{"record":{"id":"8eb555a29f461e66","repo":"hashicorp/terraform","slug":"can-t-delete-default-state-8eb555","errorCode":null,"errorMessage":"can't delete default state","messagePattern":"can't delete default state","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/kubernetes/backend_state.go","lineNumber":73,"sourceCode":"\t\t// Make sure it isn't default and the key matches\n\t\tif ws != backend.DefaultStateName && key == b.nameSuffix {\n\t\t\tm[ws] = struct{}{}\n\t\t}\n\t}\n\n\tstates := []string{backend.DefaultStateName}\n\tfor k := range m {\n\t\tstates = append(states, k)\n\t}\n\n\tsort.Strings(states[1:])\n\treturn states, diags\n}\n\nfunc (b *Backend) DeleteWorkspace(name string, _ bool) tfdiags.Diagnostics {\n\tvar diags tfdiags.Diagnostics\n\tif name == backend.DefaultStateName || name == \"\" {\n\t\treturn diags.Append(fmt.Errorf(\"can't delete default state\"))\n\t}\n\n\tclient, err := b.remoteClient(name)\n\tif err != nil {\n\t\treturn diags.Append(err)\n\t}\n\n\treturn diags.Append(client.Delete())\n}\n\nfunc (b *Backend) StateMgr(name string) (statemgr.Full, tfdiags.Diagnostics) {\n\tvar diags tfdiags.Diagnostics\n\n\tc, err := b.remoteClient(name)\n\tif err != nil {\n\t\treturn nil, diags.Append(err)\n\t}\n","sourceCodeStart":55,"sourceCodeEnd":91,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/kubernetes/backend_state.go#L55-L91","documentation":"Same protection as the inmem backend, but for the Kubernetes backend: DeleteWorkspace rejects name == backend.DefaultStateName (\"default\") or empty (backend_state.go:71-75). The default workspace's state Secret/Lease must not be deleted via workspace deletion.","triggerScenarios":"Running 'terraform workspace delete default' against a kubernetes backend, or a workspace-management script that attempts to delete the default workspace.","commonSituations":"Bulk workspace cleanup scripts; CI that deletes all workspaces at end of run; migrating away from the backend by deleting workspaces one by one and hitting 'default'.","solutions":["Skip the default workspace in any deletion loop.","To remove backend state entirely, delete the Kubernetes Secrets/Leases manually (kubectl delete secret -l tfstate/terraform=true) after switching the backend.","Switch to another workspace before operating on workspace lifecycle."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Guard workspace deletion for the k8s backend too:\n// if name == backend.DefaultStateName || name == \"\" { return nil }\n// b.DeleteWorkspace(name, force)","typeGuard":null,"tryCatchPattern":"// diags := b.DeleteWorkspace(name, force)\n// for _, d := range diags {\n//   if strings.Contains(d.Description().Summary, \"can't delete default state\") { /* skip */ }\n// }","preventionTips":["Exclude 'default' from any workspace-deletion automation.","To fully remove k8s backend state, delete the labeled Secrets/Leases with kubectl after switching backends.","Document that the default workspace is undeletable by design."],"tags":["kubernetes-backend","workspace","default-state"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}