hashicorp/terraform · error

hostname for run ( ) does not match the configured cloud…

Error message

hostname for run (%s) does not match the configured cloud integration (%s)

What it means

Thrown by Cloud.ShowPlanForRun when runHostname != b.Hostname. A saved cloud plan reference encodes the hostname it was created under; the `terraform show` command refuses to fetch a plan from a different hostname than the currently configured cloud backend, to prevent cross-endpoint confusion and token misuse.

Solutions

  1. Reconfigure the cloud backend `hostname` to match the hostname in the saved plan reference (shown as the first %s).
  2. Regenerate the plan against the currently configured hostname before running `terraform show`.
  3. Check for trailing slashes or scheme differences in the hostname config and normalize them.
  4. Confirm you are pointing at the correct TFE/HCP instance for this plan.

Example fix

// before - plan was made on app.terraform.io, backend now points elsewhere
cloud {
  hostname = "tfe.corp.local"
}
// after - match the hostname embedded in the plan reference
cloud {
  hostname = "app.terraform.io"
}
Defensive patterns

Strategy: validation

Validate before calling

// Compare hostnames before calling ShowPlanForRun.
if runHostname != b.Hostname {
    return fmt.Errorf("refusing cross-hostname show: %s vs %s", runHostname, b.Hostname)
}

Type guard

func hostnamesMatch(a, b string) bool {
    return strings.TrimRight(a, "/") == strings.TrimRight(b, "/")
}

Prevention

When it happens

Trigger: The plan file / saved plan reference was produced against one HCP Terraform/TFE hostname (e.g. app.terraform.io) but the current backend config points at a different hostname (e.g. a self-hosted TFE at tfe.corp.local). The runHostname embedded in the plan reference does not equal b.Hostname from the current cloud config.

Common situations: Switching from HCP Terraform (SaaS) to self-hosted TFE while reusing a saved plan; multiple TFE instances with plan references from the wrong one; a hostname config change (custom hostname vs default) between plan and show.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/489034ae718fc3f7. Report an issue: GitHub.

Appendix: source

Thrown at internal/cloud/backend_show.go:28

	tfe "github.com/hashicorp/go-tfe"
	"github.com/hashicorp/terraform/internal/cloud/cloudplan"
	"github.com/hashicorp/terraform/internal/plans"
)

// ShowPlanForRun downloads the JSON plan output for the specified cloud run
// (either the redacted or unredacted format, per the caller's request), and
// returns it in a cloudplan.RemotePlanJSON wrapper struct (along with various
// metadata required by terraform show). It's intended for use by the terraform
// show command, in order to format and display a saved cloud plan.
func (b *Cloud) ShowPlanForRun(ctx context.Context, runID, runHostname string, redacted bool) (*cloudplan.RemotePlanJSON, error) {
	var jsonBytes []byte
	mode := plans.NormalMode
	var opts []plans.Quality

	// Bail early if wrong hostname
	if runHostname != b.Hostname {
		return nil, fmt.Errorf("hostname for run (%s) does not match the configured cloud integration (%s)", runHostname, b.Hostname)
	}

	// Get run and plan
	r, err := b.client.Runs.ReadWithOptions(ctx, runID, &tfe.RunReadOptions{Include: []tfe.RunIncludeOpt{tfe.RunPlan, tfe.RunWorkspace}})
	if err == tfe.ErrResourceNotFound {
		return nil, fmt.Errorf("couldn't read information for cloud run %s; make sure you've run `terraform login` and that you have permission to view the run", runID)
	} else if err != nil {
		return nil, fmt.Errorf("couldn't read information for cloud run %s: %w", runID, err)
	}

	// Sort out the run mode
	if r.IsDestroy {
		mode = plans.DestroyMode
	} else if r.RefreshOnly {
		mode = plans.RefreshOnlyMode
	}

	// Check that the plan actually finished

View on GitHub (pinned to d32a084675)