hashicorp/terraform · error

could not read state version output

Error message

could not read state version output %s: %w

What it means

Thrown by GetRootOutputValues when iterating outputs and a sensitive output's value must be fetched individually via StateVersionOutputs.Read(ctx, output.ID) but that API call fails. Sensitive outputs are not included in the bulk read for security reasons and require a separate authorized fetch. The %w wraps the TFE client error and includes the output ID.

Solutions

  1. Verify the authenticated identity has permission to read sensitive state version outputs on the workspace
  2. Retry the operation if the error looks transient (network/server error on a single output)
  3. Check whether the output ID still exists in the state version outputs list (use the TFE API or UI)
Defensive patterns

Strategy: validation

Validate before calling

// Before reading outputs, verify the identity can read sensitive outputs:
// Check workspace permissions include state-version-output read with sensitive access.
ws, err := tfeClient.Workspaces.Read(ctx, organization, workspaceName)
if err != nil {
    return err
}
// TFE does not expose granular sensitive-output permission via the workspace object,
// so attempt a probe read if sensitive outputs exist.

Try / catch

outputs, err := state.GetRootOutputValues(ctx)
if err != nil && strings.Contains(err.Error(), "could not read state version output") {
    // a specific sensitive output read failed; check permissions or retry
    return nil, fmt.Errorf("failed to read a sensitive output (check permissions): %w", err)
}
return outputs, err

Prevention

When it happens

Trigger: The authenticated user/team has permission to read outputs generally but not to read sensitive output values specifically; network failure during the individual sensitive-output HTTP GET; the sensitive output's state version output record was deleted between the bulk read and the individual read; TFE server error on the specific output read.

Common situations: RBAC configuration that grants read but not sensitive-output-read; CI token scoped too narrowly for a workspace with sensitive outputs; transient TFE instability affecting a single API call within a batch.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/9213e71ae39339f2. Report an issue: GitHub.

Appendix: source

Thrown at internal/cloud/state.go:605

			}

			state := s.State()
			if state == nil {
				// We know that there is supposed to be state (and this is not simply a new workspace
				// without state) because the fallback is only invoked when outputs are present but
				// detailed types are not available.
				return nil, ErrStateVersionUnauthorizedUpgradeState
			}

			return state.RootOutputValues, nil
		}

		if output.Sensitive {
			// Since this is a sensitive value, the output must be requested explicitly in order to
			// read its value, which is assumed to be present by callers
			sensitiveOutput, err := s.tfeClient.StateVersionOutputs.Read(ctx, output.ID)
			if err != nil {
				return nil, fmt.Errorf("could not read state version output %s: %w", output.ID, err)
			}
			output.Value = sensitiveOutput.Value
		}

		cval, err := tfeOutputToCtyValue(*output)
		if err != nil {
			return nil, fmt.Errorf("could not decode output %s (ID %s)", output.Name, output.ID)
		}

		result[output.Name] = &states.OutputValue{
			Value:     cval,
			Sensitive: output.Sensitive,
		}
	}

	return result, nil
}

View on GitHub (pinned to d32a084675)