{"record":{"id":"cfdf400ed1a112ae","repo":"hashicorp/terraform","slug":"failed-to-approve-use-of-state-storage-provider","errorCode":null,"errorMessage":"Failed to approve use of state storage provider: %s","messagePattern":"Failed to approve use of state storage provider: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/command/meta_backend.go","lineNumber":3235,"sourceCode":"\t\tId: fmt.Sprintf(\"approve-provider-%s-%s\", lock.Provider().Type, lock.Version()), // E.g. approve-provider-aws-4.0.0. This needs to be unique in case the command needs approval for >1 provider.\n\t\tQuery: fmt.Sprintf(`Do you want to use provider %q (%s), version %s, for managing state?\nPlatform: %s\nAuthentication: %s\nHashes:\n%s\n`,\n\t\t\tlock.Provider().Type,\n\t\t\tlock.Provider(),\n\t\t\tlock.Version(),\n\t\t\tgetproviders.CurrentPlatform.String(),\n\t\t\tauthentication,\n\t\t\thashList.String(),\n\t\t),\n\t\tDescription: fmt.Sprintf(`Check the details above for provider %q and confirm that you trust the provider.\n\tOnly 'yes' will be accepted to confirm.`, lock.Provider().Type),\n\t})\n\tif err != nil {\n\t\treturn diags.Append(fmt.Errorf(\"Failed to approve use of state storage provider: %s\", err))\n\t}\n\tif v != \"yes\" {\n\t\treturn diags.Append(\n\t\t\tfmt.Errorf(\"State store provider %q (%s) was not approved, so init cannot continue.\",\n\t\t\t\tlock.Provider().Type,\n\t\t\t\tlock.Provider(),\n\t\t\t),\n\t\t)\n\t}\n\treturn diags\n}\n\n//-------------------------------------------------------------------\n// Output constants and initialization code\n//-------------------------------------------------------------------\n\nconst inputCloudInitCreateWorkspace = `\nThere are no workspaces with the configured tags (%s)","sourceCodeStart":3217,"sourceCodeEnd":3253,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/command/meta_backend.go#L3217-L3253","documentation":"In promptStateStorageProviderApproval, after a state-storage provider is installed whose trust/safety cannot be fully verified, Terraform asks the user to type 'yes' to approve it. The UIInput().Input() call itself errored (not the user typing 'no'). Wrapped %s is the input/IO error.","triggerScenarios":"m.UIInput().Input(...) errors during the state-store provider approval prompt. Triggers: non-TTY environment with input enabled, stdin closed/EOF, a UIInput implementation failure, or Ctrl-C/signal during the prompt.","commonSituations":"CI/container `tofu init` for a new state_store provider without a TTY; piped stdin that closes before the prompt; embedded use without a UIInput; user interrupts the approval prompt.","solutions":["Pre-approve trust out-of-band so the prompt is not needed: set the provider signing/trust configuration or pin a provider version already in the lock file with known-good hashes.","Run init in a real TTY when interactive approval is required, or supply `-input=false` together with a fully trusted/pinned provider.","Ensure the provider's package is signed and its hashes are in .terraform.lock.hcl so approval is bypassed on subsequent inits.","In embedded use, provide a UIInput that can answer the approval prompt programmatically."],"exampleFix":"// before: CI, no TTY, new state_store provider needs interactive approval\ntofu init  # -> Failed to approve use of state storage provider\n\n// after: pre-pin trusted hashes so approval is unnecessary, run non-interactive\ntofu providers lock example.com/acme/storage\ntofu init -input=false","handlingStrategy":"try-catch","validationCode":"// Skip the interactive approval prompt when its preconditions are not met:\n// no TTY, or trust already established via signed provider + lock hashes.\nfunc shouldPromptProviderApproval(isTTY bool, lockHasSignedHashes bool) bool {\n    return isTTY && !lockHasSignedHashes\n}\n\n// Pre-pin trusted hashes so approval is bypassed:\n//   tofu providers lock <provider-addr>\n// then commit .terraform.lock.hcl.","typeGuard":null,"tryCatchPattern":"v, err := m.UIInput().Input(context.Background(), opts)\nif err != nil {\n    if isNoTTYErr(err) || errors.Is(err, io.EOF) {\n        return diags.Append(fmt.Errorf(\"cannot prompt for state-store provider approval without a TTY; pre-pin trusted hashes via 'tofu providers lock %s' and re-run with -input=false: %s\", lock.Provider(), err))\n    }\n    return diags.Append(fmt.Errorf(\"Failed to approve use of state storage provider: %s\", err))\n}","preventionTips":["Pre-pin trusted provider hashes with `tofu providers lock` and commit .terraform.lock.hcl.","Use a signing/trust configuration so the approval prompt is bypassed.","Run init in a TTY for the first approval of a new state-store provider, or run `-input=false` after pinning.","In embedded use, provide a UIInput that can answer the approval prompt."],"tags":["state-store","provider","interactive","approval","trust","tty"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}