{"record":{"id":"8999da81782ae895","repo":"hashicorp/terraform","slug":"action-s-has-ephemeral-config-values-which-are-n","errorCode":null,"errorMessage":"action %s has ephemeral config values, which are not supported in action invocations","messagePattern":"action (.+?) has ephemeral config values, which are not supported in action invocations","errorType":"console","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/command/jsonplan/action_invocations.go","lineNumber":162,"sourceCode":"\tcase *plans.InvokeActionTrigger:\n\t\tai.InvokeActionTrigger = &InvokeActionTrigger{}\n\t\tif at.CallingResourceAddr != nil {\n\t\t\tai.InvokeActionTrigger.CallingResourceAddress = at.CallingResourceAddr.String()\n\t\t}\n\tdefault:\n\t\treturn ai, fmt.Errorf(\"unsupported action trigger type: %T\", at)\n\t}\n\n\tvar config []byte\n\tvar sensitive []byte\n\tvar unknown []byte\n\n\tif actionDec.ConfigValue != cty.NilVal {\n\t\tunmarkedValue, pvms := actionDec.ConfigValue.UnmarkDeepWithPaths()\n\t\tsensitivePaths, otherMarks := marks.PathsWithMark(pvms, marks.Sensitive)\n\t\tephemeralPaths, otherMarks := marks.PathsWithMark(otherMarks, marks.Ephemeral)\n\t\tif len(ephemeralPaths) > 0 {\n\t\t\treturn ai, fmt.Errorf(\"action %s has ephemeral config values, which are not supported in action invocations\", action.Addr)\n\t\t}\n\t\tif len(otherMarks) > 0 {\n\t\t\treturn ai, fmt.Errorf(\"action %s has config values with unsupported marks: %v\", action.Addr, otherMarks)\n\t\t}\n\n\t\tunknownValue := unknownAsBool(unmarkedValue)\n\t\tunknown, err = ctyjson.Marshal(unknownValue, unknownValue.Type())\n\t\tif err != nil {\n\t\t\treturn ai, err\n\t\t}\n\n\t\tconfigValue := omitUnknowns(unmarkedValue)\n\t\tconfig, err = ctyjson.Marshal(configValue, configValue.Type())\n\t\tif err != nil {\n\t\t\treturn ai, err\n\t\t}\n\n\t\tsensitivePaths = append(sensitivePaths, schema.ConfigSchema.SensitivePaths(unmarkedValue, nil)...)","sourceCodeStart":144,"sourceCodeEnd":180,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/command/jsonplan/action_invocations.go#L144-L180","documentation":"Action invocation config contains ephemeral marks. Ephemeral values are intentionally non-serializable, so the plan JSON renderer refuses to embed them in an action invocation's config.","triggerScenarios":"An action block references an ephemeral variable/resource output or a value derived from one; ephemeral marks propagated through expressions into the action config.","commonSituations":"Using ephemeral values (write-only secrets, ephemeral resources) inside an action invocation, which the current plan-renderer does not support.","solutions":["Remove ephemeral inputs from the action invocation config; pass non-ephemeral values instead.","Wait for / upgrade to a Terraform version that supports ephemeral config in action invocations.","If marks are unexpected, trace where the ephemeral mark was applied — it may indicate an upstream bug."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Check an action config value for ephemeral marks before marshaling.\nfunc hasEphemeral(v cty.Value) bool {\n    _, pms := v.UnmarkDeepWithPaths()\n    _, _ = marks.PathsWithMark(pms, marks.Sensitive)\n    ephemeral, _ := marks.PathsWithMark(pms, marks.Ephemeral) // simplified\n    return len(ephemeral) > 0\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Avoid routing ephemeral values (write-only secrets, ephemeral resources) into action invocation config.","Track ephemeral propagation in expressions during config authoring."],"tags":["go","terraform","plan","actions","ephemeral","marks","jsonplan"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}