{"record":{"id":"8f0365a2372634be","repo":"hashicorp/terraform","slug":"default-state-is-not-allowed-to-be-deleted","errorCode":null,"errorMessage":"default state is not allowed to be deleted","messagePattern":"default state is not allowed to be deleted","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/cos/backend_state.go","lineNumber":71,"sourceCode":"\t\tparts := strings.Split(strings.TrimPrefix(vv.Key, prefix), \"/\")\n\t\tif len(parts) > 0 && parts[0] != \"\" {\n\t\t\tws = append(ws, parts[0])\n\t\t}\n\t}\n\n\tsort.Strings(ws[1:])\n\tlog.Printf(\"[DEBUG] list all workspaces, workspaces: %v\", ws)\n\n\treturn ws, diags\n}\n\n// DeleteWorkspace deletes the named workspaces. The \"default\" state cannot be deleted.\nfunc (b *Backend) DeleteWorkspace(name string, _ bool) tfdiags.Diagnostics {\n\tvar diags tfdiags.Diagnostics\n\tlog.Printf(\"[DEBUG] delete workspace, workspace: %v\", name)\n\n\tif name == backend.DefaultStateName || name == \"\" {\n\t\treturn tfdiags.Diagnostics{}.Append(fmt.Errorf(\"default state is not allowed to be deleted\"))\n\t}\n\n\tc, err := b.client(name)\n\tif err != nil {\n\t\treturn diags.Append(err)\n\t}\n\n\treturn diags.Append(c.Delete())\n}\n\n// StateMgr manage the state, if the named state not exists, a new file will created\nfunc (b *Backend) StateMgr(name string) (statemgr.Full, tfdiags.Diagnostics) {\n\tvar diags tfdiags.Diagnostics\n\tlog.Printf(\"[DEBUG] state manager, current workspace: %v\", name)\n\n\tc, err := b.client(name)\n\tif err != nil {\n\t\treturn nil, diags.Append(err)","sourceCodeStart":53,"sourceCodeEnd":89,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/cos/backend_state.go#L53-L89","documentation":"Backend.DeleteWorkspace refuses to delete the workspace whose name is backend.DefaultStateName ('default') or empty. The default workspace is the root state of the backend and cannot be removed through the workspace API.","triggerScenarios":"terraform workspace delete default, or the backend's DeleteWorkspace called with name == \"default\" or \"\".","commonSituations":"Automation/CI tries to wipe all workspaces including default; a cleanup script enumerates workspaces and deletes each without skipping default.","solutions":["Do not delete the default workspace. Run terraform destroy first if you want to remove resources.","If you truly want to remove the state object, manually delete it from the COS bucket at the default stateFile path after destroying.","Update cleanup scripts to skip name == 'default'."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Reject attempts to delete the default workspace before calling DeleteWorkspace.\nfunc safeDeleteWorkspace(b *Backend, name string) tfdiags.Diagnostics {\n    if name == backend.DefaultStateName || strings.TrimSpace(name) == \"\" {\n        var d tfdiags.Diagnostics\n        return d.Append(fmt.Errorf(\"default state is not allowed to be deleted\"))\n    }\n    return b.DeleteWorkspace(name, false)\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Skip name == 'default' in workspace cleanup automation.","Run terraform destroy before any manual state removal.","Document that the default workspace is immutable for delete.","Audit CI scripts that enumerate and delete workspaces."],"tags":["cos","tencent-cloud","workspace","backend"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}