hashicorp/terraform · error

missing state name

Error message

missing state name

What it means

Optional and Required are mutually exclusive on an Attribute. Optional means the user may omit the value; Required means the user must set it — the two cannot both be true. The validator rejects this contradiction outright.

Solutions

  1. Choose Optional (user may set) or Required (user must set), not both.
  2. If the provider should also supply a value, add Computed: true alongside Optional: true (Optional+Computed is allowed).

Example fix

// before
"name": { Type: cty.String, Optional: true, Required: true },
// after
"name": { Type: cty.String, Required: true },
Defensive patterns

Strategy: validation

Validate before calling

// Optional and Required are mutually exclusive.
func notOptionalAndRequired(a *configschema.Attribute) bool {
    return a == nil || !(a.Optional && a.Required)
}

Type guard

func mutuallyExclusiveFlags(optional, required bool) bool { return !(optional && required) }

Prevention

When it happens

Trigger: An Attribute with both Optional: true and Required: true. Guard at internal_validate.go:149 is `a.Optional && a.Required`.

Common situations: Flipping flags during a refactor and leaving both set; codegen merging two schema fragments that each set one flag.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/936c96bebd59a6b0. Report an issue: GitHub.

Appendix: source

Thrown at internal/backend/remote-state/s3/backend_state.go:158

	if name == backend.DefaultStateName || name == "" {
		return diags.Append(fmt.Errorf("can't delete default state"))
	}

	log.Info("Deleting workspace")

	client, err := b.remoteClient(name)
	if err != nil {
		return diags.Append(err)
	}

	return diags.Append(client.Delete())
}

// get a remote client configured for this state
func (b *Backend) remoteClient(name string) (*RemoteClient, error) {
	if name == "" {
		return nil, errors.New("missing state name")
	}

	client := &RemoteClient{
		s3Client:              b.s3Client,
		dynClient:             b.dynClient,
		bucketName:            b.bucketName,
		path:                  b.path(name),
		serverSideEncryption:  b.serverSideEncryption,
		customerEncryptionKey: b.customerEncryptionKey,
		acl:                   b.acl,
		kmsKeyID:              b.kmsKeyID,
		ddbTable:              b.ddbTable,
		skipS3Checksum:        b.skipS3Checksum,
		lockFilePath:          b.getLockFilePath(name),
		useLockFile:           b.useLockFile,
	}

	return client, nil

View on GitHub (pinned to d32a084675)