hashicorp/terraform · error

Failed to override

Error message

Failed to override: %w
%s

What it means

In the interactive override flow, b.confirm() returned an error that is NOT errRunOverridden (which is the expected success path). The wrapped error and run URL are surfaced together so the operator can see why the confirmation prompt failed (typo in 'override' keyword, context cancel, input error) and where to recover manually.

Solutions

  1. Type exactly 'override' (case-sensitive) when prompted, or choose the non-override option.
  2. Use the run URL in the message to override or discard manually in the TFE/HCP UI.
  3. If the prompt is unexpected, ensure --auto-approve is set or skip the override path.
Defensive patterns

Strategy: try-catch

Validate before calling

const overrideKeyword = "override"

func validOverrideInput(s string) bool { return s == overrideKeyword }

Try / catch

err := b.confirm(ctx, op, opts, r, "override")
if err != nil && err != errRunOverridden {
    // provide manual recovery path via run URL embedded in the error
    log.Printf("override prompt failed: %v", err)
    return err
}

Prevention

When it happens

Trigger: b.confirm(...) returns err where err != nil AND err != errRunOverridden: user typed something other than 'override'; UIIn.Input failed; stopCtx was canceled mid-prompt; input EOF on a closed stdin.

Common situations: Operator mistyped the override keyword; CI accidentally reached the interactive branch with a half-open TTY; SSH session dropped during the prompt.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/d99cac74c2d692df. Report an issue: GitHub.

Appendix: source

Thrown at internal/cloud/backend_common.go:418

				!pc.Actions.IsOverridable || !pc.Permissions.CanOverride {
				return fmt.Errorf("%s soft failed.\n%s", msgPrefix, runURL)
			}

			if op.AutoApprove {
				if _, err = b.client.PolicyChecks.Override(stopCtx, pc.ID); err != nil {
					return b.generalError(fmt.Sprintf("Failed to override policy check.\n%s", runURL), err)
				}
			} else if !b.input {
				return errPolicyOverrideNeedsUIConfirmation
			} else {
				opts := &terraform.InputOpts{
					Id:          "override",
					Query:       "\nDo you want to override the soft failed policy check?",
					Description: "Only 'override' will be accepted to override.",
				}
				err = b.confirm(stopCtx, op, opts, r, "override")
				if err != nil && err != errRunOverridden {
					return fmt.Errorf("Failed to override: %w\n%s\n", err, runURL)
				}

				if err != errRunOverridden {
					if _, err = b.client.PolicyChecks.Override(stopCtx, pc.ID); err != nil {
						return b.generalError(fmt.Sprintf("Failed to override policy check.\n%s", runURL), err)
					}
				} else {
					runURL := fmt.Sprintf(runHeader, b.Hostname, b.Organization, op.Workspace, r.ID)
					b.CLI.Output(fmt.Sprintf("The run needs to be manually overridden or discarded.\n%s\n", runURL))
				}
			}

			if b.CLI != nil {
				b.CLI.Output("------------------------------------------------------------------------")
			}
		default:
			return fmt.Errorf("Unknown or unexpected policy state: %s", pc.Status)
		}

View on GitHub (pinned to d32a084675)