hashicorp/terraform · error
can not get from Terraform backend configuration
Error message
can not get %s from Terraform backend configuration
What it means
Thrown by the OCI auth config provider's accessor methods (TenancyOCID, UserOCID, KeyFingerprint, etc.) when the corresponding attribute was not set in the backend configuration (auth.go:91-110). The %s is the attribute name constant (e.g., 'tenancy_ocid'). These methods implement the OCI SDK's ConfigurationProvider interface and are called lazily when the SDK needs each credential piece.
Solutions
- Provide all required API-key attributes in the backend block: tenancy_ocid, user_ocid, fingerprint, and either private_key or private_key_path (plus private_key_password if the key is encrypted).
- Match attribute names exactly to the schema (e.g., tenancy_ocid, not tenancyId).
- If running on an OCI instance, use auth='instance_principal' instead of supplying API-key fields.
- If using a config file profile, set auth='config_file_profile' with config_file_profile name rather than individual attributes.
Example fix
// before
terraform {
backend "oci" {
auth = "api_key"
tenancy_ocid = "ocid1.tenancy.oc1..aaa"
# user_ocid, fingerprint, key missing
}
}
// after
terraform {
backend "oci" {
auth = "api_key"
tenancy_ocid = "ocid1.tenancy.oc1..aaa"
user_ocid = "ocid1.user.oc1..aaa"
fingerprint = "aa:bb:cc:..."
private_key_path = "/path/to/key.pem"
private_key_password = "passphrase"
}
} Defensive patterns
Strategy: validation
Validate before calling
// Validate all required API-key attributes are set before init:
// required := []string{tenancyOcid, userOcid, fingerprint, privateKeyOrPath}
// for _, v := range required { if v == "" { return fmt.Errorf("missing OCI backend attr") } } Try / catch
// _, err := provider.TenancyOCID()
// if err != nil && strings.Contains(err.Error(), "can not get") {
// // missing attribute; surface which one and add to backend block
// } Prevention
- When auth=api_key, always set tenancy_ocid, user_ocid, fingerprint, and a private key (path or value).
- Use auth=instance_principal on OCI compute instances to avoid API-key sprawl.
- Use auth=config_file_profile to reference an existing OCI config profile instead of repeating attributes.
When it happens
Trigger: The OCI backend is configured with auth=api_key but omits one or more required attributes (tenancy_ocid, user_ocid, fingerprint, private_key/private_key_path). When the SDK requests the missing value during signing, the accessor returns this error.
Common situations: Switching auth mode to api_key without providing all five API-key attributes; typo in an attribute name so it is not read; relying on env vars that the backend does not consume (the OCI backend reads from its own block, not OCI_* env vars, for these fields); partial config left over from an instance-principal setup.
Related errors
- cannot create temporary file to update credentials
- cannot read
- credentials file has invalid value for "credentials"…
- Failed to configure
- failed to determine request credentials
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/6d5ffd8a7ac9e6db.
Report an issue: GitHub.
Appendix: source
Thrown at internal/backend/remote-state/oci/auth.go:95
p.privateKeyPassword = privateKeyPasswordVal.AsString()
}
return p
}
func (p ociAuthConfigProvider) AuthType() (common.AuthConfig, error) {
return common.AuthConfig{
AuthType: common.UnknownAuthenticationType,
IsFromConfigFile: false,
OboToken: nil,
},
fmt.Errorf("unsupported, keep the interface")
}
func (p ociAuthConfigProvider) TenancyOCID() (string, error) {
if p.tenancyOcid != "" {
return p.tenancyOcid, nil
}
return "", fmt.Errorf("can not get %s from Terraform backend configuration", TenancyOcidAttrName)
}
func (p ociAuthConfigProvider) UserOCID() (string, error) {
if p.userOcid != "" {
return p.userOcid, nil
}
return "", fmt.Errorf("can not get %s from Terraform backend configuration", UserOcidAttrName)
}
func (p ociAuthConfigProvider) KeyFingerprint() (string, error) {
if p.fingerprint != "" {
return p.fingerprint, nil
}
return "", fmt.Errorf("can not get %s from Terraform backend configuration", FingerprintAttrName)
}
func (p ociAuthConfigProvider) Region() (string, error) {
if p.region != "" {View on GitHub (pinned to d32a084675)