{"record":{"id":"a27b58db62a25b0f","repo":"hashicorp/terraform","slug":"building-storage-accounts-client-v","errorCode":null,"errorMessage":"building Storage Accounts client: %+v","messagePattern":"building Storage Accounts client: %\\+v","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/azure/api_client.go","lineNumber":98,"sourceCode":"\t\t}\n\n\t\t// When using Azure CLI to auth, the user can leave the \"subscription_id\" unspecified. In this case the subscription id is inferred from\n\t\t// the Azure CLI default subscription.\n\t\tif config.SubscriptionID == \"\" {\n\t\t\tif cachedAuth, ok := resourceManagerAuth.(*auth.CachedAuthorizer); ok {\n\t\t\t\tif cliAuth, ok := cachedAuth.Source.(*auth.AzureCliAuthorizer); ok && cliAuth.DefaultSubscriptionID != \"\" {\n\t\t\t\t\tconfig.SubscriptionID = cliAuth.DefaultSubscriptionID\n\t\t\t\t}\n\t\t\t}\n\t\t}\n\t\tif config.SubscriptionID == \"\" {\n\t\t\treturn nil, fmt.Errorf(\"subscription id not specified\")\n\t\t}\n\n\t\t// Setup the SA client.\n\t\tclient.storageAccountsClient, err = storageaccounts.NewStorageAccountsClientWithBaseURI(config.AuthConfig.Environment.ResourceManager)\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"building Storage Accounts client: %+v\", err)\n\t\t}\n\t\tclient.configureClient(client.storageAccountsClient.Client, resourceManagerAuth)\n\n\t\t// Populating the storage account detail\n\t\tstorageAccountId := commonids.NewStorageAccountID(config.SubscriptionID, config.ResourceGroupName, client.storageAccountName)\n\t\tresp, err := client.storageAccountsClient.GetProperties(ctx, storageAccountId, storageaccounts.DefaultGetPropertiesOperationOptions())\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"retrieving %s: %+v\", storageAccountId, err)\n\t\t}\n\t\tif resp.Model == nil {\n\t\t\treturn nil, fmt.Errorf(\"retrieving %s: model was nil\", storageAccountId)\n\t\t}\n\t\tclient.accountDetail, err = populateAccountDetails(storageAccountId, *resp.Model)\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"populating details for %s: %+v\", storageAccountId, err)\n\t\t}\n\t}\n","sourceCodeStart":80,"sourceCodeEnd":116,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/azure/api_client.go#L80-L116","documentation":"Thrown by Azure buildClient when storageaccounts.NewStorageAccountsClientWithBaseURI(config.AuthConfig.Environment.ResourceManager) returns an error. This constructor only fails when the ARM base URI is empty or not a parseable URL, so the root cause is the environment metadata rather than credentials.","triggerScenarios":"config.AuthConfig.Environment.ResourceManager is empty or malformed, so the go-azure-sdk storageaccounts client cannot be constructed. Happens with a custom/incorrect environment name, a hand-built environments.Environment missing the ResourceManager endpoint, or a version skew in go-azure-sdk that changed how base URIs are resolved.","commonSituations":"Using environment=... with an unsupported name (typo of 'AzurePublicCloud', a private cloud name not registered), overriding ARM_ENDPOINT or metadata_url with a bad URL, or a stale go-azure-sdk dependency that no longer matches the environment struct shape.","solutions":["Verify the environment name is one Terraform recognizes (AzurePublicCloud, AzureChinaCloud, AzureUSGovernmentCloud, AzureGermanCloud, or a properly configured custom environment).","For air-gapped/custom clouds, ensure the environment metadata fully defines the ResourceManager endpoint URL and is reachable.","If overriding endpoints via env vars, supply a complete, parseable ARM base URL.","Update the go-azure-sdk dependency to the version Terraform core expects to avoid struct/endpoint mismatches."],"exampleFix":"# before: custom env with no ARM endpoint\nexport ARM_ENVIRONMENT=\"MyCloud\"   # not registered -> building Storage Accounts client fails\n# after: use a supported env or register metadata\nexport ARM_ENVIRONMENT=\"AzurePublicCloud\"","handlingStrategy":"validation","validationCode":"func validEnv(env environments.Environment) error {\n    if env.ResourceManager == nil || *env.ResourceManager == \"\" {\n        return fmt.Errorf(\"environment has no ResourceManager endpoint\")\n    }\n    if _, err := url.Parse(*env.ResourceManager); err != nil {\n        return fmt.Errorf(\"ResourceManager endpoint is not a URL: %w\", err)\n    }\n    return nil\n}","typeGuard":"null","tryCatchPattern":"client, err := azure.NewClient(ctx, cfg)\nif err != nil && strings.Contains(err.Error(), \"building Storage Accounts client\") {\n    // environment metadata is wrong; verify ARM_ENVIRONMENT / metadata URL\n}","preventionTips":["Use a supported environment name unless you have fully defined custom metadata.","Keep go-azure-sdk in lockstep with the Terraform version to avoid endpoint-resolution regressions.","Smoke-test custom environments by calling storageaccounts client construction in isolation."],"tags":["azure","backend","sdk","configuration","environment","arm"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}