hashicorp/terraform · error
could not read state version outputs
Error message
could not read state version outputs: %w
What it means
Thrown by GetRootOutputValues when RetryBackoff returns a non-nil error that is neither context.DeadlineExceeded nor context.Canceled — i.e., a FatalError was encountered (the inner function returned NonRetryableError). The %w wraps the fatal inner error, which originates from StateVersionOutputs.ReadCurrent returning a non-'service unavailable' error.
Solutions
- Check the wrapped error for HTTP status: 401/403 means auth/permissions, 404 means the resource is gone
- Verify the authenticated identity has permission to read state version outputs on the workspace
- Confirm the workspace and its current state version still exist
- Retry the terraform command if the error appears transient (network blips producing unexpected error bodies)
Defensive patterns
Strategy: try-catch
Validate before calling
// Before calling GetRootOutputValues, verify read permissions for outputs:
ws, err := tfeClient.Workspaces.Read(ctx, organization, workspaceName)
if err != nil {
return err
}
if ws.CurrentStateVersion == nil {
return fmt.Errorf("no current state version; outputs may not be readable")
} Try / catch
outputs, err := state.GetRootOutputValues(ctx)
if err != nil && strings.Contains(err.Error(), "could not read state version outputs") {
// non-retryable (fatal) error from TFE — check auth/permissions
return nil, fmt.Errorf("output read failed (likely auth/permissions): %w", err)
}
return outputs, err Prevention
- Ensure the CI/service account token has state-version-output read permission
- Do not change workspace permissions mid-operation
- Verify the workspace and current state version exist before reading outputs
When it happens
Trigger: StateVersionOutputs.ReadCurrent returns a non-retryable error such as 401/403 (auth/permission), 404 (workspace or state version gone), or a malformed response; the error string does not contain 'service unavailable' so it is wrapped in NonRetryableError and RetryBackoff stops immediately.
Common situations: Expired or insufficient API token when reading outputs; workspace permissions changed to read-only for a role that cannot read state version outputs; workspace or state version deleted between the run and the output read; TFE API returning an unexpected error format.
Related errors
- could not read state version output
- current outputs were not ready to be read within the…
- canceled reading current outputs
- could not decode output
- could not interpret output
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/5bffe2461b34c2e1.
Report an issue: GitHub.
Appendix: source
Thrown at internal/cloud/state.go:572
so, err = s.tfeClient.StateVersionOutputs.ReadCurrent(ctx, s.workspace.ID)
if err != nil {
if strings.Contains(err.Error(), "service unavailable") {
return err
}
return NonRetryableError{err}
}
return nil
})
if err != nil {
switch err {
case context.DeadlineExceeded:
return nil, fmt.Errorf("current outputs were not ready to be read within the deadline. Please try again")
case context.Canceled:
return nil, fmt.Errorf("canceled reading current outputs")
}
return nil, fmt.Errorf("could not read state version outputs: %w", err)
}
result := make(map[string]*states.OutputValue)
for _, output := range so.Items {
if output.DetailedType == nil {
// If there is no detailed type information available, this state was probably created
// with a version of terraform < 1.3.0. In this case, we'll eject completely from this
// function and fall back to the old behavior of reading the entire state file, which
// requires a higher level of authorization.
log.Printf("[DEBUG] falling back to reading full state")
if err := s.RefreshState(); err != nil {
return nil, fmt.Errorf("failed to load state: %w", err)
}
state := s.State()
if state == nil {View on GitHub (pinned to d32a084675)