{"record":{"id":"8e8be1ff7ec0d0a1","repo":"hashicorp/terraform","slug":"action-s-has-config-values-with-unsupported-marks","errorCode":null,"errorMessage":"action %s has config values with unsupported marks: %v","messagePattern":"action (.+?) has config values with unsupported marks: (.+?)","errorType":"console","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/command/jsonplan/action_invocations.go","lineNumber":165,"sourceCode":"\t\t\tai.InvokeActionTrigger.CallingResourceAddress = at.CallingResourceAddr.String()\n\t\t}\n\tdefault:\n\t\treturn ai, fmt.Errorf(\"unsupported action trigger type: %T\", at)\n\t}\n\n\tvar config []byte\n\tvar sensitive []byte\n\tvar unknown []byte\n\n\tif actionDec.ConfigValue != cty.NilVal {\n\t\tunmarkedValue, pvms := actionDec.ConfigValue.UnmarkDeepWithPaths()\n\t\tsensitivePaths, otherMarks := marks.PathsWithMark(pvms, marks.Sensitive)\n\t\tephemeralPaths, otherMarks := marks.PathsWithMark(otherMarks, marks.Ephemeral)\n\t\tif len(ephemeralPaths) > 0 {\n\t\t\treturn ai, fmt.Errorf(\"action %s has ephemeral config values, which are not supported in action invocations\", action.Addr)\n\t\t}\n\t\tif len(otherMarks) > 0 {\n\t\t\treturn ai, fmt.Errorf(\"action %s has config values with unsupported marks: %v\", action.Addr, otherMarks)\n\t\t}\n\n\t\tunknownValue := unknownAsBool(unmarkedValue)\n\t\tunknown, err = ctyjson.Marshal(unknownValue, unknownValue.Type())\n\t\tif err != nil {\n\t\t\treturn ai, err\n\t\t}\n\n\t\tconfigValue := omitUnknowns(unmarkedValue)\n\t\tconfig, err = ctyjson.Marshal(configValue, configValue.Type())\n\t\tif err != nil {\n\t\t\treturn ai, err\n\t\t}\n\n\t\tsensitivePaths = append(sensitivePaths, schema.ConfigSchema.SensitivePaths(unmarkedValue, nil)...)\n\t\tcs := jsonstate.SensitiveAsBool(marks.MarkPaths(unmarkedValue, marks.Sensitive, sensitivePaths))\n\t\tsensitive, err = ctyjson.Marshal(cs, cs.Type())\n\t\tif err != nil {","sourceCodeStart":147,"sourceCodeEnd":183,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/command/jsonplan/action_invocations.go#L147-L183","documentation":"After removing Sensitive and Ephemeral marks from the action config value, additional mark types remain. The renderer only knows how to serialize Sensitive and Ephemeral, so any other mark type is unsupported for action invocations.","triggerScenarios":"A custom or experimental mark type was applied to config values (e.g. a third-party mark, deprecated marks, or marks from a newer internal feature) that the action marshaling path cannot handle.","commonSituations":"Forked Terraform with extra mark types; future Terraform version introducing a mark not yet handled here.","solutions":["Inspect the marks listed via %v to identify which non-Sensitive/Ephemeral mark is present.","Avoid applying unsupported marks to values that flow into action invocation config.","Add handling for the mark type in MarshalActionInvocation if you control the mark definition.","Upgrade or align Terraform versions so only supported marks reach this code."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Report any mark types other than Sensitive/Ephemeral on the value.\nfunc unsupportedMarks(v cty.Value) ([]cty.PathValueMarks, error) {\n    _, pms := v.UnmarkDeepWithPaths()\n    _, rest := marks.PathsWithMark(pms, marks.Sensitive)\n    _, rest = marks.PathsWithMark(rest, marks.Ephemeral)\n    return rest, nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Do not apply non-standard marks to values flowing into action config.","In forks defining custom marks, add explicit handling here or filter marks upstream."],"tags":["go","terraform","plan","actions","marks","jsonplan"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}