hashicorp/terraform · critical
found invalid type within path
Error message
found invalid type within path (%v:%T), the validation shouldn't have allowed this to happen; this is a bug in Terraform, please report it
What it means
A panic in PathMatcher.GetChildWithKey: a path element is neither a string nor a float64. JSON-decoded paths should only contain strings (attribute names) and numbers (indices); any other type means upstream path validation failed. The message explicitly states this is a Terraform bug and asks for a report.
Solutions
- Report the bug to Terraform with the config, plan, and state that triggered it — this path should be unreachable.
- As a workaround, regenerate the plan/state from a clean `terraform init && terraform plan`.
- Update to the latest Terraform patch release; the bug may already be fixed.
Defensive patterns
Strategy: type-guard
Validate before calling
// Sanitize a decoded path so only string/float64 elements remain.
func sanitizePath(p []any) []any {
out := make([]any, 0, len(p))
for _, e := range p {
switch e.(type) {
case string, float64: out = append(out, e)
}
}
return out
} Type guard
func isCanonicalPathElement(v any) bool {
switch v.(type) {
case string, float64: return true
default: return false
}
} Prevention
- Report the panic as a Terraform bug with plan/state attached.
- Regenerate plans from a clean init to avoid corrupted sensitive paths.
- Keep Terraform updated; path-validation fixes land in patch releases.
When it happens
Trigger: Calling GetChildWithKey with a Paths slice containing a bool, nil, map, or slice element — possible only if the path was not normalized through the standard JSON unmarshaling/validation (which produces string/float64). Triggered during sensitive-attribute path matching in JSON plan/state rendering.
Common situations: Internal Terraform bug in path handling; custom/buggy callers passing non-canonical paths; corruption during JSON decoding of sensitive_paths.
Related errors
- resource has an unsupported mode
- unsupported view type
- backendDiags.Err()
- can not read leafPassphraseBytes from
- confirmFunc must not be nil
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/44167298f8ca8b44.
Report an issue: GitHub.
Appendix: source
Thrown at internal/command/jsonformat/structured/attribute_path/matcher.go:164
child.Paths = append(child.Paths, path)
}
// If not we would simply drop this path from our set of paths but
// either way we just continue.
continue
}
switch val := path[0].(type) {
case string:
if val == key {
child.Paths = append(child.Paths, path[1:])
}
case float64:
// here we must assume the path being looked up no longer matches
// the given data structure, so the caller in incorrect. This is
// fine, because it only means that we don't match any paths.
default:
panic(fmt.Errorf("found invalid type within path (%v:%T), the validation shouldn't have allowed this to happen; this is a bug in Terraform, please report it", val, val))
}
}
return child
}
func (p *PathMatcher) GetChildWithIndex(index int) Matcher {
child := &PathMatcher{
Propagate: p.Propagate,
}
for _, path := range p.Paths {
if len(path) == 0 {
// This means that the current value matched, but not necessarily
// it's child.
if p.Propagate {
// If propagate is true, then our child match our matches
child.Paths = append(child.Paths, path)View on GitHub (pinned to d32a084675)