{"record":{"id":"f24f611838439678","repo":"hashicorp/terraform","slug":"s-hard-failed","errorCode":null,"errorMessage":"%s hard failed.","messagePattern":"(.+?) hard failed\\.","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote/backend_common.go","lineNumber":445,"sourceCode":"\t\t\t\t\tline = append(line, l...)\n\t\t\t\t}\n\n\t\t\t\tif next || len(line) > 0 {\n\t\t\t\t\tb.CLI.Output(b.Colorize().Color(string(line)))\n\t\t\t\t}\n\t\t\t}\n\t\t}\n\n\t\tswitch pc.Status {\n\t\tcase tfe.PolicyPasses:\n\t\t\tif (r.HasChanges && op.Type == backendrun.OperationTypeApply || i < len(r.PolicyChecks)-1) && b.CLI != nil {\n\t\t\t\tb.CLI.Output(\"\\n------------------------------------------------------------------------\")\n\t\t\t}\n\t\t\tcontinue\n\t\tcase tfe.PolicyErrored:\n\t\t\treturn fmt.Errorf(\"%s errored.\", msgPrefix)\n\t\tcase tfe.PolicyHardFailed:\n\t\t\treturn fmt.Errorf(\"%s hard failed.\", msgPrefix)\n\t\tcase tfe.PolicySoftFailed:\n\t\t\trunURL := fmt.Sprintf(runHeaderErr, b.hostname, b.organization, op.Workspace, r.ID)\n\n\t\t\tif op.Type == backendrun.OperationTypePlan || op.UIOut == nil || op.UIIn == nil ||\n\t\t\t\t!pc.Actions.IsOverridable || !pc.Permissions.CanOverride {\n\t\t\t\treturn fmt.Errorf(\"%s soft failed.\\n%s\", msgPrefix, runURL)\n\t\t\t}\n\n\t\t\tif op.AutoApprove {\n\t\t\t\tif _, err = b.client.PolicyChecks.Override(stopCtx, pc.ID); err != nil {\n\t\t\t\t\treturn generalError(fmt.Sprintf(\"Failed to override policy check.\\n%s\", runURL), err)\n\t\t\t\t}\n\t\t\t} else {\n\t\t\t\topts := &terraform.InputOpts{\n\t\t\t\t\tId:          \"override\",\n\t\t\t\t\tQuery:       \"\\nDo you want to override the soft failed policy check?\",\n\t\t\t\t\tDescription: \"Only 'override' will be accepted to override.\",\n\t\t\t\t}","sourceCodeStart":427,"sourceCodeEnd":463,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote/backend_common.go#L427-L463","documentation":"Returned when a policy check's status is tfe.PolicyHardFailed. Hard-mandatory policy violations cannot be overridden by any user; the run is permanently blocked until the configuration complies. There is no override path, unlike soft failures.","triggerScenarios":"pc.Status == tfe.PolicyHardFailed during checkPolicy. A policy enforced at 'hard-mandatory' level evaluated to false (e.g. disallowed instance type, forbidden region, missing required tags).","commonSituations":"Config violates a governance policy (banned provider, public S3 bucket, non-approved AMI); policy enforcement was recently tightened; new policy set added to the workspace.","solutions":["Read the policy failure detail in the TFC/TFE UI to see which rule failed and why.","Modify the Terraform configuration to satisfy the hard-mandatory policy.","If the policy itself is wrong, change its enforcement level (requires policy admin) - but do not weaken governance lightly.","Re-plan once the configuration complies."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Pre-flight policy simulation is not directly available, but you can static-check\n// configs against known-hard rules before pushing.\n// Use 'terraform validate' + custom Conftest/OPA checks mirroring hard-mandatory rules.","typeGuard":null,"tryCatchPattern":"// Hard fails are non-recoverable; do not retry, route to the config owner.\nif pc.Status == tfe.PolicyHardFailed {\n    return fmt.Errorf(\"hard-mandatory policy failed; config must be changed - no override possible\")\n}","preventionTips":["Mirror hard-mandatory policies as local pre-commit/CI checks (Conftest, OPA) so failures surface before reaching TFC.","Document each hard-mandatory policy with example-compliant configs.","Notify governance owners when adding/tightening hard policies so teams can adapt."],"tags":["backend","remote-backend","policy","sentinel","hard-fail","governance","go"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}