{"record":{"id":"d5594074e84876cc","repo":"hashicorp/terraform","slug":"error-creating-multipart-upload-s","errorCode":null,"errorMessage":"error creating multipart upload: %s","messagePattern":"error creating multipart upload: (.+?)","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/oci/multipart_upload.go","lineNumber":79,"sourceCode":"\tmultipartUploadRequest := &objectstorage.CreateMultipartUploadRequest{\n\t\tNamespaceName:   common.String(multipartUploadData.client.namespace),\n\t\tBucketName:      common.String(multipartUploadData.client.bucketName),\n\t\tRequestMetadata: multipartUploadData.RequestMetadata,\n\t\tCreateMultipartUploadDetails: objectstorage.CreateMultipartUploadDetails{\n\t\t\tObject: common.String(multipartUploadData.client.path),\n\t\t},\n\t}\n\tif multipartUploadData.client.kmsKeyID != \"\" {\n\t\tmultipartUploadRequest.OpcSseKmsKeyId = common.String(multipartUploadData.client.kmsKeyID)\n\t} else if multipartUploadData.client.SSECustomerKey != \"\" && multipartUploadData.client.SSECustomerKeySHA256 != \"\" {\n\t\tmultipartUploadRequest.OpcSseCustomerKey = common.String(multipartUploadData.client.SSECustomerKey)\n\t\tmultipartUploadRequest.OpcSseCustomerKeySha256 = common.String(multipartUploadData.client.SSECustomerKeySHA256)\n\t\tmultipartUploadRequest.OpcSseCustomerAlgorithm = common.String(multipartUploadData.client.SSECustomerAlgorithm)\n\t}\n\n\tmultipartUploadResponse, err := multipartUploadData.client.objectStorageClient.CreateMultipartUpload(context.Background(), *multipartUploadRequest)\n\tif err != nil {\n\t\treturn fmt.Errorf(\"error creating multipart upload: %s\", err)\n\t}\n\n\tworkerCount := defaultNumberOfGoroutines\n\tosUploadPartResponses := make(chan objectStorageUploadPartResponse, len(sourceBlocks))\n\tsourceBlocksChan := make(chan objectStorageSourceBlock, len(sourceBlocks))\n\n\twg := &sync.WaitGroup{}\n\twg.Add(len(sourceBlocks))\n\n\t// Push all source blocks into the channel\n\tfor _, sourceBlock := range sourceBlocks {\n\t\tsourceBlocksChan <- sourceBlock\n\t}\n\tclose(sourceBlocksChan)\n\terrChan := make(chan error, workerCount)\n\t// Start workers\n\tfor i := 0; i < workerCount; i++ {\n\t\tgo func() {","sourceCodeStart":61,"sourceCodeEnd":97,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/oci/multipart_upload.go#L61-L97","documentation":"CreateMultipartUpload — the call that opens a multipart upload session — failed. Same auth/encryption surface as PutObject (309) but on the multipart-init API. Note: the fallback to single-part (client.go:147) only triggers when dataSize ≤ MaxFilePartSize; otherwise this error propagates.","triggerScenarios":"IAM lacks permission to create multipart uploads; KMS key invalid or in an inaccessible compartment; SSE-C customer key misconfigured; bucket deleted; 5xx on the service.","commonSituations":"KMS key rotated; SSE-C and SSE-KMS both partially set; cross-compartment bucket without the right policy; transient OCI incident.","solutions":["Verify the principal can call CreateMultipartUpload (OBJECT_CREATE on the bucket).","Confirm kms_key_id / SSE-C fields are consistent and the key is active.","Confirm the bucket still exists and is in the configured namespace/compartment.","For dataSize ≤ MaxFilePartSize the code will fall back to single-part upload; for larger sizes, resolve the multipart-init failure before retrying."],"exampleFix":"// before: large state with KMS key the runner cannot use\n//   dataSize > DefaultFilePartSize  -> multiPartUploadImpl -> 316\n// after: point at an active key in an accessible compartment\nbackend \"oci\" { kms_key_id = var.active_kms_key_ocid }","handlingStrategy":"retry","validationCode":"// Pre-flight: verify CreateMultipartUpload will succeed for this principal\nfunc canMultipart(c *RemoteClient) error {\n    req := objectstorage.CreateMultipartUploadRequest{\n        NamespaceName: common.String(c.namespace),\n        BucketName:    common.String(c.bucketName),\n        CreateMultipartUploadDetails: objectstorage.CreateMultipartUploadDetails{\n            Object: common.String(c.path + \".probe\"),\n        },\n    }\n    if c.kmsKeyID != \"\" { req.OpcSseKmsKeyId = common.String(c.kmsKeyID) }\n    resp, err := c.objectStorageClient.CreateMultipartUpload(context.Background(), req)\n    if err != nil { return err }\n    abort := objectstorage.AbortMultipartUploadRequest{UploadId: resp.UploadId, NamespaceName: resp.Namespace, BucketName: resp.Bucket, ObjectName: resp.Object}\n    _, _ = c.objectStorageClient.AbortMultipartUpload(context.Background(), abort)\n    return nil\n}","typeGuard":"func isServiceError(err error) (common.ServiceError, bool) {\n    var se common.ServiceError\n    return se, errors.As(err, &se)\n}","tryCatchPattern":"// Retry 5xx/429 on multipart init; surface 4xx for config fixes\nfor i := 0; i < 3; i++ {\n    resp, err := client.CreateMultipartUpload(ctx, *req)\n    if err == nil { return resp, nil }\n    var se common.ServiceError\n    if errors.As(err, &se) && (se.GetHTTPStatusCode() == 429 || se.GetHTTPStatusCode() >= 500) {\n        time.Sleep(backoff(i)); continue\n    }\n    return resp, err\n}","preventionTips":["Confirm the principal can call CreateMultipartUpload before relying on large-state uploads.","Keep kms_key_id / SSE-C config consistent with the single-part path.","For dataSize ≤ MaxFilePartSize, the backend falls back to single-part — keep that path healthy too.","Document that large states also need the multipart-init permission, not just PutObject."],"tags":["oci","multipart-upload","iam","encryption"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}