hashicorp/terraform · error

Error loading encryption key

Error message

Error loading encryption key: %s

What it means

Thrown when the customer-supplied encryption_key value cannot be read by readPathOrContents. Like the credentials handling, the encryption_key accepts either a file path or inline content; this error means neither resolved to readable bytes.

Solutions

  1. Confirm the file exists at the configured path and is readable by the terraform process.
  2. Prefer an absolute path or a path relative to the terraform working directory.
  3. If passing the key inline, paste the base64 string directly as encryption_key.
  4. Restrict file permissions and store the key in a secret manager, then materialize it before running terraform.

Example fix

// before
backend "gcs" {
  bucket        = "tf-state"
  encryption_key = "./keys/state.key"   # missing
}
// after
backend "gcs" {
  bucket        = "tf-state"
  encryption_key = "/abs/path/state.key"
}
Defensive patterns

Strategy: validation

Validate before calling

key := /* config attr */ ""
if key != "" {
    if _, err := readPathOrContents(key); err != nil {
        return fmt.Errorf("encryption_key source is unreadable: %w", err)
    }
}

Prevention

When it happens

Trigger: Configure sees a non-empty encryption_key; readPathOrContents(key) returns an error — missing file, permission denied, or unreadable path.

Common situations: encryption_key points to a key file that is gitignored and absent on this machine; relative path resolved from the wrong directory; the file was rotated and the old path removed.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/aed02b995e739bf2. Report an issue: GitHub.

Appendix: source

Thrown at internal/backend/remote-state/gcs/backend.go:268

		endpoint := option.WithEndpoint(storageEndpoint)
		opts = append(opts, endpoint)
	}
	client, err := storage.NewClient(ctx, opts...)
	if err != nil {
		return backendbase.ErrorAsDiagnostics(
			fmt.Errorf("storage.NewClient() failed: %v", err),
		)
	}

	b.storageClient = client

	// Customer-supplied encryption
	key := data.String("encryption_key")
	if key != "" {
		kc, err := readPathOrContents(key)
		if err != nil {
			return backendbase.ErrorAsDiagnostics(
				fmt.Errorf("Error loading encryption key: %s", err),
			)
		}

		// The GCS client expects a customer supplied encryption key to be
		// passed in as a 32 byte long byte slice. The byte slice is base64
		// encoded before being passed to the API. We take a base64 encoded key
		// to remain consistent with the GCS docs.
		// https://cloud.google.com/storage/docs/encryption#customer-supplied
		// https://github.com/GoogleCloudPlatform/google-cloud-go/blob/def681/storage/storage.go#L1181
		k, err := base64.StdEncoding.DecodeString(kc)
		if err != nil {
			return backendbase.ErrorAsDiagnostics(
				fmt.Errorf("Error decoding encryption key: %s", err),
			)
		}
		b.encryptionKey = k
	}

View on GitHub (pinned to d32a084675)