{"record":{"id":"eab2119180c99329","repo":"hashicorp/terraform","slug":"error-loading-variables-w-eab211","errorCode":null,"errorMessage":"error loading variables: %w","messagePattern":"error loading variables: %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/cloud/backend_context.go","lineNumber":208,"sourceCode":"\t\tdiags = diags.Append(fmt.Errorf(\"error finding remote workspace: %w\", err))\n\t\treturn nil, diags\n\t}\n\n\tw, err := b.fetchWorkspace(ctx, b.Organization, workspace)\n\tif err != nil {\n\t\tdiags = diags.Append(fmt.Errorf(\"error loading workspace: %w\", err))\n\t\treturn nil, diags\n\t}\n\n\tif isLocalExecutionMode(w.ExecutionMode) {\n\t\tlog.Printf(\"[TRACE] cloud: skipping variable fetch for workspace %s/%s (%s), workspace is in Local Execution mode\", b.getRemoteWorkspaceName(workspace), b.Organization, remoteWorkspaceID)\n\t\treturn nil, nil\n\t}\n\n\tlog.Printf(\"[TRACE] cloud: retrieving variables from workspace %s/%s (%s)\", b.getRemoteWorkspaceName(workspace), b.Organization, remoteWorkspaceID)\n\ttfeVariables, err := b.client.Variables.ListAll(ctx, remoteWorkspaceID, nil)\n\tif err != nil && err != tfe.ErrResourceNotFound {\n\t\tdiags = diags.Append(fmt.Errorf(\"error loading variables: %w\", err))\n\t\treturn nil, diags\n\t}\n\n\tresult := make(map[string]arguments.UnparsedVariableValue)\n\tif tfeVariables != nil {\n\t\tfor _, v := range tfeVariables.Items {\n\t\t\tif v.Category == tfe.CategoryTerraform {\n\t\t\t\tresult[v.Key] = &remoteStoredVariableValue{\n\t\t\t\t\tdefinition: v,\n\t\t\t\t}\n\t\t\t}\n\t\t}\n\t}\n\n\treturn result, nil\n}\n\n// remoteStoredVariableValue is a backendrun.UnparsedVariableValue implementation","sourceCodeStart":190,"sourceCodeEnd":226,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/cloud/backend_context.go#L190-L226","documentation":"Thrown by Cloud.FetchVariables when b.client.Variables.ListAll(ctx, remoteWorkspaceID, nil) fails with any error except tfe.ErrResourceNotFound. ErrResourceNotFound is intentionally tolerated (treated as 'no variables'), but all other failures — auth, permission, network, server error — surface here. This is the call that actually pulls the Terraform-category variables for the run.","triggerScenarios":"ListAll paginates the workspace variables endpoint; it errors on 401/403 (token can read the workspace but not its variables), 5xx server error, transport timeout, or a malformed workspace ID passed through from getRemoteWorkspaceID. Local Execution mode workspaces never reach this call (they return early at line 200).","commonSituations":"Custom team role with 'read workspace' but not 'read variables'; token expired between the workspace read and the variable read; large variable set hitting a gateway timeout; TFE upgrade mid-session changing the API contract.","solutions":["Check the wrapped `%w` error: 403 means the token's team role lacks 'Variables: Read' on the workspace.","Re-run `terraform login` and confirm the token belongs to a team with variable read permission.","Retry the operation — transient 5xx/network failures on ListAll are common.","If self-hosted TFE, verify the variables API endpoint is reachable and not rate-limited.","Confirm the workspace is not in Local Execution mode (that path skips this call entirely)."],"exampleFix":null,"handlingStrategy":"retry","validationCode":"// Confirm the token can list variables before the run.\n// (Requires the same TFE client; call in a pre-flight check.)\nfunc canListVariables(c *tfe.Client, ctx context.Context, wsID string) error {\n    _, err := c.Variables.List(ctx, wsID, nil)\n    return err\n}","typeGuard":null,"tryCatchPattern":"// Distinguish ErrResourceNotFound (tolerated) from real errors.\nvars, err := c.Variables.ListAll(ctx, wsID, nil)\nif err != nil && err != tfe.ErrResourceNotFound {\n    return fmt.Errorf(\"error loading variables: %w\", err)\n}","preventionTips":["Grant the token's team role 'Variables: Read' on every cloud workspace.","Avoid Local Execution mode unless you intentionally skip variable fetch.","Retry transient API failures — ListAll is a read.","Audit team role permissions before adding a workspace to the backend."],"tags":["terraform","hcp-terraform","tfe","variables","api","auth","permissions"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}