hashicorp/terraform · warning

Error checking latest version

Error message

Error checking latest version: %s

What it means

Thrown by the `terraform version` command after the optional version-check function (c.CheckFunc, typically the HashiCorp Checkpoint service) returns a non-nil error. The command does NOT abort: the error is appended to diagnostics, the version banner still prints, and the command returns exit code 0. It is purely informational — the latest-version probe failed, not the version command itself.

Solutions

  1. Ignore it — the command still succeeds (exit 0); the only effect is no 'outdated' banner.
  2. If the noise is unwanted, set CHECKPOINT_DISABLE=1 (or disable checkpoint in config) so CheckFunc short-circuits before any network call.
  3. Restore network egress to the checkpoint service (e.g. checkpoint.hashicorp.com) and retry.
  4. If using a custom CheckFunc, ensure it returns (nil, nil) on soft failure instead of an error.

Example fix

// before
info, err := c.CheckFunc()
if err != nil {
    diags = diags.Append(fmt.Errorf("\nError checking latest version: %s", err))
}

// after — treat checkpoint errors as soft, keep running
if info, err := c.CheckFunc(); err == nil && info != nil && info.Outdated {
    latest, outdated = info.Latest, true
}
Defensive patterns

Strategy: try-catch

Validate before calling

// pre-flight: only set CheckFunc when checkpoint is enabled and network is up
if !checkpointDisabled() && hostReachable("checkpoint.hashicorp.com") {
    c.CheckFunc = buildCheckFunc()
}

Try / catch

info, err := c.CheckFunc()
if err != nil {
    // log at debug, do not surface to user-facing diags
    log.Printf("[DEBUG] version check skipped: %v", err)
} else if info != nil && info.Outdated {
    latest, outdated = info.Latest, true
}

Prevention

When it happens

Trigger: Invoking `terraform version` (or any path that runs VersionCommand.Run with CheckFunc set) when the checkpoint endpoint is unreachable, the response is malformed, or CheckFunc was wired to a custom function that itself returned an error.

Common situations: Air-gapped / offline host, corporate proxy blocking checkpoint.hashicorp.com, DNS failure, expired/clock-skewed TLS, or CHECKPOINT_DISABLE tripping a custom build that still defines CheckFunc but errors when the service is absent.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/46d83b4d389c95a2. Report an issue: GitHub.

Appendix: source

Thrown at internal/command/version.go:104

	// since the most recent change to dependencies.
	//
	// Generally-speaking this is a best-effort thing that will give us a good
	// result in the usual case where the user successfully ran "terraform init"
	// and then hit a problem running _another_ command.
	var providerLocks map[addrs.Provider]*depsfile.ProviderLock
	if locks, err := c.lockedDependencies(); err == nil {
		providerLocks = locks.AllProviders()
	}

	// If we have a version check function, then let's check for
	// the latest version as well.
	var latest string
	var outdated bool
	if c.CheckFunc != nil {
		// Check the latest version
		info, err := c.CheckFunc()
		if err != nil {
			diags = diags.Append(fmt.Errorf(
				"\nError checking latest version: %s", err))
		}
		if info.Outdated {
			latest = info.Latest
			outdated = true
		}
	}

	// Format and print output
	view.LogVersion(version, platform, providerLocks, outdated, latest, diags)

	return 0
}

func (c *VersionCommand) Synopsis() string {
	return "Show the current Terraform version"
}

View on GitHub (pinned to d32a084675)