{"record":{"id":"d7d4337bc8ee6352","repo":"hashicorp/terraform","slug":"failed-to-refresh-state-s","errorCode":null,"errorMessage":"Failed to refresh state: %s\n","messagePattern":"Failed to refresh state: (.+?)\n","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/command/state_show.go","lineNumber":118,"sourceCode":"\tschemas, diags := lr.Core.Schemas(lr.Config, lr.InputState)\n\tif diags.HasErrors() {\n\t\treturn view.DisplayResourceInstanceState(jsonformat.State{}, diags)\n\t}\n\n\t// Get the state\n\tenv, err := c.Workspace()\n\tif err != nil {\n\t\tdiags = diags.Append(fmt.Sprintf(\"Error selecting workspace: %s\\n\", err))\n\t\tview.Diagnostics(diags)\n\t\treturn 1\n\t}\n\tstateMgr, sDiags := b.StateMgr(env)\n\tif sDiags.HasErrors() {\n\t\tdiags = diags.Append(fmt.Errorf(errStateLoadingState, sDiags.Err()))\n\t\treturn view.DisplayResourceInstanceState(jsonformat.State{}, diags)\n\t}\n\tif err := stateMgr.RefreshState(); err != nil {\n\t\tdiags = diags.Append(fmt.Errorf(\"Failed to refresh state: %s\\n\", err))\n\t\treturn view.DisplayResourceInstanceState(jsonformat.State{}, diags)\n\t}\n\n\tstate := stateMgr.State()\n\tif state == nil {\n\t\tdiags = diags.Append(errors.New(errStateNotFound))\n\t\treturn view.DisplayResourceInstanceState(jsonformat.State{}, diags)\n\t}\n\n\tis := state.ResourceInstance(addr)\n\tif !is.HasCurrent() {\n\t\tdiags = diags.Append(errors.New(errNoInstanceFound))\n\t\treturn view.DisplayResourceInstanceState(jsonformat.State{}, diags)\n\t}\n\n\t// check if the resource has a configured provider, otherwise this will use the default provider\n\trs := state.Resource(addr.ContainingResource())\n\tabsPc := addrs.AbsProviderConfig{","sourceCodeStart":100,"sourceCodeEnd":136,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/command/state_show.go#L100-L136","documentation":"Thrown by state_show.go when stateMgr.RefreshState() returns a non-nil error during `terraform state show`. StateMgr was constructed fine ([755] did not fire), but reading the latest snapshot from persistent storage failed. Mirror of [741] for the state show path.","triggerScenarios":"Backend is reachable but the GET/refresh of state fails: S3 NoSuchKey on the state object, HTTP backend 5xx, DynamoDB lock contention, corrupt local state file decode, network blip mid-read.","commonSituations":"State object deleted out-of-band but workspace metadata remains; transient provider error; concurrent run holds the lock; truncated state file from a prior interrupted apply; mismatched KMS/encryption key.","solutions":["Retry — most remote-backend refresh errors are transient.","Confirm the state object exists in the backend (`aws s3 ls s3://<bucket>/<key>`).","Release a stale lock with `terraform force-unlock <LOCK_ID>` only if you are certain no run is active.","For local state, restore from terraform.tfstate.backup."],"exampleFix":"# before: state object missing in S3\n terraform state show aws_instance.web\n\n# after: restore object then retry\n aws s3 cp backup/terraform.tfstate s3://bucket/prod/terraform.tfstate\n terraform state show aws_instance.web","handlingStrategy":"retry","validationCode":"// Head the state object before refresh (S3 example).\nif _, err := s3Client.HeadObject(&s3.HeadObjectInput{Bucket: &bucket, Key: &key}); err != nil {\n    return fmt.Errorf(\"state object missing: %w\", err)\n}","typeGuard":null,"tryCatchPattern":"if err := stateMgr.RefreshState(); err != nil {\n    if isTransientBackendErr(err) {\n        // single retry; refresh is safe (read-only)\n        if err2 := stateMgr.RefreshState(); err2 == nil { err = nil }\n    }\n    if err != nil {\n        diags = diags.Append(fmt.Errorf(\"Failed to refresh state: %s\\n\", err))\n        return view.DisplayResourceInstanceState(jsonformat.State{}, diags)\n    }\n}","preventionTips":["Enable versioning on the state bucket so deleted objects can be restored.","Never delete the state object out-of-band; use `terraform state` subcommands.","Use state locking and avoid `force-unlock` unless certain.","Schedule migrations during low-concurrency windows to avoid lock contention."],"tags":["terraform","state-show","refresh","backend","io","lock"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}