hashicorp/terraform · error
action has config values with unsupported marks
Error message
action %s has config values with unsupported marks: %v
What it means
After removing Sensitive and Ephemeral marks from the action config value, additional mark types remain. The renderer only knows how to serialize Sensitive and Ephemeral, so any other mark type is unsupported for action invocations.
Solutions
- Inspect the marks listed via %v to identify which non-Sensitive/Ephemeral mark is present.
- Avoid applying unsupported marks to values that flow into action invocation config.
- Add handling for the mark type in MarshalActionInvocation if you control the mark definition.
- Upgrade or align Terraform versions so only supported marks reach this code.
Defensive patterns
Strategy: validation
Validate before calling
// Report any mark types other than Sensitive/Ephemeral on the value.
func unsupportedMarks(v cty.Value) ([]cty.PathValueMarks, error) {
_, pms := v.UnmarkDeepWithPaths()
_, rest := marks.PathsWithMark(pms, marks.Sensitive)
_, rest = marks.PathsWithMark(rest, marks.Ephemeral)
return rest, nil
} Prevention
- Do not apply non-standard marks to values flowing into action config.
- In forks defining custom marks, add explicit handling here or filter marks upstream.
When it happens
Trigger: A custom or experimental mark type was applied to config values (e.g. a third-party mark, deprecated marks, or marks from a newer internal feature) that the action marshaling path cannot handle.
Common situations: Forked Terraform with extra mark types; future Terraform version introducing a mark not yet handled here.
Related errors
- action has ephemeral config values, which are not supported…
- error in marshaling deferred action invocations
- error marshaling action invocations
- failed to decode action
- no schema found for (in provider )
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/8e8be1ff7ec0d0a1.
Report an issue: GitHub.
Appendix: source
Thrown at internal/command/jsonplan/action_invocations.go:165
ai.InvokeActionTrigger.CallingResourceAddress = at.CallingResourceAddr.String()
}
default:
return ai, fmt.Errorf("unsupported action trigger type: %T", at)
}
var config []byte
var sensitive []byte
var unknown []byte
if actionDec.ConfigValue != cty.NilVal {
unmarkedValue, pvms := actionDec.ConfigValue.UnmarkDeepWithPaths()
sensitivePaths, otherMarks := marks.PathsWithMark(pvms, marks.Sensitive)
ephemeralPaths, otherMarks := marks.PathsWithMark(otherMarks, marks.Ephemeral)
if len(ephemeralPaths) > 0 {
return ai, fmt.Errorf("action %s has ephemeral config values, which are not supported in action invocations", action.Addr)
}
if len(otherMarks) > 0 {
return ai, fmt.Errorf("action %s has config values with unsupported marks: %v", action.Addr, otherMarks)
}
unknownValue := unknownAsBool(unmarkedValue)
unknown, err = ctyjson.Marshal(unknownValue, unknownValue.Type())
if err != nil {
return ai, err
}
configValue := omitUnknowns(unmarkedValue)
config, err = ctyjson.Marshal(configValue, configValue.Type())
if err != nil {
return ai, err
}
sensitivePaths = append(sensitivePaths, schema.ConfigSchema.SensitivePaths(unmarkedValue, nil)...)
cs := jsonstate.SensitiveAsBool(marks.MarkPaths(unmarkedValue, marks.Sensitive, sensitivePaths))
sensitive, err = ctyjson.Marshal(cs, cs.Type())
if err != nil {View on GitHub (pinned to d32a084675)