{"record":{"id":"df6daa238b31ffa0","repo":"hashicorp/terraform","slug":"populating-details-for-s-v","errorCode":null,"errorMessage":"populating details for %s: %+v","messagePattern":"populating details for (.+?): %\\+v","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/azure/api_client.go","lineNumber":113,"sourceCode":"\t\t// Setup the SA client.\n\t\tclient.storageAccountsClient, err = storageaccounts.NewStorageAccountsClientWithBaseURI(config.AuthConfig.Environment.ResourceManager)\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"building Storage Accounts client: %+v\", err)\n\t\t}\n\t\tclient.configureClient(client.storageAccountsClient.Client, resourceManagerAuth)\n\n\t\t// Populating the storage account detail\n\t\tstorageAccountId := commonids.NewStorageAccountID(config.SubscriptionID, config.ResourceGroupName, client.storageAccountName)\n\t\tresp, err := client.storageAccountsClient.GetProperties(ctx, storageAccountId, storageaccounts.DefaultGetPropertiesOperationOptions())\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"retrieving %s: %+v\", storageAccountId, err)\n\t\t}\n\t\tif resp.Model == nil {\n\t\t\treturn nil, fmt.Errorf(\"retrieving %s: model was nil\", storageAccountId)\n\t\t}\n\t\tclient.accountDetail, err = populateAccountDetails(storageAccountId, *resp.Model)\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"populating details for %s: %+v\", storageAccountId, err)\n\t\t}\n\t}\n\n\treturn &client, nil\n}\n\nfunc (c *Client) getBlobClient(ctx context.Context) (bc *blobs.Client, err error) {\n\tif c.blobsClient != nil {\n\t\treturn c.blobsClient, nil\n\t}\n\n\tdefer func() {\n\t\tif err == nil {\n\t\t\tc.blobsClient = bc\n\t\t}\n\t}()\n\n\tvar baseUri string","sourceCodeStart":95,"sourceCodeEnd":131,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/azure/api_client.go#L95-L131","documentation":"Thrown by buildClient when, after fetching the Storage Account via storageAccountsClient.GetProperties, the helper populateAccountDetails returns an error. That helper fails only when the ARM response is missing nested payloads: account.Properties == nil or account.Properties.PrimaryEndpoints == nil. In other words the ARM GetProperties call succeeded (HTTP 200) but the returned model is missing the data-plane endpoint information the backend needs to build the blob/container clients.","triggerScenarios":"buildClient reaches populateAccountDetails (requires armAuthRequired == true, i.e. lookup_blob_endpoint set, or no access_key/sas/aad). The ARM-returned StorageAccount has nil Properties or nil Properties.PrimaryEndpoints.","commonSituations":"Storage account still provisioning (transient ARM state); ARM returned a stale or degraded response during a region incident; account was created by tooling that produced a non-standard SKU layout (e.g. premium-only) exposing no blob PrimaryEndpoints; rare SDK contract violation across API versions.","solutions":["Wait a few minutes and re-run `terraform init` (transient ARM state during account provisioning).","Confirm via `az storage account show -g <rg> -n <acct>` that properties.primaryEndpoints.blob is populated; if not, the account is unhealthy.","Provide an explicit access_key or sas_token in the backend block to bypass ARM lookup entirely.","If reproducible, set use_azuread_auth = true to skip the populateAccountDetails code path.","Open an Azure support ticket if the ARM API consistently returns nil properties for a healthy account."],"exampleFix":null,"handlingStrategy":"retry","validationCode":"// Pre-flight: confirm the ARM StorageAccount has the nested payloads buildClient needs.\nfunc storageAccountHasEndpoints(ctx context.Context, c *storageaccounts.StorageAccountsClient, id commonids.StorageAccountId) error {\n    resp, err := c.GetProperties(ctx, id, storageaccounts.DefaultGetPropertiesOperationOptions())\n    if err != nil { return err }\n    if resp.Model == nil || resp.Model.Properties == nil || resp.Model.Properties.PrimaryEndpoints == nil {\n        return fmt.Errorf(\"storage account %s missing Properties/PrimaryEndpoints\", id)\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":"// buildClient wraps populateAccountDetails; retry with backoff for transient ARM nil-properties.\nvar client *azure.Client\nerr := backoff.Retry(func() error {\n    c, err := azure.BuildClient(ctx, cfg)\n    if err != nil {\n        if strings.Contains(err.Error(), \"populating details\") { return err }\n        return backoff.Permanent(err)\n    }\n    client = c\n    return nil\n}, backoff.NewExponentialBackOff())","preventionTips":["Pre-warm new storage accounts: wait until `az storage account show` returns populated primaryEndpoints before running terraform init.","Provide access_key or sas_token in CI to bypass the ARM lookup path entirely.","Prefer use_azuread_auth = true to skip populateAccountDetails."],"tags":["azure","terraform-backend","arm","storage-account","remote-state","configuration"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}