hashicorp/terraform · error

can not get from Terraform backend configuration

Error message

can not get %s from Terraform backend configuration

What it means

Thrown by the OCI auth config provider's accessor methods (TenancyOCID, UserOCID, KeyFingerprint, etc.) when the corresponding attribute was not set in the backend configuration (auth.go:91-110). The %s is the attribute name constant (e.g., 'tenancy_ocid'). These methods implement the OCI SDK's ConfigurationProvider interface and are called lazily when the SDK needs each credential piece.

Solutions

  1. Provide all required API-key attributes in the backend block: tenancy_ocid, user_ocid, fingerprint, and either private_key or private_key_path (plus private_key_password if the key is encrypted).
  2. Match attribute names exactly to the schema (e.g., tenancy_ocid, not tenancyId).
  3. If running on an OCI instance, use auth='instance_principal' instead of supplying API-key fields.
  4. If using a config file profile, set auth='config_file_profile' with config_file_profile name rather than individual attributes.

Example fix

// before
terraform {
  backend "oci" {
    auth         = "api_key"
    tenancy_ocid = "ocid1.tenancy.oc1..aaa"
    # user_ocid, fingerprint, key missing
  }
}
// after
terraform {
  backend "oci" {
    auth                 = "api_key"
    tenancy_ocid         = "ocid1.tenancy.oc1..aaa"
    user_ocid            = "ocid1.user.oc1..aaa"
    fingerprint          = "aa:bb:cc:..."
    private_key_path     = "/path/to/key.pem"
    private_key_password = "passphrase"
  }
}
Defensive patterns

Strategy: validation

Validate before calling

// Validate all required API-key attributes are set before init:
// required := []string{tenancyOcid, userOcid, fingerprint, privateKeyOrPath}
// for _, v := range required { if v == "" { return fmt.Errorf("missing OCI backend attr") } }

Try / catch

// _, err := provider.TenancyOCID()
// if err != nil && strings.Contains(err.Error(), "can not get") {
//   // missing attribute; surface which one and add to backend block
// }

Prevention

When it happens

Trigger: The OCI backend is configured with auth=api_key but omits one or more required attributes (tenancy_ocid, user_ocid, fingerprint, private_key/private_key_path). When the SDK requests the missing value during signing, the accessor returns this error.

Common situations: Switching auth mode to api_key without providing all five API-key attributes; typo in an attribute name so it is not read; relying on env vars that the backend does not consume (the OCI backend reads from its own block, not OCI_* env vars, for these fields); partial config left over from an instance-principal setup.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/6d5ffd8a7ac9e6db. Report an issue: GitHub.

Appendix: source

Thrown at internal/backend/remote-state/oci/auth.go:95

		p.privateKeyPassword = privateKeyPasswordVal.AsString()
	}

	return p
}
func (p ociAuthConfigProvider) AuthType() (common.AuthConfig, error) {
	return common.AuthConfig{
			AuthType:         common.UnknownAuthenticationType,
			IsFromConfigFile: false,
			OboToken:         nil,
		},
		fmt.Errorf("unsupported, keep the interface")
}

func (p ociAuthConfigProvider) TenancyOCID() (string, error) {
	if p.tenancyOcid != "" {
		return p.tenancyOcid, nil
	}
	return "", fmt.Errorf("can not get %s from Terraform backend configuration", TenancyOcidAttrName)
}

func (p ociAuthConfigProvider) UserOCID() (string, error) {
	if p.userOcid != "" {
		return p.userOcid, nil
	}
	return "", fmt.Errorf("can not get %s from Terraform backend configuration", UserOcidAttrName)
}

func (p ociAuthConfigProvider) KeyFingerprint() (string, error) {
	if p.fingerprint != "" {
		return p.fingerprint, nil
	}
	return "", fmt.Errorf("can not get %s from Terraform backend configuration", FingerprintAttrName)
}

func (p ociAuthConfigProvider) Region() (string, error) {
	if p.region != "" {

View on GitHub (pinned to d32a084675)