hashicorp/terraform · error
can't delete default state
Error message
can't delete default state
What it means
Same protection as the inmem backend, but for the Kubernetes backend: DeleteWorkspace rejects name == backend.DefaultStateName ("default") or empty (backend_state.go:71-75). The default workspace's state Secret/Lease must not be deleted via workspace deletion.
Solutions
- Skip the default workspace in any deletion loop.
- To remove backend state entirely, delete the Kubernetes Secrets/Leases manually (kubectl delete secret -l tfstate/terraform=true) after switching the backend.
- Switch to another workspace before operating on workspace lifecycle.
Defensive patterns
Strategy: validation
Validate before calling
// Guard workspace deletion for the k8s backend too:
// if name == backend.DefaultStateName || name == "" { return nil }
// b.DeleteWorkspace(name, force) Try / catch
// diags := b.DeleteWorkspace(name, force)
// for _, d := range diags {
// if strings.Contains(d.Description().Summary, "can't delete default state") { /* skip */ }
// } Prevention
- Exclude 'default' from any workspace-deletion automation.
- To fully remove k8s backend state, delete the labeled Secrets/Leases with kubectl after switching backends.
- Document that the default workspace is undeletable by design.
When it happens
Trigger: Running 'terraform workspace delete default' against a kubernetes backend, or a workspace-management script that attempts to delete the default workspace.
Common situations: Bulk workspace cleanup scripts; CI that deletes all workspaces at end of run; migrating away from the backend by deleting workspaces one by one and hitting 'default'.
Related errors
- can't delete default state
- can't delete default state
- can't delete default state
- can't delete default state
- can't delete default state
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/8eb555a29f461e66.
Report an issue: GitHub.
Appendix: source
Thrown at internal/backend/remote-state/kubernetes/backend_state.go:73
// Make sure it isn't default and the key matches
if ws != backend.DefaultStateName && key == b.nameSuffix {
m[ws] = struct{}{}
}
}
states := []string{backend.DefaultStateName}
for k := range m {
states = append(states, k)
}
sort.Strings(states[1:])
return states, diags
}
func (b *Backend) DeleteWorkspace(name string, _ bool) tfdiags.Diagnostics {
var diags tfdiags.Diagnostics
if name == backend.DefaultStateName || name == "" {
return diags.Append(fmt.Errorf("can't delete default state"))
}
client, err := b.remoteClient(name)
if err != nil {
return diags.Append(err)
}
return diags.Append(client.Delete())
}
func (b *Backend) StateMgr(name string) (statemgr.Full, tfdiags.Diagnostics) {
var diags tfdiags.Diagnostics
c, err := b.remoteClient(name)
if err != nil {
return nil, diags.Append(err)
}
View on GitHub (pinned to d32a084675)