hashicorp/terraform · error

couldn't read information for cloud run

Error message

couldn't read information for cloud run %s; make sure you've run `terraform login` and that you have permission to view the run

What it means

Thrown by Cloud.ShowPlanForRun when b.client.Runs.ReadWithOptions returns exactly tfe.ErrResourceNotFound. The TFE API could not find the run ID, which most commonly means the request is unauthenticated or the caller lacks permission — TFE returns 404 rather than 403 for hidden resources. The message prompts `terraform login` and permission verification.

Solutions

  1. Run `terraform login` and authenticate against the correct hostname.
  2. Verify the run ID is correct and belongs to a workspace your team can view.
  3. Confirm the token's team has 'Runs: Read' permission on the workspace.
  4. Check that the run was not discarded/deleted in the HCP Terraform UI.
Defensive patterns

Strategy: validation

Validate before calling

// Ensure a token exists and the run is viewable before show.
if b.Token == "" {
    return errors.New("no token; run `terraform login`")
}

Try / catch

r, err := b.client.Runs.ReadWithOptions(ctx, runID, opts)
if err == tfe.ErrResourceNotFound {
    // prompt login / check permissions, do not retry blindly
}

Prevention

When it happens

Trigger: ShowPlanForRun is given a runID whose run is invisible to the current token: either no token (no `terraform login`), a token for a different org/user, or a token whose team cannot view the run. The API returns 404 → ErrResourceNotFound.

Common situations: Forgetting to `terraform login` before `terraform show`; using a token from a different org than the run; the run was deleted or belongs to a workspace the team has no access to; cross-org plan viewing.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/9b0b22ed32b1a040. Report an issue: GitHub.

Appendix: source

Thrown at internal/cloud/backend_show.go:34

// ShowPlanForRun downloads the JSON plan output for the specified cloud run
// (either the redacted or unredacted format, per the caller's request), and
// returns it in a cloudplan.RemotePlanJSON wrapper struct (along with various
// metadata required by terraform show). It's intended for use by the terraform
// show command, in order to format and display a saved cloud plan.
func (b *Cloud) ShowPlanForRun(ctx context.Context, runID, runHostname string, redacted bool) (*cloudplan.RemotePlanJSON, error) {
	var jsonBytes []byte
	mode := plans.NormalMode
	var opts []plans.Quality

	// Bail early if wrong hostname
	if runHostname != b.Hostname {
		return nil, fmt.Errorf("hostname for run (%s) does not match the configured cloud integration (%s)", runHostname, b.Hostname)
	}

	// Get run and plan
	r, err := b.client.Runs.ReadWithOptions(ctx, runID, &tfe.RunReadOptions{Include: []tfe.RunIncludeOpt{tfe.RunPlan, tfe.RunWorkspace}})
	if err == tfe.ErrResourceNotFound {
		return nil, fmt.Errorf("couldn't read information for cloud run %s; make sure you've run `terraform login` and that you have permission to view the run", runID)
	} else if err != nil {
		return nil, fmt.Errorf("couldn't read information for cloud run %s: %w", runID, err)
	}

	// Sort out the run mode
	if r.IsDestroy {
		mode = plans.DestroyMode
	} else if r.RefreshOnly {
		mode = plans.RefreshOnlyMode
	}

	// Check that the plan actually finished
	switch r.Plan.Status {
	case tfe.PlanErrored:
		// Errored plans might still be displayable, but we want to mention it to the renderer.
		opts = append(opts, plans.Errored)
	case tfe.PlanFinished:
		// Good to go, but alert the renderer if it has no changes.

View on GitHub (pinned to d32a084675)