hashicorp/terraform · error

could not read state version outputs

Error message

could not read state version outputs: %w

What it means

Thrown by GetRootOutputValues when RetryBackoff returns a non-nil error that is neither context.DeadlineExceeded nor context.Canceled — i.e., a FatalError was encountered (the inner function returned NonRetryableError). The %w wraps the fatal inner error, which originates from StateVersionOutputs.ReadCurrent returning a non-'service unavailable' error.

Solutions

  1. Check the wrapped error for HTTP status: 401/403 means auth/permissions, 404 means the resource is gone
  2. Verify the authenticated identity has permission to read state version outputs on the workspace
  3. Confirm the workspace and its current state version still exist
  4. Retry the terraform command if the error appears transient (network blips producing unexpected error bodies)
Defensive patterns

Strategy: try-catch

Validate before calling

// Before calling GetRootOutputValues, verify read permissions for outputs:
ws, err := tfeClient.Workspaces.Read(ctx, organization, workspaceName)
if err != nil {
    return err
}
if ws.CurrentStateVersion == nil {
    return fmt.Errorf("no current state version; outputs may not be readable")
}

Try / catch

outputs, err := state.GetRootOutputValues(ctx)
if err != nil && strings.Contains(err.Error(), "could not read state version outputs") {
    // non-retryable (fatal) error from TFE — check auth/permissions
    return nil, fmt.Errorf("output read failed (likely auth/permissions): %w", err)
}
return outputs, err

Prevention

When it happens

Trigger: StateVersionOutputs.ReadCurrent returns a non-retryable error such as 401/403 (auth/permission), 404 (workspace or state version gone), or a malformed response; the error string does not contain 'service unavailable' so it is wrapped in NonRetryableError and RetryBackoff stops immediately.

Common situations: Expired or insufficient API token when reading outputs; workspace permissions changed to read-only for a role that cannot read state version outputs; workspace or state version deleted between the run and the output read; TFE API returning an unexpected error format.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/5bffe2461b34c2e1. Report an issue: GitHub.

Appendix: source

Thrown at internal/cloud/state.go:572

		so, err = s.tfeClient.StateVersionOutputs.ReadCurrent(ctx, s.workspace.ID)

		if err != nil {
			if strings.Contains(err.Error(), "service unavailable") {
				return err
			}
			return NonRetryableError{err}
		}
		return nil
	})

	if err != nil {
		switch err {
		case context.DeadlineExceeded:
			return nil, fmt.Errorf("current outputs were not ready to be read within the deadline. Please try again")
		case context.Canceled:
			return nil, fmt.Errorf("canceled reading current outputs")
		}
		return nil, fmt.Errorf("could not read state version outputs: %w", err)
	}

	result := make(map[string]*states.OutputValue)

	for _, output := range so.Items {
		if output.DetailedType == nil {
			// If there is no detailed type information available, this state was probably created
			// with a version of terraform < 1.3.0. In this case, we'll eject completely from this
			// function and fall back to the old behavior of reading the entire state file, which
			// requires a higher level of authorization.
			log.Printf("[DEBUG] falling back to reading full state")

			if err := s.RefreshState(); err != nil {
				return nil, fmt.Errorf("failed to load state: %w", err)
			}

			state := s.State()
			if state == nil {

View on GitHub (pinned to d32a084675)