hashicorp/terraform · error

action has config values with unsupported marks

Error message

action %s has config values with unsupported marks: %v

What it means

After removing Sensitive and Ephemeral marks from the action config value, additional mark types remain. The renderer only knows how to serialize Sensitive and Ephemeral, so any other mark type is unsupported for action invocations.

Solutions

  1. Inspect the marks listed via %v to identify which non-Sensitive/Ephemeral mark is present.
  2. Avoid applying unsupported marks to values that flow into action invocation config.
  3. Add handling for the mark type in MarshalActionInvocation if you control the mark definition.
  4. Upgrade or align Terraform versions so only supported marks reach this code.
Defensive patterns

Strategy: validation

Validate before calling

// Report any mark types other than Sensitive/Ephemeral on the value.
func unsupportedMarks(v cty.Value) ([]cty.PathValueMarks, error) {
    _, pms := v.UnmarkDeepWithPaths()
    _, rest := marks.PathsWithMark(pms, marks.Sensitive)
    _, rest = marks.PathsWithMark(rest, marks.Ephemeral)
    return rest, nil
}

Prevention

When it happens

Trigger: A custom or experimental mark type was applied to config values (e.g. a third-party mark, deprecated marks, or marks from a newer internal feature) that the action marshaling path cannot handle.

Common situations: Forked Terraform with extra mark types; future Terraform version introducing a mark not yet handled here.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/8e8be1ff7ec0d0a1. Report an issue: GitHub.

Appendix: source

Thrown at internal/command/jsonplan/action_invocations.go:165

			ai.InvokeActionTrigger.CallingResourceAddress = at.CallingResourceAddr.String()
		}
	default:
		return ai, fmt.Errorf("unsupported action trigger type: %T", at)
	}

	var config []byte
	var sensitive []byte
	var unknown []byte

	if actionDec.ConfigValue != cty.NilVal {
		unmarkedValue, pvms := actionDec.ConfigValue.UnmarkDeepWithPaths()
		sensitivePaths, otherMarks := marks.PathsWithMark(pvms, marks.Sensitive)
		ephemeralPaths, otherMarks := marks.PathsWithMark(otherMarks, marks.Ephemeral)
		if len(ephemeralPaths) > 0 {
			return ai, fmt.Errorf("action %s has ephemeral config values, which are not supported in action invocations", action.Addr)
		}
		if len(otherMarks) > 0 {
			return ai, fmt.Errorf("action %s has config values with unsupported marks: %v", action.Addr, otherMarks)
		}

		unknownValue := unknownAsBool(unmarkedValue)
		unknown, err = ctyjson.Marshal(unknownValue, unknownValue.Type())
		if err != nil {
			return ai, err
		}

		configValue := omitUnknowns(unmarkedValue)
		config, err = ctyjson.Marshal(configValue, configValue.Type())
		if err != nil {
			return ai, err
		}

		sensitivePaths = append(sensitivePaths, schema.ConfigSchema.SensitivePaths(unmarkedValue, nil)...)
		cs := jsonstate.SensitiveAsBool(marks.MarkPaths(unmarkedValue, marks.Sensitive, sensitivePaths))
		sensitive, err = ctyjson.Marshal(cs, cs.Type())
		if err != nil {

View on GitHub (pinned to d32a084675)