{"record":{"id":"fe89650ff7c8a873","repo":"hashicorp/terraform","slug":"provider-s-required-by-this-configuration-but-no","errorCode":null,"errorMessage":"provider %s: required by this configuration but no version is selected","messagePattern":"provider (.+?): required by this configuration but no version is selected","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/configs/config.go","lineNumber":293,"sourceCode":"\t\tif !depsfile.ProviderIsLockable(providerAddr) {\n\t\t\tcontinue // disregard builtin providers, and such\n\t\t}\n\t\tif depLocks != nil && depLocks.ProviderIsOverridden(providerAddr) {\n\t\t\t// The \"overridden\" case is for unusual special situations like\n\t\t\t// dev overrides, so we'll explicitly note it in the logs just in\n\t\t\t// case we see bug reports with these active and it helps us\n\t\t\t// understand why we ended up using the \"wrong\" plugin.\n\t\t\tlog.Printf(\"[DEBUG] Config.VerifyDependencySelections: skipping %s because it's overridden by a special configuration setting\", providerAddr)\n\t\t\tcontinue\n\t\t}\n\n\t\tvar lock *depsfile.ProviderLock\n\t\tif depLocks != nil { // Should always be true in main code, but unfortunately sometimes not true in old tests that don't fill out arguments completely\n\t\t\tlock = depLocks.Provider(providerAddr)\n\t\t}\n\t\tif lock == nil {\n\t\t\tlog.Printf(\"[TRACE] Config.VerifyDependencySelections: provider %s has no lock file entry to satisfy %q\", providerAddr, providerreqs.VersionConstraintsString(constraints))\n\t\t\terrs = append(errs, fmt.Errorf(\"provider %s: required by this configuration but no version is selected\", providerAddr))\n\t\t\tcontinue\n\t\t}\n\n\t\tselectedVersion := lock.Version()\n\t\tallowedVersions := providerreqs.MeetingConstraints(constraints)\n\t\tlog.Printf(\"[TRACE] Config.VerifyDependencySelections: provider %s has %s to satisfy %q\", providerAddr, selectedVersion.String(), providerreqs.VersionConstraintsString(constraints))\n\t\tif !allowedVersions.Has(selectedVersion) {\n\t\t\t// The most likely cause of this is that the author of a module\n\t\t\t// has changed its constraints, but this could also happen in\n\t\t\t// some other unusual situations, such as the user directly\n\t\t\t// editing the lock file to record something invalid. We'll\n\t\t\t// distinguish those cases here in order to avoid the more\n\t\t\t// specific error message potentially being a red herring in\n\t\t\t// the edge-cases.\n\t\t\tcurrentConstraints := providerreqs.VersionConstraintsString(constraints)\n\t\t\tlockedConstraints := providerreqs.VersionConstraintsString(lock.VersionConstraints())\n\t\t\tswitch {\n\t\t\tcase currentConstraints != lockedConstraints:","sourceCodeStart":275,"sourceCodeEnd":311,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/configs/config.go#L275-L311","documentation":"During dependency selection verification, a provider required by the configuration has no corresponding entry in the dependency lock file (.terraform.lock.hcl). This means terraform init has not been run (or not re-run after adding a new provider requirement), so no version has been selected and locked for that provider.","triggerScenarios":"A required_providers entry exists in the config (directly or via a module) but .terraform.lock.hcl has no provider block for that source address. Occurs after adding a new provider to the config without running terraform init, or after deleting the lock file, or after pulling a module that introduces a new provider dependency.","commonSituations":"Developer adds a new provider block to main.tf and runs terraform plan without terraform init. Team member clones the repo but the lock file is gitignored or was deleted. A module update pulls in a transitive provider dependency not in the lock file. Lock file was manually edited and the entry was removed.","solutions":["Run terraform init to resolve and lock the missing provider.","Verify the provider source address in required_providers matches exactly (e.g., hashicorp/aws vs registry.terraform.io/hashicorp/aws).","Ensure .terraform.lock.hcl is committed to version control and not gitignored.","If the provider was recently added, confirm the module referencing it is correctly referenced in the configuration."],"exampleFix":"# before — new provider added but not initialized\nrequired_providers {\n  google = {\n    source  = \"hashicorp/google\"\n    version = \"~> 4.0\"\n  }\n}\n# running `terraform plan` directly → error\n\n# after — initialize first\nterraform init\nterraform plan","handlingStrategy":"validation","validationCode":"// Check that every required provider has a lock entry before plan\n// Shell pre-check:\n//   terraform providers lock -platform=linux_amd64\n// Or simply always run terraform init after changing required_providers.\n\n// Go-side (if embedding Terraform):\nfunc ensureProvidersLocked(workingDir string) error {\n    cmd := exec.Command(\"terraform\", \"init\", \"-input=false\", \"-lockfile=readonly\")\n    cmd.Dir = workingDir\n    return cmd.Run()\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Always run terraform init after adding or changing required_providers.","Commit .terraform.lock.hcl to version control.","Use terraform init -lockfile=readonly in CI to fail fast if the lock file is out of date.","Never gitignore .terraform.lock.hcl."],"tags":["config","providers","dependency-lock","init","lock-file"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}