{"record":{"id":"9ac692b1c70528f5","repo":"hashicorp/terraform","slug":"s-s-nestingset-attributes-may-not-contain-writeo","errorCode":null,"errorMessage":"%s%s: NestingSet attributes may not contain WriteOnly attributes","messagePattern":"(.+?)(.+?): NestingSet attributes may not contain WriteOnly attributes","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/configs/configschema/internal_validate.go","lineNumber":186,"sourceCode":"\n\tif a.NestedType != nil {\n\t\tswitch a.NestedType.Nesting {\n\t\tcase NestingSingle, NestingMap, NestingGroup:\n\t\t\t// no validations to perform\n\t\tcase NestingList, NestingSet:\n\t\t\tif a.NestedType.Nesting == NestingSet {\n\t\t\t\tety := a.ImpliedType()\n\t\t\t\tif ety.HasDynamicTypes() {\n\t\t\t\t\t// This is not permitted because the HCL (cty) set implementation\n\t\t\t\t\t// needs to know the exact type of set elements in order to\n\t\t\t\t\t// properly hash them, and so can't support mixed types.\n\t\t\t\t\terr = errors.Join(err, fmt.Errorf(\"%s%s: NestingSet attributes may not contain attributes of cty.DynamicPseudoType\", prefix, name))\n\t\t\t\t}\n\t\t\t\tif a.NestedType.ContainsWriteOnly() {\n\t\t\t\t\t// This is not permitted because any marks within sets will\n\t\t\t\t\t// be hoisted up the outer set value, so only the set itself\n\t\t\t\t\t// can be WriteOnly.\n\t\t\t\t\terr = errors.Join(err, fmt.Errorf(\"%s%s: NestingSet attributes may not contain WriteOnly attributes\", prefix, name))\n\t\t\t\t}\n\t\t\t}\n\t\tdefault:\n\t\t\terr = errors.Join(err, fmt.Errorf(\"%s%s: invalid nesting mode %s\", prefix, name, a.NestedType.Nesting))\n\t\t}\n\t\tfor name, attrS := range a.NestedType.Attributes {\n\t\t\tif attrS == nil {\n\t\t\t\terr = errors.Join(err, fmt.Errorf(\"%s%s: attribute schema is nil\", prefix, name))\n\t\t\t\tcontinue\n\t\t\t}\n\t\t\terr = errors.Join(err, attrS.internalValidate(name, prefix))\n\t\t}\n\t}\n\n\treturn err\n}\n\nfunc (o *Object) InternalValidate() error {","sourceCodeStart":168,"sourceCodeEnd":204,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/configs/configschema/internal_validate.go#L168-L204","documentation":"Thrown during schema validation when a NestingSet block contains an attribute marked WriteOnly. The runtime marks WriteOnly values and those marks get hoisted up to the enclosing set, which would corrupt set identity for the whole collection. To keep set semantics well-defined, only the set itself may be WriteOnly, never any nested attribute inside it.","triggerScenarios":"Declaring an attribute with WriteOnly: true inside a NestedType whose Nesting is NestingSet, then calling InternalValidate. WriteOnly attributes (ephemeral/sensitive-on-write values) are a newer schema feature used to model values that must not persist in state.","commonSituations":"Adding ephemeral credentials or tokens to a set-typed block; converting a sensitive attribute into a WriteOnly one without checking whether it lives inside a set; provider framework migrations that introduce WriteOnly on pre-existing set members.","solutions":["Remove WriteOnly: true from every attribute that lives inside the NestingSet block, or","Move the WriteOnly attribute out of the set onto a sibling attribute on the parent block, or","Change the nesting from NestingSet to NestingList/NestingMap, which do not have the mark-hoisting constraint.","If the entire set is meant to be write-only, mark the parent Attribute (not its children) accordingly."],"exampleFix":"// before\nNestedType: &configschema.Object{\n    Nesting: configschema.NestingSet,\n    Attributes: map[string]*configschema.Attribute{\n        \"token\": {Type: cty.String, Optional: true, WriteOnly: true},\n    },\n}\n\n// after — move WriteOnly out of the set\nNestedType: &configschema.Object{\n    Nesting: configschema.NestingList,\n    Attributes: map[string]*configschema.Attribute{\n        \"token\": {Type: cty.String, Optional: true, WriteOnly: true},\n    },\n}","handlingStrategy":"validation","validationCode":"func assertSetHasNoWriteOnly(o *configschema.Object) error {\n    if o == nil || o.Nesting != configschema.NestingSet { return nil }\n    if o.ContainsWriteOnly() {\n        return fmt.Errorf(\"NestingSet object contains WriteOnly attributes\")\n    }\n    return nil\n}","typeGuard":"func isWriteOnlySafe(o *configschema.Object) bool {\n    if o == nil { return true }\n    if o.Nesting == configschema.NestingSet && o.ContainsWriteOnly() { return false }\n    for _, a := range o.Attributes {\n        if a != nil && a.NestedType != nil && !isWriteOnlySafe(a.NestedType) { return false }\n    }\n    return true\n}","tryCatchPattern":null,"preventionTips":["Place WriteOnly attributes outside of any NestingSet block.","If a set itself must be write-only, mark the parent Attribute, not its children.","Use NestingList/NestingMap when WriteOnly members are required inside a collection."],"tags":["schema-validation","write-only","nesting-set","configschema","go"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}