{"record":{"id":"fda17015f2ac2dfc","repo":"hashicorp/terraform","slug":"error-loading-workspace-w-fda170","errorCode":null,"errorMessage":"error loading workspace: %w","messagePattern":"error loading workspace: %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/cloud/backend_context.go","lineNumber":196,"sourceCode":"\t}\n\n\treturn remoteWorkspace.ID, nil\n}\n\n// FetchVariables implements backendrun.ConstVariableSupplier by retrieving\n// Terraform variables from the HCP Terraform or Terraform Enterprise workspace.\nfunc (b *Cloud) FetchVariables(ctx context.Context, workspace string) (map[string]arguments.UnparsedVariableValue, tfdiags.Diagnostics) {\n\tvar diags tfdiags.Diagnostics\n\n\tremoteWorkspaceID, err := b.getRemoteWorkspaceID(ctx, workspace)\n\tif err != nil {\n\t\tdiags = diags.Append(fmt.Errorf(\"error finding remote workspace: %w\", err))\n\t\treturn nil, diags\n\t}\n\n\tw, err := b.fetchWorkspace(ctx, b.Organization, workspace)\n\tif err != nil {\n\t\tdiags = diags.Append(fmt.Errorf(\"error loading workspace: %w\", err))\n\t\treturn nil, diags\n\t}\n\n\tif isLocalExecutionMode(w.ExecutionMode) {\n\t\tlog.Printf(\"[TRACE] cloud: skipping variable fetch for workspace %s/%s (%s), workspace is in Local Execution mode\", b.getRemoteWorkspaceName(workspace), b.Organization, remoteWorkspaceID)\n\t\treturn nil, nil\n\t}\n\n\tlog.Printf(\"[TRACE] cloud: retrieving variables from workspace %s/%s (%s)\", b.getRemoteWorkspaceName(workspace), b.Organization, remoteWorkspaceID)\n\ttfeVariables, err := b.client.Variables.ListAll(ctx, remoteWorkspaceID, nil)\n\tif err != nil && err != tfe.ErrResourceNotFound {\n\t\tdiags = diags.Append(fmt.Errorf(\"error loading variables: %w\", err))\n\t\treturn nil, diags\n\t}\n\n\tresult := make(map[string]arguments.UnparsedVariableValue)\n\tif tfeVariables != nil {\n\t\tfor _, v := range tfeVariables.Items {","sourceCodeStart":178,"sourceCodeEnd":214,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/cloud/backend_context.go#L178-L214","documentation":"Thrown by Cloud.FetchVariables after b.fetchWorkspace(ctx, b.Organization, workspace) returns a non-nil error. The backend needs full workspace metadata (not just the ID that getRemoteWorkspaceID already retrieved) to inspect ExecutionMode before deciding whether to fetch variables. The wrapped error carries the underlying cause from the TFE/HCP API client.","triggerScenarios":"fetchWorkspace issues a TFE Workspaces.Read request; it fails on a 404 (wrong org/workspace name), 401/403 (token lacks read access or `terraform login` not done), network/transport error, or a 5xx from the TFE instance. The earlier getRemoteWorkspaceID succeeded (so the workspace exists by ID lookup), making this most often a transient API hiccup, a permissions race, or an API-version skew between the two read calls.","commonSituations":"Workspace name casing mismatch between workspaces block and the real HCP workspace; token scoped to a team without workspace read; self-hosted TFE behind a flaky proxy; org name typo in the cloud backend config; an API call retry where the second read hits a different rate-limit window.","solutions":["Verify the workspace name and organization in your cloud backend config match HCP Terraform exactly (case-sensitive).","Run `terraform login` again or rotate the token; confirm the token's team has read access on the workspace.","Re-run: fetchWorkspace is a plain read, so transient API/network errors often clear on retry.","Inspect the wrapped `%w` cause: a 404 points to naming, a 401/403 to auth, a timeout to network.","If using self-hosted TFE, check the API health and that the agent/runner can reach it."],"exampleFix":"// before\nworkspaces {\n  name = \"my-app-prod\"\n  organization = \"MyOrg\"\n}\n// after - fix casing to match HCP Terraform exactly\nworkspaces {\n  name = \"my-app-prod\"\n  organization = \"myorg\"\n}","handlingStrategy":"try-catch","validationCode":"// Before calling operations that trigger FetchVariables, verify workspace access.\nfunc workspaceReadable(b *Cloud, ctx context.Context, org, name string) error {\n    _, err := b.fetchWorkspace(ctx, org, name)\n    return err\n}","typeGuard":null,"tryCatchPattern":"// diags is the idiomatic Go pattern here; FetchVariables returns diags.\ndiags := backend.FetchVariables(ctx, ws)\nif diags.HasErrors() {\n    // surface diags to the user; do not proceed\n}","preventionTips":["Use the same token/team with read access on all workspaces referenced by the config.","Pin a stable TFE/HCP version to avoid API-contract drift.","Run `terraform login` and validate the token before invoking plan/apply.","Keep workspace/org names in version control matching HCP Terraform exactly (case-sensitive)."],"tags":["terraform","hcp-terraform","tfe","workspace","api","auth","network"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}