hashicorp/terraform · error

can't delete default state

Error message

can't delete default state

What it means

Same protection as the inmem backend, but for the Kubernetes backend: DeleteWorkspace rejects name == backend.DefaultStateName ("default") or empty (backend_state.go:71-75). The default workspace's state Secret/Lease must not be deleted via workspace deletion.

Solutions

  1. Skip the default workspace in any deletion loop.
  2. To remove backend state entirely, delete the Kubernetes Secrets/Leases manually (kubectl delete secret -l tfstate/terraform=true) after switching the backend.
  3. Switch to another workspace before operating on workspace lifecycle.
Defensive patterns

Strategy: validation

Validate before calling

// Guard workspace deletion for the k8s backend too:
// if name == backend.DefaultStateName || name == "" { return nil }
// b.DeleteWorkspace(name, force)

Try / catch

// diags := b.DeleteWorkspace(name, force)
// for _, d := range diags {
//   if strings.Contains(d.Description().Summary, "can't delete default state") { /* skip */ }
// }

Prevention

When it happens

Trigger: Running 'terraform workspace delete default' against a kubernetes backend, or a workspace-management script that attempts to delete the default workspace.

Common situations: Bulk workspace cleanup scripts; CI that deletes all workspaces at end of run; migrating away from the backend by deleting workspaces one by one and hitting 'default'.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/8eb555a29f461e66. Report an issue: GitHub.

Appendix: source

Thrown at internal/backend/remote-state/kubernetes/backend_state.go:73

		// Make sure it isn't default and the key matches
		if ws != backend.DefaultStateName && key == b.nameSuffix {
			m[ws] = struct{}{}
		}
	}

	states := []string{backend.DefaultStateName}
	for k := range m {
		states = append(states, k)
	}

	sort.Strings(states[1:])
	return states, diags
}

func (b *Backend) DeleteWorkspace(name string, _ bool) tfdiags.Diagnostics {
	var diags tfdiags.Diagnostics
	if name == backend.DefaultStateName || name == "" {
		return diags.Append(fmt.Errorf("can't delete default state"))
	}

	client, err := b.remoteClient(name)
	if err != nil {
		return diags.Append(err)
	}

	return diags.Append(client.Delete())
}

func (b *Backend) StateMgr(name string) (statemgr.Full, tfdiags.Diagnostics) {
	var diags tfdiags.Diagnostics

	c, err := b.remoteClient(name)
	if err != nil {
		return nil, diags.Append(err)
	}

View on GitHub (pinned to d32a084675)