{"record":{"id":"9213e71ae39339f2","repo":"hashicorp/terraform","slug":"could-not-read-state-version-output-s-w","errorCode":null,"errorMessage":"could not read state version output %s: %w","messagePattern":"could not read state version output (.+?): %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/cloud/state.go","lineNumber":605,"sourceCode":"\t\t\t}\n\n\t\t\tstate := s.State()\n\t\t\tif state == nil {\n\t\t\t\t// We know that there is supposed to be state (and this is not simply a new workspace\n\t\t\t\t// without state) because the fallback is only invoked when outputs are present but\n\t\t\t\t// detailed types are not available.\n\t\t\t\treturn nil, ErrStateVersionUnauthorizedUpgradeState\n\t\t\t}\n\n\t\t\treturn state.RootOutputValues, nil\n\t\t}\n\n\t\tif output.Sensitive {\n\t\t\t// Since this is a sensitive value, the output must be requested explicitly in order to\n\t\t\t// read its value, which is assumed to be present by callers\n\t\t\tsensitiveOutput, err := s.tfeClient.StateVersionOutputs.Read(ctx, output.ID)\n\t\t\tif err != nil {\n\t\t\t\treturn nil, fmt.Errorf(\"could not read state version output %s: %w\", output.ID, err)\n\t\t\t}\n\t\t\toutput.Value = sensitiveOutput.Value\n\t\t}\n\n\t\tcval, err := tfeOutputToCtyValue(*output)\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"could not decode output %s (ID %s)\", output.Name, output.ID)\n\t\t}\n\n\t\tresult[output.Name] = &states.OutputValue{\n\t\t\tValue:     cval,\n\t\t\tSensitive: output.Sensitive,\n\t\t}\n\t}\n\n\treturn result, nil\n}\n","sourceCodeStart":587,"sourceCodeEnd":623,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/cloud/state.go#L587-L623","documentation":"Thrown by GetRootOutputValues when iterating outputs and a sensitive output's value must be fetched individually via StateVersionOutputs.Read(ctx, output.ID) but that API call fails. Sensitive outputs are not included in the bulk read for security reasons and require a separate authorized fetch. The %w wraps the TFE client error and includes the output ID.","triggerScenarios":"The authenticated user/team has permission to read outputs generally but not to read sensitive output values specifically; network failure during the individual sensitive-output HTTP GET; the sensitive output's state version output record was deleted between the bulk read and the individual read; TFE server error on the specific output read.","commonSituations":"RBAC configuration that grants read but not sensitive-output-read; CI token scoped too narrowly for a workspace with sensitive outputs; transient TFE instability affecting a single API call within a batch.","solutions":["Verify the authenticated identity has permission to read sensitive state version outputs on the workspace","Retry the operation if the error looks transient (network/server error on a single output)","Check whether the output ID still exists in the state version outputs list (use the TFE API or UI)"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Before reading outputs, verify the identity can read sensitive outputs:\n// Check workspace permissions include state-version-output read with sensitive access.\nws, err := tfeClient.Workspaces.Read(ctx, organization, workspaceName)\nif err != nil {\n    return err\n}\n// TFE does not expose granular sensitive-output permission via the workspace object,\n// so attempt a probe read if sensitive outputs exist.","typeGuard":null,"tryCatchPattern":"outputs, err := state.GetRootOutputValues(ctx)\nif err != nil && strings.Contains(err.Error(), \"could not read state version output\") {\n    // a specific sensitive output read failed; check permissions or retry\n    return nil, fmt.Errorf(\"failed to read a sensitive output (check permissions): %w\", err)\n}\nreturn outputs, err","preventionTips":["Ensure the CI/service account has permission to read sensitive state version outputs, not just regular outputs","Minimize the number of sensitive outputs to reduce the blast radius of permission gaps","Audit workspace RBAC when adding new sensitive outputs to ensure the automation identity can read them"],"tags":["outputs","sensitive","tfe","permissions","authentication","terraform"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}