hashicorp/terraform · critical

found invalid type within path

Error message

found invalid type within path (%v:%T), the validation shouldn't have allowed this to happen; this is a bug in Terraform, please report it

What it means

A panic in PathMatcher.GetChildWithKey: a path element is neither a string nor a float64. JSON-decoded paths should only contain strings (attribute names) and numbers (indices); any other type means upstream path validation failed. The message explicitly states this is a Terraform bug and asks for a report.

Solutions

  1. Report the bug to Terraform with the config, plan, and state that triggered it — this path should be unreachable.
  2. As a workaround, regenerate the plan/state from a clean `terraform init && terraform plan`.
  3. Update to the latest Terraform patch release; the bug may already be fixed.
Defensive patterns

Strategy: type-guard

Validate before calling

// Sanitize a decoded path so only string/float64 elements remain.
func sanitizePath(p []any) []any {
    out := make([]any, 0, len(p))
    for _, e := range p {
        switch e.(type) {
        case string, float64: out = append(out, e)
        }
    }
    return out
}

Type guard

func isCanonicalPathElement(v any) bool {
    switch v.(type) {
    case string, float64: return true
    default: return false
    }
}

Prevention

When it happens

Trigger: Calling GetChildWithKey with a Paths slice containing a bool, nil, map, or slice element — possible only if the path was not normalized through the standard JSON unmarshaling/validation (which produces string/float64). Triggered during sensitive-attribute path matching in JSON plan/state rendering.

Common situations: Internal Terraform bug in path handling; custom/buggy callers passing non-canonical paths; corruption during JSON decoding of sensitive_paths.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/44167298f8ca8b44. Report an issue: GitHub.

Appendix: source

Thrown at internal/command/jsonformat/structured/attribute_path/matcher.go:164

				child.Paths = append(child.Paths, path)
			}

			// If not we would simply drop this path from our set of paths but
			// either way we just continue.
			continue
		}

		switch val := path[0].(type) {
		case string:
			if val == key {
				child.Paths = append(child.Paths, path[1:])
			}
		case float64:
			// here we must assume the path being looked up no longer matches
			// the given data structure, so the caller in incorrect. This is
			// fine, because it only means that we don't match any paths.
		default:
			panic(fmt.Errorf("found invalid type within path (%v:%T), the validation shouldn't have allowed this to happen; this is a bug in Terraform, please report it", val, val))

		}
	}
	return child
}

func (p *PathMatcher) GetChildWithIndex(index int) Matcher {
	child := &PathMatcher{
		Propagate: p.Propagate,
	}
	for _, path := range p.Paths {
		if len(path) == 0 {
			// This means that the current value matched, but not necessarily
			// it's child.

			if p.Propagate {
				// If propagate is true, then our child match our matches
				child.Paths = append(child.Paths, path)

View on GitHub (pinned to d32a084675)