{"record":{"id":"aed02b995e739bf2","repo":"hashicorp/terraform","slug":"error-loading-encryption-key-s","errorCode":null,"errorMessage":"Error loading encryption key: %s","messagePattern":"Error loading encryption key: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/gcs/backend.go","lineNumber":268,"sourceCode":"\t\tendpoint := option.WithEndpoint(storageEndpoint)\n\t\topts = append(opts, endpoint)\n\t}\n\tclient, err := storage.NewClient(ctx, opts...)\n\tif err != nil {\n\t\treturn backendbase.ErrorAsDiagnostics(\n\t\t\tfmt.Errorf(\"storage.NewClient() failed: %v\", err),\n\t\t)\n\t}\n\n\tb.storageClient = client\n\n\t// Customer-supplied encryption\n\tkey := data.String(\"encryption_key\")\n\tif key != \"\" {\n\t\tkc, err := readPathOrContents(key)\n\t\tif err != nil {\n\t\t\treturn backendbase.ErrorAsDiagnostics(\n\t\t\t\tfmt.Errorf(\"Error loading encryption key: %s\", err),\n\t\t\t)\n\t\t}\n\n\t\t// The GCS client expects a customer supplied encryption key to be\n\t\t// passed in as a 32 byte long byte slice. The byte slice is base64\n\t\t// encoded before being passed to the API. We take a base64 encoded key\n\t\t// to remain consistent with the GCS docs.\n\t\t// https://cloud.google.com/storage/docs/encryption#customer-supplied\n\t\t// https://github.com/GoogleCloudPlatform/google-cloud-go/blob/def681/storage/storage.go#L1181\n\t\tk, err := base64.StdEncoding.DecodeString(kc)\n\t\tif err != nil {\n\t\t\treturn backendbase.ErrorAsDiagnostics(\n\t\t\t\tfmt.Errorf(\"Error decoding encryption key: %s\", err),\n\t\t\t)\n\t\t}\n\t\tb.encryptionKey = k\n\t}\n","sourceCodeStart":250,"sourceCodeEnd":286,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/gcs/backend.go#L250-L286","documentation":"Thrown when the customer-supplied encryption_key value cannot be read by readPathOrContents. Like the credentials handling, the encryption_key accepts either a file path or inline content; this error means neither resolved to readable bytes.","triggerScenarios":"Configure sees a non-empty encryption_key; readPathOrContents(key) returns an error — missing file, permission denied, or unreadable path.","commonSituations":"encryption_key points to a key file that is gitignored and absent on this machine; relative path resolved from the wrong directory; the file was rotated and the old path removed.","solutions":["Confirm the file exists at the configured path and is readable by the terraform process.","Prefer an absolute path or a path relative to the terraform working directory.","If passing the key inline, paste the base64 string directly as encryption_key.","Restrict file permissions and store the key in a secret manager, then materialize it before running terraform."],"exampleFix":"// before\nbackend \"gcs\" {\n  bucket        = \"tf-state\"\n  encryption_key = \"./keys/state.key\"   # missing\n}\n// after\nbackend \"gcs\" {\n  bucket        = \"tf-state\"\n  encryption_key = \"/abs/path/state.key\"\n}","handlingStrategy":"validation","validationCode":"key := /* config attr */ \"\"\nif key != \"\" {\n    if _, err := readPathOrContents(key); err != nil {\n        return fmt.Errorf(\"encryption_key source is unreadable: %w\", err)\n    }\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Store the encryption key in a secret manager and write it to a known absolute path before terraform runs.","Verify the file's presence in a pre-flight CI step."],"tags":["gcs","backend","encryption","configuration"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}