hashicorp/terraform · error

identity schema not found for type

Error message

identity schema not found for type %s

What it means

Returned by the tfplugin6 ReadResource handler when core sent a non-nil CurrentIdentity but the resource schema has no Identity block (resSchema.Identity == nil). The wrapper cannot decode identity bytes without a target type, so it refuses the read.

Solutions

  1. Upgrade the provider to a version that declares an identity schema for the resource.
  2. If developing the provider, add the Identity block to the resource schema.
  3. Align terraform core and provider versions so both understand identity for the type.
  4. Remove stale identity from state if the resource legitimately no longer supports identity.

Example fix

// before: resource schema has no identity
resSchema.Identity = nil
// after
resSchema.Identity = identityConfigSchema
Defensive patterns

Strategy: validation

Validate before calling

// Before forwarding CurrentIdentity on a ReadResource RPC, ensure the type declares identity.
schemas, err := client.GetProviderSchema(ctx, &tfplugin6.GetProviderSchema_Request{})
if err != nil {
    return err
}
resSchema, ok := schemas.ResourceTypes[typeName]
if !ok || resSchema.Identity == nil {
    // do not send CurrentIdentity for this type
    req.CurrentIdentity = nil
}
return client.ReadResource(ctx, req)

Type guard

func hasIdentitySchema(s *tfplugin6.Schema, typeName string) bool {
    r, ok := s.ResourceTypes[typeName]
    return ok && r.Identity != nil
}

Prevention

When it happens

Trigger: req.CurrentIdentity != nil && req.CurrentIdentity.IdentityData != nil while p.schema.ResourceTypes[req.TypeName].Identity == nil.

Common situations: Terraform core version supports resource identity and forwards identity data, but the provider (or this resource type) predates identity support or did not declare an identity schema; state carries identity for a resource whose schema dropped it.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/dd98717a18688ecd. Report an issue: GitHub.

Appendix: source

Thrown at internal/grpcwrap/provider6.go:302

	ty := resSchema.Body.ImpliedType()

	stateVal, err := decodeDynamicValue6(req.CurrentState, ty)
	if err != nil {
		resp.Diagnostics = convert.AppendProtoDiag(resp.Diagnostics, err)
		return resp, nil
	}

	metaTy := p.schema.ProviderMeta.Body.ImpliedType()
	metaVal, err := decodeDynamicValue6(req.ProviderMeta, metaTy)
	if err != nil {
		resp.Diagnostics = convert.AppendProtoDiag(resp.Diagnostics, err)
		return resp, nil
	}

	var currentIdentity cty.Value
	if req.CurrentIdentity != nil && req.CurrentIdentity.IdentityData != nil {
		if resSchema.Identity == nil {
			return resp, fmt.Errorf("identity schema not found for type %s", req.TypeName)
		}

		currentIdentity, err = decodeDynamicValue6(req.CurrentIdentity.IdentityData, resSchema.Identity.ImpliedType())
		if err != nil {
			resp.Diagnostics = convert.AppendProtoDiag(resp.Diagnostics, err)
			return resp, nil
		}
	}

	readResp := p.provider.ReadResource(providers.ReadResourceRequest{
		TypeName:        req.TypeName,
		PriorState:      stateVal,
		Private:         req.Private,
		ProviderMeta:    metaVal,
		CurrentIdentity: currentIdentity,
	})
	resp.Diagnostics = convert.AppendProtoDiag(resp.Diagnostics, readResp.Diagnostics)
	if readResp.Diagnostics.HasErrors() {

View on GitHub (pinned to d32a084675)