{"record":{"id":"e4bd719f6e747716","repo":"hashicorp/terraform","slug":"cannot-serialize-updated-credentials-file-s","errorCode":null,"errorMessage":"cannot serialize updated credentials file: %s","messagePattern":"cannot serialize updated credentials file: (.+?)","errorType":"console","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/command/cliconfig/credentials.go","lineNumber":386,"sourceCode":"\t\t\tdelete(rawCredsMap, givenHost)\n\t\t}\n\t}\n\n\t// If we have a new object to store we'll write it in now. If the previous\n\t// object had the hostname written in a different way then this will\n\t// appear to change it into our canonical display form, with all the\n\t// letters in lowercase and other transforms from the Internationalized\n\t// Domain Names specification.\n\tif new != nil {\n\t\ttoStore := new.ToStore()\n\t\trawCredsMap[host.ForDisplay()] = ctyjson.SimpleJSONValue{\n\t\t\tValue: toStore,\n\t\t}\n\t}\n\n\tnewSrc, err := json.MarshalIndent(raw, \"\", \"  \")\n\tif err != nil {\n\t\treturn fmt.Errorf(\"cannot serialize updated credentials file: %s\", err)\n\t}\n\n\t// Now we'll write our new content over the top of the existing file.\n\t// Because we updated the data structure surgically here we should not\n\t// have disturbed the meaning of any other content in the file, but it\n\t// might have a different JSON layout than before.\n\t// We'll create a new file with a different name first and then rename\n\t// it over the old file in order to make the change as atomically as\n\t// the underlying OS/filesystem will allow.\n\t{\n\t\tdir, file := filepath.Split(filename)\n\t\tf, err := ioutil.TempFile(dir, file)\n\t\tif err != nil {\n\t\t\treturn fmt.Errorf(\"cannot create temporary file to update credentials: %s\", err)\n\t\t}\n\t\ttmpName := f.Name()\n\t\tmoved := false\n\t\tdefer func(f *os.File, name string) {","sourceCodeStart":368,"sourceCodeEnd":404,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/command/cliconfig/credentials.go#L368-L404","documentation":"Thrown when json.MarshalIndent fails to serialize the in-memory credentials map (already updated with the new host entry) back to bytes. Because the source data was itself just decoded from JSON, a marshal failure here is extremely rare — it indicates an internal inconsistency such as a ctyjson.SimpleJSONValue whose nested Value cannot round-trip, or a value type marshal does not accept.","triggerScenarios":"new.ToStore() produced a cty.Value that ctyjson cannot encode (e.g. contains types or marks unsupported by JSON); a nil/invalid value slipped into rawCredsMap via a programmatic caller; an exotic pre-existing entry that survived decode but cannot re-encode.","commonSituations":"Almost never seen in normal CLI use. Surfaces in programmatic embedding of Terraform where a custom HostCredentialsWritable.ToStore returns a non-JSON-encodable cty.Value, or when a corrupted in-memory map is passed.","solutions":["If you are embedding Terraform programmatically, verify the HostCredentialsWritable.ToStore() implementation returns a JSON-friendly cty.Value (string/number/object).","For CLI users: back up and delete the credentials file, then re-run `terraform login` to rebuild a clean map.","Capture the underlying error string (%s) to identify which value type marshal rejected.","Check the Terraform version — a cty serialization regression could be the cause."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"// When programmatically providing HostCredentialsWritable, ensure ToStore()\n// returns a JSON-encodable cty.Value (string/number/bool/object of those).\nfunc safeToStore(w svcauth.HostCredentialsWritable) error {\n    v := w.ToStore()\n    if _, err := ctyjson.Marshal(v, v.Type()); err != nil {\n        return fmt.Errorf(\"ToStore value not JSON-encodable: %w\", err)\n    }\n    return nil\n}","preventionTips":["Keep ToStore() outputs to primitive cty types.","Round-trip test credentials write/read in unit tests.","Upgrade cty/terraform together to avoid serialization regressions."],"tags":["credentials","json","serialization","cty","internal"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}