{"record":{"id":"ad3fa8158aee2817","repo":"hashicorp/terraform","slug":"attribute-q-is-required","errorCode":null,"errorMessage":"attribute %q is required","messagePattern":"attribute %q is required","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/backendbase/sdklike.go","lineNumber":155,"sourceCode":"\t\t\tv = os.Getenv(envName)\n\t\t\tif v != \"\" {\n\t\t\t\treturn v\n\t\t\t}\n\t\t}\n\t}\n\treturn v\n}\n\n// SDKLikeRequiredWithEnvDefault is a convenience wrapper around\n// [SDKLikeEnvDefault] which returns an error if the result is still the\n// empty string even after trying all of the fallback environment variables.\n//\n// This wrapper requires an additional argument specifying the attribute name\n// just because that becomes part of the returned error message.\nfunc SDKLikeRequiredWithEnvDefault(attrPath string, v string, envNames ...string) (string, error) {\n\tret := SDKLikeEnvDefault(v, envNames...)\n\tif ret == \"\" {\n\t\treturn \"\", fmt.Errorf(\"attribute %q is required\", attrPath)\n\t}\n\treturn ret, nil\n}\n\n// SDKLikeDefaults captures legacy-SDK-like default values to help fill the\n// gap in abstraction level between the legacy SDK and Terraform's own\n// configuration schema model.\ntype SDKLikeDefaults map[string]SDKLikeDefault\n\ntype SDKLikeDefault struct {\n\tEnvVars  []string\n\tFallback string\n\n\t// Required is for situations where an argument is optional to set\n\t// in the configuration but _must_ eventually be set through the\n\t// combination of the configuration and the environment variables\n\t// in this object.\n\t//","sourceCodeStart":137,"sourceCodeEnd":173,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/backendbase/sdklike.go#L137-L173","documentation":"Thrown by backendbase.SDKLikeRequiredWithEnvDefault, a helper that emulates the legacy Terraform SDK's required-string-with-env-fallback behavior. It returns this error only when the supplied value is empty AND every fallback environment variable is also empty/unset. It exists to give backend authors a single call that both resolves env defaults and enforces presence.","triggerScenarios":"Calling SDKLikeRequiredWithEnvDefault(attrPath, v, envNames...) where v == \"\" and os.Getenv(name) returns \"\" for every name in envNames. This typically happens inside a backend's Configure() while reading a schema attribute such as bucket, key, or region.","commonSituations":"The backend block in terraform configuration omits a required argument (e.g. azurerm backend missing storage_account_name) and the matching env var (e.g. ARM_STORAGE_ACCOUNT) is also unset. Also seen in CI when the secret feeding the env var was not injected, or after a backend schema migration that renamed an env var.","solutions":["Set the attribute directly in the backend {} block so v is non-empty before the helper runs.","Export one of the fallback env vars named in envNames with a non-empty value (e.g. export ARM_STORAGE_ACCOUNT=...).","If calling SDKLikeRequiredWithEnvDefault from your own backend code, verify the envNames slice still matches the env vars your users expect after any rename.","Check for trailing whitespace or quoted-empty secrets in CI that resolve the env var to an empty string."],"exampleFix":"// before: backend block missing storage_account_name\nbackend \"azurerm\" {\n  container_name = \"tfstate\"\n}\n// after\nbackend \"azurerm\" {\n  resource_group_name  = \"rg-tf\"\n  storage_account_name = \"mystgacct\"\n  container_name       = \"tfstate\"\n  key                  = \"prod.terraform.tfstate\"\n}","handlingStrategy":"validation","validationCode":"// Before calling SDKLikeRequiredWithEnvDefault, resolve and check yourself.\nfunc resolveRequired(attrPath, v string, envNames ...string) (string, error) {\n    if v == \"\" {\n        for _, n := range envNames {\n            if e := strings.TrimSpace(os.Getenv(n)); e != \"\" {\n                v = e\n                break\n            }\n        }\n    }\n    if v == \"\" {\n        return \"\", fmt.Errorf(\"attribute %q is required (checked config + %v)\", attrPath, envNames)\n    }\n    return v, nil\n}","typeGuard":"null","tryCatchPattern":"// SDKLikeRequiredWithEnvDefault returns (string, error); treat empty-result-with-nil-err as impossible.\nval, err := backendbase.SDKLikeRequiredWithEnvDefault(\"bucket\", cfg.Bucket, \"AWS_BUCKET\", \"TF_BUCKET\")\nif err != nil {\n    return fmt.Errorf(\"backend init: %w\", err)\n}\ncfg.Bucket = val","preventionTips":["Document the env var fallbacks next to each required attribute so users know what to set.","Unit-test backend Configure with both the config value and each env var populated, plus the all-empty case.","Fail backend init early with a precise message rather than letting downstream code crash on an empty string."],"tags":["backend","configuration","required-attribute","sdklike","env-var"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}