hashicorp/terraform · error
could not read state version output
Error message
could not read state version output %s: %w
What it means
Thrown by GetRootOutputValues when iterating outputs and a sensitive output's value must be fetched individually via StateVersionOutputs.Read(ctx, output.ID) but that API call fails. Sensitive outputs are not included in the bulk read for security reasons and require a separate authorized fetch. The %w wraps the TFE client error and includes the output ID.
Solutions
- Verify the authenticated identity has permission to read sensitive state version outputs on the workspace
- Retry the operation if the error looks transient (network/server error on a single output)
- Check whether the output ID still exists in the state version outputs list (use the TFE API or UI)
Defensive patterns
Strategy: validation
Validate before calling
// Before reading outputs, verify the identity can read sensitive outputs:
// Check workspace permissions include state-version-output read with sensitive access.
ws, err := tfeClient.Workspaces.Read(ctx, organization, workspaceName)
if err != nil {
return err
}
// TFE does not expose granular sensitive-output permission via the workspace object,
// so attempt a probe read if sensitive outputs exist. Try / catch
outputs, err := state.GetRootOutputValues(ctx)
if err != nil && strings.Contains(err.Error(), "could not read state version output") {
// a specific sensitive output read failed; check permissions or retry
return nil, fmt.Errorf("failed to read a sensitive output (check permissions): %w", err)
}
return outputs, err Prevention
- Ensure the CI/service account has permission to read sensitive state version outputs, not just regular outputs
- Minimize the number of sensitive outputs to reduce the blast radius of permission gaps
- Audit workspace RBAC when adding new sensitive outputs to ensure the automation identity can read them
When it happens
Trigger: The authenticated user/team has permission to read outputs generally but not to read sensitive output values specifically; network failure during the individual sensitive-output HTTP GET; the sensitive output's state version output record was deleted between the bulk read and the individual read; TFE server error on the specific output read.
Common situations: RBAC configuration that grants read but not sensitive-output-read; CI token scoped too narrowly for a workspace with sensitive outputs; transient TFE instability affecting a single API call within a batch.
Related errors
- could not read state version outputs
- canceled reading current outputs
- could not decode output
- could not interpret output
- could not interpret value
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/9213e71ae39339f2.
Report an issue: GitHub.
Appendix: source
Thrown at internal/cloud/state.go:605
}
state := s.State()
if state == nil {
// We know that there is supposed to be state (and this is not simply a new workspace
// without state) because the fallback is only invoked when outputs are present but
// detailed types are not available.
return nil, ErrStateVersionUnauthorizedUpgradeState
}
return state.RootOutputValues, nil
}
if output.Sensitive {
// Since this is a sensitive value, the output must be requested explicitly in order to
// read its value, which is assumed to be present by callers
sensitiveOutput, err := s.tfeClient.StateVersionOutputs.Read(ctx, output.ID)
if err != nil {
return nil, fmt.Errorf("could not read state version output %s: %w", output.ID, err)
}
output.Value = sensitiveOutput.Value
}
cval, err := tfeOutputToCtyValue(*output)
if err != nil {
return nil, fmt.Errorf("could not decode output %s (ID %s)", output.Name, output.ID)
}
result[output.Name] = &states.OutputValue{
Value: cval,
Sensitive: output.Sensitive,
}
}
return result, nil
}
View on GitHub (pinned to d32a084675)