hashicorp/terraform · error

couldn't read plan data for cloud run

Error message

couldn't read plan data for cloud run %s; make sure you've run `terraform login` and that you have permission to view the run

What it means

Thrown by Cloud.ShowPlanForRun when readRedactedPlan returns tfe.ErrResourceNotFound while requesting the redacted plan JSON. The redacted (safe-to-share) plan output endpoint returned 404, meaning the caller cannot view the plan — typically an auth or permission gap on the run.

Solutions

  1. Run `terraform login` against the correct hostname.
  2. Ensure the token's team has read access to plan outputs on the workspace.
  3. Retry once authenticated; if still 404, the plan output may be unavailable — request an unredacted view if you have admin access.
Defensive patterns

Strategy: validation

Validate before calling

// Confirm token has plan-output read before show.
if b.Token == "" { return errors.New("run `terraform login` first") }

Try / catch

jsonBytes, err = readRedactedPlan(ctx, baseURL, b.Token, planID)
if err == tfe.ErrResourceNotFound {
    // prompt login / permissions; consider unredacted if admin
}

Prevention

When it happens

Trigger: redacted=true path (the default `terraform show` of a cloud plan); readRedactedPlan hits the redacted-plan-output URL and gets 404. The token lacks read access to the plan output, or is absent entirely.

Common situations: Token not logged in; token's team lacks 'Plan Outputs: Read'; the plan output was garbage-collected or never generated (e.g. an empty/alien plan).

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/7fedd4ebb1e28a7f. Report an issue: GitHub.

Appendix: source

Thrown at internal/cloud/backend_show.go:70

		// Good to go, but alert the renderer if it has no changes.
		if !r.Plan.HasChanges {
			opts = append(opts, plans.NoChanges)
		}
	default:
		// Bail, we can't use this.
		err = fmt.Errorf("can't display a cloud plan that is currently %s", r.Plan.Status)
		return nil, err
	}

	// Fetch the json plan!
	if redacted {
		jsonBytes, err = readRedactedPlan(ctx, b.client.BaseURL(), b.Token, r.Plan.ID)
	} else {
		jsonBytes, err = b.client.Plans.ReadJSONOutput(ctx, r.Plan.ID)
	}
	if err == tfe.ErrResourceNotFound {
		if redacted {
			return nil, fmt.Errorf("couldn't read plan data for cloud run %s; make sure you've run `terraform login` and that you have permission to view the run", runID)
		} else {
			return nil, fmt.Errorf("couldn't read unredacted JSON plan data for cloud run %s; make sure you've run `terraform login` and that you have admin permissions on the workspace", runID)
		}
	} else if err != nil {
		return nil, fmt.Errorf("couldn't read plan data for cloud run %s: %w", runID, err)
	}

	// Format a run header and footer
	header := strings.TrimSpace(fmt.Sprintf(runHeader, b.Hostname, b.Organization, r.Workspace.Name, r.ID))
	footer := strings.TrimSpace(statusFooter(r.Status, r.Actions.IsConfirmable, r.Workspace.Locked))

	out := &cloudplan.RemotePlanJSON{
		JSONBytes: jsonBytes,
		Redacted:  redacted,
		Mode:      mode,
		Qualities: opts,
		RunHeader: header,
		RunFooter: footer,

View on GitHub (pinned to d32a084675)