{"record":{"id":"f0327ea735258656","repo":"hashicorp/terraform","slug":"storage-newclient-failed-v","errorCode":null,"errorMessage":"storage.NewClient() failed: %v","messagePattern":"storage\\.NewClient\\(\\) failed: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/gcs/backend.go","lineNumber":256,"sourceCode":"\t\t}\n\n\t\topts = append(opts, option.WithTokenSource(ts))\n\n\t} else {\n\t\topts = append(opts, credOptions...)\n\t}\n\n\topts = append(opts, option.WithUserAgent(httpclient.UserAgentString()))\n\n\t// Custom endpoint for storage API\n\tif storageEndpoint := data.String(\"storage_custom_endpoint\"); storageEndpoint != \"\" {\n\t\tendpoint := option.WithEndpoint(storageEndpoint)\n\t\topts = append(opts, endpoint)\n\t}\n\tclient, err := storage.NewClient(ctx, opts...)\n\tif err != nil {\n\t\treturn backendbase.ErrorAsDiagnostics(\n\t\t\tfmt.Errorf(\"storage.NewClient() failed: %v\", err),\n\t\t)\n\t}\n\n\tb.storageClient = client\n\n\t// Customer-supplied encryption\n\tkey := data.String(\"encryption_key\")\n\tif key != \"\" {\n\t\tkc, err := readPathOrContents(key)\n\t\tif err != nil {\n\t\t\treturn backendbase.ErrorAsDiagnostics(\n\t\t\t\tfmt.Errorf(\"Error loading encryption key: %s\", err),\n\t\t\t)\n\t\t}\n\n\t\t// The GCS client expects a customer supplied encryption key to be\n\t\t// passed in as a 32 byte long byte slice. The byte slice is base64\n\t\t// encoded before being passed to the API. We take a base64 encoded key","sourceCodeStart":238,"sourceCodeEnd":274,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/gcs/backend.go#L238-L274","documentation":"Thrown when the Google Cloud Storage client constructor returns an error. By this point credential options, user agent, and any custom endpoint have been assembled into opts; storage.NewClient(ctx, opts...) failing means authentication, transport, or endpoint configuration is invalid.","triggerScenarios":"storage.NewClient returns a non-nil error — invalid credentials JSON format accepted earlier but rejected by the token endpoint, no application-default credentials available, unreachable custom endpoint, or system clock skew breaking the OAuth exchange.","commonSituations":"Running terraform in CI without GOOGLE_APPLICATION_CREDENTIALS or workload identity; pointing storage_custom_endpoint at a URL that returns non-OAuth responses; the ADC metadata server is unreachable from the VM; transient network failure reaching googleapis.com.","solutions":["Run `gcloud auth application-default login` (or set GOOGLE_APPLICATION_CREDENTIALS) and retry.","Inspect the wrapped %v error in the message — it names the real cause (e.g., 'cannot find credentials').","Remove or correct storage_custom_endpoint if it points at a non-GCS service.","Verify outbound network access to oauth2.googleapis.com and storage.googleapis.com."],"exampleFix":"// before — no credentials in CI\n// after\ngcloud auth application-default login --backend=no  # or set GOOGLE_APPLICATION_CREDENTIALS","handlingStrategy":"retry","validationCode":"// Pre-flight ADC check before invoking terraform.\n// `gcloud auth application-default print-access-token` returns non-zero if ADC is missing.","typeGuard":null,"tryCatchPattern":"// Retry transient client-creation failures with backoff.\nvar client *storage.Client\nvar err error\nfor i := 0; i < 3; i++ {\n    client, err = storage.NewClient(ctx, opts...)\n    if err == nil { break }\n    if isPermAuthErr(err) { break } // don't retry bad creds\n    time.Sleep(backoff(i))\n}","preventionTips":["Run `gcloud auth application-default login` in interactive environments.","In CI, set GOOGLE_APPLICATION_CREDENTIALS or enable Workload Identity.","Inspect the wrapped error first — do not retry on auth-config errors."],"tags":["gcs","backend","authentication","storage","network"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}