hashicorp/terraform · error

identity schema not found for type

Error message

identity schema not found for type %s

What it means

Returned inside the grpcwrap ReadResource handler when the gRPC request carries CurrentIdentity data but the resource type's schema has no Identity block (resSchema.Identity == nil). The wrapper cannot decode identity bytes without a target type, so it refuses rather than guessing. '%s' is the resource type name.

Solutions

  1. Upgrade the provider to a build that declares identity schemas for the named resource type.
  2. If writing a provider, ensure SchemaResponse.ResourceTypes[].Identity is populated for that type in GetProviderSchema.
  3. Downgrade Terraform core to a version that does not send identity for this resource type if a provider upgrade is not possible.
  4. Verify the resource type name in the request matches a schema key that has Identity defined.

Example fix

// before: provider schema missing identity for 'example_thing'
schema.ResourceTypes["example_thing"] = &configschema.Block{Attributes: ...} // no Identity
// after (provider-side framework)
schema.ResourceTypes["example_thing"] = &configschema.Block{
    Attributes: ...,
    Identity:   identitySchema,
}
Defensive patterns

Strategy: type-guard

Validate before calling

// Provider-side: ensure identity schema exists before sending CurrentIdentity.
if schema, ok := p.schema.ResourceTypes[req.TypeName]; ok && schema.Identity != nil {
    // safe to send CurrentIdentity
} else {
    // omit identity from the request
}

Type guard

// Check identity schema presence before issuing the request.
func hasIdentitySchema(schemas map[string]*configschema.Block, t string) bool {
    b, ok := schemas[t]
    return ok && b.Identity != nil
}

Try / catch

// Caller-side: tolerate schema mismatch during upgrades.
if err != nil && strings.Contains(err.Error(), "identity schema not found") {
    log.Printf("identity not supported on %s yet; upgrade provider", t)
}

Prevention

When it happens

Trigger: A provider plugin receives a ReadResourceRequest with req.CurrentIdentity.IdentityData populated for a resource type that did not declare an identity schema in GetProviderSchema. Indicates schema/request mismatch between Terraform core and the provider.

Common situations: Provider version skew: Terraform core (with identity support) talks to an older provider build whose schema predates identity; a provider incorrectly omits the identity block for a resource that core believes has identity; test harness sending identity without configuring schema.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/3b6edc6701ca1480. Report an issue: GitHub.

Appendix: source

Thrown at internal/grpcwrap/provider.go:288

	ty := resSchema.Body.ImpliedType()

	stateVal, err := decodeDynamicValue(req.CurrentState, ty)
	if err != nil {
		resp.Diagnostics = convert.AppendProtoDiag(resp.Diagnostics, err)
		return resp, nil
	}

	metaTy := p.schema.ProviderMeta.Body.ImpliedType()
	metaVal, err := decodeDynamicValue(req.ProviderMeta, metaTy)
	if err != nil {
		resp.Diagnostics = convert.AppendProtoDiag(resp.Diagnostics, err)
		return resp, nil
	}

	var currentIdentity cty.Value
	if req.CurrentIdentity != nil && req.CurrentIdentity.IdentityData != nil {
		if resSchema.Identity == nil {
			return resp, fmt.Errorf("identity schema not found for type %s", req.TypeName)
		}
		currentIdentity, err = decodeDynamicValue(req.CurrentIdentity.IdentityData, resSchema.Identity.ImpliedType())
		if err != nil {
			resp.Diagnostics = convert.AppendProtoDiag(resp.Diagnostics, err)
			return resp, nil
		}
	}

	readResp := p.provider.ReadResource(providers.ReadResourceRequest{
		TypeName:        req.TypeName,
		PriorState:      stateVal,
		Private:         req.Private,
		ProviderMeta:    metaVal,
		CurrentIdentity: currentIdentity,
	})
	resp.Diagnostics = convert.AppendProtoDiag(resp.Diagnostics, readResp.Diagnostics)
	if readResp.Diagnostics.HasErrors() {
		return resp, nil

View on GitHub (pinned to d32a084675)