hashicorp/terraform · error

argument is required

Error message

argument %q is required

What it means

Thrown by SDKLikeDefaults.ApplyTo while filling environment-variable defaults into a backend config object. It fires for an attribute whose SDKLikeDefault has Required=true when, after checking the config value, every EnvVars entry, and the Fallback string, the value is still empty. This is the schema-driven counterpart of error 120 and is what end users see most often from built-in backends.

Solutions

  1. Add the missing required argument to the backend block (the attrName in the error message names it).
  2. Export the env var listed in that attribute's EnvVars (consult the backend's backend.go schema definition for the exact names).
  3. If authoring a backend, double-check that EnvVars in the SDKLikeDefault match the documented env var names and that Fallback is intentionally empty.
  4. Run terraform init -reconfigure after fixing config so the cached backend config is rebuilt.

Example fix

// before
backend "consul" {
  path = "tf/lock"
}
// error: argument "address" is required  -> after
backend "consul" {
  address = "127.0.0.1:8500"
  path    = "tf/lock"
}
Defensive patterns

Strategy: validation

Validate before calling

// Inspect the schema's SDKLikeDefaults before ApplyTo to pre-flight required attrs.
func missingRequired(base cty.Value, defs backendbase.SDKLikeDefaults) []string {
    var missing []string
    for name, d := range defs {
        if !d.Required { continue }
        v := base.GetAttr(name)
        if !v.IsNull() && v.AsString() != "" { continue }
        set := false
        for _, e := range d.EnvVars { if os.Getenv(e) != "" { set = true; break } }
        if !set && d.Fallback == "" { missing = append(missing, name) }
    }
    return missing
}

Type guard

null

Try / catch

v, err := b.SDKLikeDefaults.ApplyTo(config)
if err != nil {
    // err already names the attr; surface it to the user verbatim.
    return v, diags.Append(err)
}

Prevention

When it happens

Trigger: ApplyTo iterates base.Type().AttributeTypes(); for an attrName with defs.Required==true, rawStr stays "" because: givenVal is null/empty, none of defs.EnvVars is set in the environment, and defs.Fallback is empty (as required for Required attributes).

Common situations: A required backend argument is omitted from both the HCL backend block and the environment. Examples: consul backend missing address, s3 backend missing bucket, gcs backend missing bucket with no GOOGLE_* env. Also triggered by a typo in the env var name so it never resolves.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/1f7bce47693cbca3. Report an issue: GitHub.

Appendix: source

Thrown at internal/backend/backendbase/sdklike.go:227

		rawStr := ""
		if !vStr.IsNull() {
			rawStr = vStr.AsString()
		}

		if rawStr == "" {
			for _, envName := range defs.EnvVars {
				rawStr = os.Getenv(envName)
				if rawStr != "" {
					break
				}
			}
		}
		if rawStr == "" {
			rawStr = defs.Fallback
		}
		if defs.Required && rawStr == "" {
			return cty.NilVal, fmt.Errorf("argument %q is required", attrName)
		}

		// As a special case, if we still have an empty string and the original
		// value was null then we'll preserve the null. This is a compromise,
		// assuming that SDKLikeData knows how to treat a null value as a
		// zero value anyway and if we preserve the null then the recipient
		// of this result can still use the cty.Value result directly to
		// distinguish between the value being set explicitly to empty in
		// the config vs. being entirely unset.
		if rawStr == "" && givenVal.IsNull() {
			retAttrs[attrName] = givenVal
			continue
		}

		// By the time we get here, rawStr should be empty only if the original
		// value was unset and all of the fallback environment variables were
		// also unset. Otherwise, rawStr contains a string representation of
		// a value that we now need to convert back to the type that was

View on GitHub (pinned to d32a084675)