomeEnv() error {\n    home, err := os.UserHomeDir()\n    if err != nil {\n        return fmt.Errorf(\"cannot determine home directory: %w\", err)\n    }\n    if home == \"\" {\n        return errors.New(\"HOME is not set; cannot locate credentials file\")\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Ensure HOME is set in all environments (containers, CI, systemd services)","Use TF_CLI_CONFIG_FILE to bypass home directory resolution for config path","Set up credentials via terraform login after fixing the environment","Document HOME as a required environment variable in deployment runbooks"],"tags":["cli-config","credentials","home-directory","environment"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}