{"record":{"id":"a460fbbd74163a02","repo":"hashicorp/terraform","slug":"lease-does-does-not-have-q-label","errorCode":null,"errorMessage":"Lease does does not have %q label","messagePattern":"Lease does does not have %q label","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/kubernetes/client.go","lineNumber":399,"sourceCode":"\tif !ok || v != \"true\" {\n\t\treturn fmt.Errorf(\"Secret does does not have %q label\", tfstateKey)\n\t}\n\n\tdelProp := metav1.DeletePropagationBackground\n\tdelOps := metav1.DeleteOptions{PropagationPolicy: &delProp}\n\treturn c.kubernetesSecretClient.Delete(context.Background(), name, delOps)\n}\n\nfunc (c *RemoteClient) deleteLease(name string) error {\n\tsecret, err := c.getLease(name)\n\tif err != nil {\n\t\treturn err\n\t}\n\n\tlabels := secret.GetLabels()\n\tv, ok := labels[tfstateKey]\n\tif !ok || v != \"true\" {\n\t\treturn fmt.Errorf(\"Lease does does not have %q label\", tfstateKey)\n\t}\n\n\tdelProp := metav1.DeletePropagationBackground\n\tdelOps := metav1.DeleteOptions{PropagationPolicy: &delProp}\n\treturn c.kubernetesLeaseClient.Delete(context.Background(), name, delOps)\n}\n\nfunc (c *RemoteClient) createSecretName(idx int) (string, error) {\n\tsecretName := strings.Join([]string{tfstateKey, c.workspace, c.nameSuffix}, \"-\")\n\n\tif idx > 0 {\n\t\tsecretName = fmt.Sprintf(\"%s-part-%d\", secretName, idx)\n\t}\n\n\terrs := validation.IsDNS1123Subdomain(secretName)\n\tif len(errs) > 0 {\n\t\tk8sInfo := `\nThis is a requirement for Kubernetes secret names. ","sourceCodeStart":381,"sourceCodeEnd":417,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/kubernetes/client.go#L381-L417","documentation":"Returned by deleteLease when the targeted Lease lacks the tfstateKey label (client.go:396-400). Mirrors deleteSecret's guard: only Leases the backend created (and labeled) may be deleted. Note the same 'does does' typo as the Secret variant.","triggerScenarios":"deleteLease is invoked on a Lease without the tfstateKey=true label — either manually created, label-stripped by a webhook, or a name collision with an unrelated coordination Lease.","commonSituations":"A mutation/label-stripping webhook removing labels; manual cleanup that removed labels; name collision with application Leases; cross-namespace label policy enforcement.","solutions":["Verify the Lease is a Terraform lock Lease; if so, re-apply the tfstateKey=true label with kubectl label lease.","If unrelated, resolve the naming collision rather than deleting.","Audit admission webhooks/controllers for label stripping on the coordination.k8s.io namespace.","The 'does does' typo is cosmetic — safe to ignore."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Before deleting, confirm the Lease is backend-managed:\n// lease, _ := getLease(name)\n// if lease.GetLabels()[tfstateKey] != \"true\" { /* not managed; refuse to delete */ }","typeGuard":null,"tryCatchPattern":"// if err := client.deleteLease(name); err != nil {\n//   if strings.Contains(err.Error(), \"Lease does does not have\") {\n//     // re-label if genuinely a state Lease, else investigate collision\n//   }\n// }","preventionTips":["Preserve the tfstateKey=true label on backend-managed Leases.","Exempt coordination Leases created by Terraform from label-stripping controllers.","Avoid Lease name collisions with application Leases."],"tags":["kubernetes-backend","lease","label","delete","guard"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}