hashicorp/terraform · error
Error loading encryption key
Error message
Error loading encryption key: %s
What it means
Thrown when the customer-supplied encryption_key value cannot be read by readPathOrContents. Like the credentials handling, the encryption_key accepts either a file path or inline content; this error means neither resolved to readable bytes.
Solutions
- Confirm the file exists at the configured path and is readable by the terraform process.
- Prefer an absolute path or a path relative to the terraform working directory.
- If passing the key inline, paste the base64 string directly as encryption_key.
- Restrict file permissions and store the key in a secret manager, then materialize it before running terraform.
Example fix
// before
backend "gcs" {
bucket = "tf-state"
encryption_key = "./keys/state.key" # missing
}
// after
backend "gcs" {
bucket = "tf-state"
encryption_key = "/abs/path/state.key"
} Defensive patterns
Strategy: validation
Validate before calling
key := /* config attr */ ""
if key != "" {
if _, err := readPathOrContents(key); err != nil {
return fmt.Errorf("encryption_key source is unreadable: %w", err)
}
} Prevention
- Store the encryption key in a secret manager and write it to a known absolute path before terraform runs.
- Verify the file's presence in a pre-flight CI step.
When it happens
Trigger: Configure sees a non-empty encryption_key; readPathOrContents(key) returns an error — missing file, permission denied, or unreadable path.
Common situations: encryption_key points to a key file that is gitignored and absent on this machine; relative path resolved from the wrong directory; the file was rotated and the old path removed.
Related errors
- Error decoding encryption key
- Error loading credentials
- impersonate_service_account_delegates elements must not be…
- the string provided in credentials is neither valid json…
- address argument is required
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/aed02b995e739bf2.
Report an issue: GitHub.
Appendix: source
Thrown at internal/backend/remote-state/gcs/backend.go:268
endpoint := option.WithEndpoint(storageEndpoint)
opts = append(opts, endpoint)
}
client, err := storage.NewClient(ctx, opts...)
if err != nil {
return backendbase.ErrorAsDiagnostics(
fmt.Errorf("storage.NewClient() failed: %v", err),
)
}
b.storageClient = client
// Customer-supplied encryption
key := data.String("encryption_key")
if key != "" {
kc, err := readPathOrContents(key)
if err != nil {
return backendbase.ErrorAsDiagnostics(
fmt.Errorf("Error loading encryption key: %s", err),
)
}
// The GCS client expects a customer supplied encryption key to be
// passed in as a 32 byte long byte slice. The byte slice is base64
// encoded before being passed to the API. We take a base64 encoded key
// to remain consistent with the GCS docs.
// https://cloud.google.com/storage/docs/encryption#customer-supplied
// https://github.com/GoogleCloudPlatform/google-cloud-go/blob/def681/storage/storage.go#L1181
k, err := base64.StdEncoding.DecodeString(kc)
if err != nil {
return backendbase.ErrorAsDiagnostics(
fmt.Errorf("Error decoding encryption key: %s", err),
)
}
b.encryptionKey = k
}
View on GitHub (pinned to d32a084675)