hashicorp/terraform · error
Failed to get existing workspaces
Error message
Failed to get existing workspaces: %s
What it means
Returned from `Meta.selectWorkspace` when `b.Workspaces()` returns diagnostics that have errors AND the error string is not the `backend.ErrWorkspacesNotSupported` sentinel. The backend was asked to enumerate workspaces and failed for a reason other than not supporting the concept at all.
Solutions
- Inspect the wrapped `%s` (the diagnostics error) for the HTTP status or filesystem error.
- For cloud backends, verify the token has at least `read-workspaces` permission on the organization.
- Confirm the `organization` and `hostname` in the `cloud` block are correct.
- Run `terraform init` to re-establish connectivity and re-authenticate if needed.
- For local backends, check permissions on the state directory.
Example fix
// before: token lacks read permission
cloud { organization = "acme" workspaces { name = "prod" } }
# grant 'Read Workspaces' to the token's team in HCP Terraform org settings,
# then
terraform init
terraform plan Defensive patterns
Strategy: try-catch
Validate before calling
// For cloud backends, pre-check token permissions / org access.
// Ensure the token can list workspaces before running selectWorkspace.
client, _ := tfe.NewClient(&tfe.Config{Token: tok, Address: addr})
if _, err := client.Organizations.Read(ctx, org); err != nil {
return fmt.Errorf("token cannot access org %s: %w", org, err)
} Type guard
// Skip the error if the backend simply lacks workspace support.
if diags.Err().Error() == backend.ErrWorkspacesNotSupported.Error() { return nil } Try / catch
// Distinguish 'not supported' (benign) from real listing failures.
if diags.HasErrors() && diags.Err().Error() != backend.ErrWorkspacesNotSupported.Error() {
return fmt.Errorf("Failed to get existing workspaces: %s", diags.Err())
} Prevention
- Grant the API token `read-workspaces` permission on the org.
- Verify `organization` spelling in the `cloud` block.
- Run `terraform init` to surface connectivity/auth issues before operations.
When it happens
Trigger: `b.Workspaces()` issues the backend's workspace-listing routine — for the cloud backend this is an API call filtered by `workspaces.tags`/`workspaces.name`; for the local backend it is a directory read. Failures include API 5xx/4xx, permission errors, network failures, or a local filesystem read error. The early `ErrWorkspacesNotSupported` short-circuit means this only fires for backends that DO support workspaces but failed to list them.
Common situations: HCP Terraform API token lacks permission to list workspaces in the organization; `workspaces.tags` filter references tags that cause a server error; network blip to `app.terraform.io`; local backend cannot read `.terraform/terraform.tfstate.d/` due to permissions; organization name typo in the `cloud` block.
Related errors
- Couldn't create initial workspace: no name provided
- Couldn't create initial workspace
- Currently selected workspace
- Error creating workspace
- error deleting workspace
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/3f3ae4087e79f4fc.
Report an issue: GitHub.
Appendix: source
Thrown at internal/command/meta_backend.go:246
m.backendConfigState = &workdir.BackendConfigState{
Type: "local",
ConfigRaw: json.RawMessage("{}"),
}
}
return local, diags
}
// selectWorkspace gets a list of existing workspaces and then checks
// if the currently selected workspace is valid. If not, it will ask
// the user to select a workspace from the list.
func (m *Meta) selectWorkspace(b backend.Backend) error {
workspaces, diags := b.Workspaces()
if diags.HasErrors() && diags.Err().Error() == backend.ErrWorkspacesNotSupported.Error() {
return nil
}
if diags.HasErrors() {
return fmt.Errorf("Failed to get existing workspaces: %s", diags.Err())
}
if diags.HasWarnings() {
log.Printf("[WARN] selectWorkspace: warning(s) returned when getting workspaces: %s", diags.ErrWithWarnings())
}
if len(workspaces) == 0 {
if c, ok := b.(*cloud.Cloud); ok && m.input {
// len is always 1 if using Name; 0 means we're using Tags and there
// aren't any matching workspaces. Which might be normal and fine, so
// let's just ask:
name, err := m.UIInput().Input(context.Background(), &terraform.InputOpts{
Id: "create-workspace",
Query: "\n[reset][bold][yellow]No workspaces found.[reset]",
Description: fmt.Sprintf(inputCloudInitCreateWorkspace, c.WorkspaceMapping.DescribeTags()),
})
if err != nil {
return fmt.Errorf("Couldn't create initial workspace: %w", err)
}
name = strings.TrimSpace(name)View on GitHub (pinned to d32a084675)