hashicorp/terraform · error

Failed to set state store provider configuration

Error message

Failed to set state store provider configuration: %w

What it means

Immediately after the state_store config is persisted, the provider portion of the config is set via s.StateStore.Provider.SetConfig(providerConfigVal, b.ProviderSchema()). If that encode fails, this error wraps the cause. It reflects a provider-schema vs provider-config mismatch, distinct from the state-store schema error at 671.

Solutions

  1. Inspect inner %w for the failing provider attribute/type.
  2. Align the provider version (lock file vs cache vs config) with `tofu init -upgrade` or by correcting the version constraint.
  3. Strip undocumented keys from the provider {} sub-block of the state_store.
  4. Recompile/replace a dev provider so its schema matches the declared config.

Example fix

// before
state_store "acme" {
  provider = "example.com/acme/storage"
  provider_config {
    token = "..."   # not in provider schema
  }
}

// after
state_store "acme" {
  provider = "example.com/acme/storage"
  provider_config {
    # schema-declared provider attributes only
  }
}
Defensive patterns

Strategy: validation

Validate before calling

// Validate the provider_config sub-block against the provider schema.
func validateProviderConfig(providerCfg cty.Value, schema *configschema.Block) error {
    if schema == nil { return fmt.Errorf("provider schema is nil") }
    if err := schema.ImpliedType().Value(providerCfg); err != nil {
        return fmt.Errorf("provider config does not match schema: %w", err)
    }
    return nil
}

Try / catch

if err := s.StateStore.Provider.SetConfig(providerConfigVal, b.ProviderSchema()); err != nil {
    if isJSONEncodingErr(err) {
        diags = diags.Append(fmt.Errorf("state-store provider config does not match schema (remove undocumented keys / align provider version): %w", err))
    } else {
        diags = diags.Append(fmt.Errorf("Failed to set state store provider configuration: %w", err))
    }
    return nil, diags
}

Prevention

When it happens

Trigger: Provider.SetConfig fails encoding providerConfigVal against b.ProviderSchema(). Triggers: provider schema nil/malformed, provider config block has unknown attributes/types, or provider plugin version whose provider schema differs from what Terraform built the config value against.

Common situations: Provider pinned to a version with a different provider-schema than expected; extra keys in the state_store provider {} sub-block; provider plugin built against a different Terraform plugin SDK.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/5ffde5fe357203a2. Report an issue: GitHub.

Appendix: source

Thrown at internal/command/meta_backend.go:2278

	s.Backend = nil // unset this; user may be running `terraform init -reconfigure` and there's a preexisting backend state file.
	s.StateStore = &workdir.StateStoreConfigState{
		Type: c.Type,
		Hash: uint64(stateStoreHash),
		Provider: &workdir.ProviderConfigState{
			Source:  &c.ProviderAddr,
			Version: pVersion,
		},
		ProviderSupplyMode: c.ProviderSupplyMode,
	}
	err := s.StateStore.SetConfig(storeConfigVal, b.ConfigSchema())
	if err != nil {
		diags = diags.Append(fmt.Errorf("Failed to set state store configuration: %w", err))
		return nil, diags
	}

	err = s.StateStore.Provider.SetConfig(providerConfigVal, b.ProviderSchema())
	if err != nil {
		diags = diags.Append(fmt.Errorf("Failed to set state store provider configuration: %w", err))
		return nil, diags
	}

	// Verify that selected workspace exists in the state store.
	if opts.Init && b != nil {
		if err := m.selectWorkspace(b); err != nil {
			if errors.Is(err, &errBackendNoExistingWorkspaces{}) {
				ws, err := m.Workspace()
				if err != nil {
					diags = diags.Append(fmt.Errorf("Failed to check current workspace: %w", err))
					return nil, diags
				}

				if ws == backend.DefaultStateName {
					// If the default workspace is selected, no workspaces existing _may_ be expected.
					// It's valid for the default workspace's state to not be created until the first apply takes place.
					// However, it could be that the user is configuring their working directory for the first time but
					// they expect pre-existing state to be in the store from previous actions. In that case, the user

View on GitHub (pinned to d32a084675)