hashicorp/terraform · error
invalid tfvars syntax
Error message
invalid tfvars syntax: %s
What it means
decode_tfvars feeds the input string to hclsyntax.ParseConfig. If the HCL parser reports errors (unterminated strings, invalid tokens, malformed expressions), they are wrapped into this message. This is a genuine user-facing error: the supplied string is not valid HCL/terraform-tfvars syntax.
Solutions
- Read the wrapped HCL diagnostic to locate the exact offset/token causing the parse failure and fix it
- Validate the string parses as HCL before calling (run it through hclsyntax.ParseConfig, or terraform fmt -check)
- If the input is a file, run terraform fmt on it first to surface and auto-fix common syntax issues
Example fix
// before
decode_tfvars("name = 'broken")
// after
decode_tfvars("name = \"fixed\"") Defensive patterns
Strategy: validation
Validate before calling
// Pre-parse the tfvars string with HCL before handing it to decode_tfvars.
// In Go:
f, diags := hclsyntax.ParseConfig([]byte(src), "check.tfvars", hcl.InitialPos)
if diags.HasErrors() {
// surface diags to the user instead of calling decode_tfvars
return diags
}
// In HCL, validate the source file first:
// validate that file(var.path) is non-empty and well-formed via a fmt check in CI Prevention
- Run terraform fmt -check on any .tfvars file whose contents you feed to decode_tfvars
- When constructing tfvars strings programmatically, escape embedded quotes and avoid unterminated tokens
- Add a CI lint step that parses tfvars inputs through hclsyntax before deployment
When it happens
Trigger: decode_tfvars("name = 'broken") with an unterminated string; decode_tfvars("a = =") with an invalid expression token; any malformed tfvars content passed as the single argument.
Common situations: Reading a .tfvars file with file() that contains a typo or unbalanced quotes; programmatically building a tfvars string without escaping embedded quotes; copy-pasting partial config into decode_tfvars.
Related errors
- invalid expression for variable
- cannot decode tfvars from a null value
- invalid tfvars content
- all arguments must have the same type
- argument must be a list or tuple
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/b2f382c1720897a2.
Report an issue: GitHub.
Appendix: source
Thrown at internal/builtin/providers/terraform/functions.go:121
// type, since it will be an object type decided based on which
// arguments and values we find in the string.
return cty.DynamicVal, nil
}
// If we get here then we know that:
// - there's exactly one element in args
// - it's a string
// - it is known and non-null
// So therefore the following is guaranteed to succeed.
src := []byte(args[0].AsString())
// As usual when we wrap HCL stuff up in functions, we end up needing to
// stuff HCL diagnostics into plain string error messages. This produces
// a non-ideal result but is still better than hiding the HCL-provided
// diagnosis altogether.
f, hclDiags := hclsyntax.ParseConfig(src, "<decode_tfvars argument>", hcl.InitialPos)
if hclDiags.HasErrors() {
return cty.NilVal, fmt.Errorf("invalid tfvars syntax: %s", hclDiags.Error())
}
attrs, hclDiags := f.Body.JustAttributes()
if hclDiags.HasErrors() {
return cty.NilVal, fmt.Errorf("invalid tfvars content: %s", hclDiags.Error())
}
retAttrs := make(map[string]cty.Value, len(attrs))
for name, attr := range attrs {
// Evaluating the expression with no EvalContext achieves the same
// interpretation as Terraform CLI makes of .tfvars files, rejecting
// any function calls or references to symbols.
v, hclDiags := attr.Expr.Value(nil)
if hclDiags.HasErrors() {
return cty.NilVal, fmt.Errorf("invalid expression for variable %q: %s", name, hclDiags.Error())
}
retAttrs[name] = v
}
return cty.ObjectVal(retAttrs), nilView on GitHub (pinned to d32a084675)