{"record":{"id":"8c3320675d8c03b5","repo":"hashicorp/terraform","slug":"failed-to-append-certs","errorCode":null,"errorMessage":"failed to append certs","messagePattern":"failed to append certs","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/http/backend.go","lineNumber":294,"sourceCode":"\t\treturn fmt.Errorf(\"client_certificate_pem is set but client_private_key_pem is not\")\n\t}\n\tif clientPrivateKeyPem != \"\" && clientCertificatePem == \"\" {\n\t\treturn fmt.Errorf(\"client_private_key_pem is set but client_certificate_pem is not\")\n\t}\n\n\t// TLS configuration is needed; create an object and configure it\n\tvar tlsConfig tls.Config\n\tclient.HTTPClient.Transport.(*http.Transport).TLSClientConfig = &tlsConfig\n\n\tif skipCertVerification {\n\t\t// ignores TLS verification\n\t\ttlsConfig.InsecureSkipVerify = true\n\t}\n\tif clientCACertificatePem != \"\" {\n\t\t// trust servers based on a CA\n\t\ttlsConfig.RootCAs = x509.NewCertPool()\n\t\tif !tlsConfig.RootCAs.AppendCertsFromPEM([]byte(clientCACertificatePem)) {\n\t\t\treturn errors.New(\"failed to append certs\")\n\t\t}\n\t}\n\tif clientCertificatePem != \"\" && clientPrivateKeyPem != \"\" {\n\t\t// attach a client certificate to the TLS handshake (aka mTLS)\n\t\tcertificate, err := tls.X509KeyPair([]byte(clientCertificatePem), []byte(clientPrivateKeyPem))\n\t\tif err != nil {\n\t\t\treturn fmt.Errorf(\"cannot load client certificate: %w\", err)\n\t\t}\n\t\ttlsConfig.Certificates = []tls.Certificate{certificate}\n\t}\n\n\treturn nil\n}\n\nfunc (b *Backend) StateMgr(name string) (statemgr.Full, tfdiags.Diagnostics) {\n\tvar diags tfdiags.Diagnostics\n\n\tif name != backend.DefaultStateName {","sourceCodeStart":276,"sourceCodeEnd":312,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/http/backend.go#L276-L312","documentation":"In NestingList or NestingSet mode, if MaxItems is set (non-zero, meaning a hard upper bound) then MinItems must not exceed it. A floor above the ceiling is an impossible constraint. When MaxItems is 0 it means unbounded, so the check is skipped.","triggerScenarios":"NestingList/NestingSet with MinItems: 5, MaxItems: 3. Guard at internal_validate.go:89 is `blockS.MinItems > blockS.MaxItems && blockS.MaxItems != 0`.","commonSituations":"Swapping min/max values when authoring the schema; computing limits from config where the floor overruns the cap; copy-paste from another block with different bounds.","solutions":["Ensure MinItems <= MaxItems when MaxItems != 0.","Set MaxItems: 0 if you want no upper limit.","Lower MinItems or raise MaxItems so the range is satisfiable."],"exampleFix":"// before\n\"items\": { Nesting: configschema.NestingList, MinItems: 5, MaxItems: 3 },\n// after\n\"items\": { Nesting: configschema.NestingList, MinItems: 3, MaxItems: 5 },","handlingStrategy":"validation","validationCode":"// In NestingList/NestingSet, MinItems must not exceed MaxItems (when MaxItems != 0).\nfunc validRange(nb *configschema.NestedBlock) bool {\n    switch nb.Nesting {\n    case configschema.NestingList, configschema.NestingSet:\n        return nb.MaxItems == 0 || nb.MinItems <= nb.MaxItems\n    }\n    return true\n}","typeGuard":"func minLteMax(min, max int) bool { return max == 0 || min <= max }","tryCatchPattern":null,"preventionTips":["Always order limits as MinItems <= MaxItems in schema literals.","Set MaxItems: 0 for unbounded rather than a large number.","Add a lint check in schema-builder code."],"tags":["schema-validation","configschema","nestinglist","nestingset","minitems","maxitems","provider-schema"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}