{"record":{"id":"d88e29ec154c7e3d","repo":"hashicorp/terraform","slug":"resource-identity-schema-version-d-for-s-in-stat","errorCode":null,"errorMessage":"resource identity schema version %d for %s in state does not match version %d from the provider","messagePattern":"resource identity schema version (.+?) for (.+?) in state does not match version (.+?) from the provider","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/command/jsonstate/state.go","lineNumber":433,"sourceCode":"\t\t\t\tresAddr.Type,\n\t\t\t)\n\n\t\t\t// It is possible that the only instance is deposed\n\t\t\tif ri.Current != nil {\n\t\t\t\tif schema.Version != int64(ri.Current.SchemaVersion) {\n\t\t\t\t\treturn nil, fmt.Errorf(\"schema version %d for %s in state does not match version %d from the provider\", ri.Current.SchemaVersion, resAddr, schema.Version)\n\t\t\t\t}\n\n\t\t\t\tcurrent.SchemaVersion = ri.Current.SchemaVersion\n\n\t\t\t\tif schema.Body == nil {\n\t\t\t\t\treturn nil, fmt.Errorf(\"no schema found for %s (in provider %s)\", resAddr.String(), r.ProviderConfig.Provider)\n\t\t\t\t}\n\n\t\t\t\t// Check if we have an identity in the state\n\t\t\t\tif ri.Current.IdentityJSON != nil {\n\t\t\t\t\tif schema.IdentityVersion != int64(ri.Current.IdentitySchemaVersion) {\n\t\t\t\t\t\treturn nil, fmt.Errorf(\"resource identity schema version %d for %s in state does not match version %d from the provider\", ri.Current.IdentitySchemaVersion, resAddr, schema.IdentityVersion)\n\t\t\t\t\t}\n\n\t\t\t\t\tif schema.Identity == nil {\n\t\t\t\t\t\treturn nil, fmt.Errorf(\"no resource identity schema found for %s (in provider %s)\", resAddr.String(), r.ProviderConfig.Provider)\n\t\t\t\t\t}\n\n\t\t\t\t\tcurrent.IdentitySchemaVersion = &ri.Current.IdentitySchemaVersion\n\t\t\t\t}\n\n\t\t\t\triObj, err := ri.Current.Decode(schema)\n\t\t\t\tif err != nil {\n\t\t\t\t\treturn nil, err\n\t\t\t\t}\n\n\t\t\t\tvar value cty.Value\n\t\t\t\tvar sensitivePaths []cty.Path\n\t\t\t\tvalue, current.AttributeValues, sensitivePaths, err = marshalAttributeValues(riObj.Value)\n\t\t\t\tif err != nil {","sourceCodeStart":415,"sourceCodeEnd":451,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/command/jsonstate/state.go#L415-L451","documentation":"Thrown by jsonstate when the state instance carries identity JSON (ri.Current.IdentityJSON != nil) and its identity schema version (IdentitySchemaVersion) does not match the provider's current identity schema version (schema.IdentityVersion). Identity is versioned separately from the main resource schema; a mismatch means the stored identity layout cannot be interpreted by the active provider.","triggerScenarios":"A provider upgrade changed its resource-identity schema version; state was written by a provider version with a different identity schema; identity state upgrade did not run (e.g. raw state push without refresh).","commonSituations":"Provider release that restructured resource identity; enabling/disabling an identity feature across provider versions; restoring identity-bearing state from a newer stack onto an older provider.","solutions":["Run `terraform apply -refresh-only` so the provider upgrades identity state to the current schema version.","Align the provider version with the one that wrote the identity data.","If identity is obsolete, clear it from state through a targeted state edit/refresh once the provider supports it.","Restore a state backup whose identity schema version matches the configured provider."],"exampleFix":"# state carries identity from provider 1.x; provider pinned to 2.x\nrequired_providers { p = { version = \"~> 1.0\" } }  # match writer\n# then terraform init && terraform apply -refresh-only to upgrade identity state","handlingStrategy":"validation","validationCode":"if ri.Current.IdentityJSON != nil && int64(ri.Current.IdentitySchemaVersion) != schema.IdentityVersion {\n    return fmt.Errorf(\"identity schema version %d for %s is stale (provider has %d); run 'terraform apply -refresh-only'\", ri.Current.IdentitySchemaVersion, resAddr, schema.IdentityVersion)\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["After a provider upgrade that changes resource identity, run `terraform apply -refresh-only`.","Keep the provider version aligned with the state's identity-schema provenance.","Track identity-schema versions in the same workflow as resource schema versions."],"tags":["terraform","json-state","identity","schema-version","provider","version-drift"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}