hashicorp/terraform · error

must be eight hexadecimal digits

Error message

must be eight hexadecimal digits

What it means

Returned by addrs.ParseDeposedKey when the raw string is not exactly 8 characters long, OR when it is 8 chars but hex.DecodeString rejects it (non-hex characters). A DeposedKey must be exactly eight lowercase hexadecimal digits (e.g. 'a1b2c3d4'). On failure the function returns the zero key "00000000".

Solutions

  1. Supply exactly 8 lowercase hex digits (0-9, a-f).
  2. Trim whitespace and strip any surrounding quotes/punctuation before parsing.
  3. If you generated the key yourself, use NewDeposedKey() which always produces a valid key.
  4. Validate with a regex like ^[0-9a-f]{8}$ before calling ParseDeposedKey.

Example fix

// before
k, err := addrs.ParseDeposedKey(strings.TrimSpace(input))

// after
input = strings.TrimSpace(input)
if !regexp.MustCompile(`^[0-9a-f]{8}$`).MatchString(input) {
    return addrs.DeposedKey(""), fmt.Errorf("invalid deposed key %q: need 8 lowercase hex digits", input)
}
k, err := addrs.ParseDeposedKey(input)
Defensive patterns

Strategy: validation

Validate before calling

raw := strings.TrimSpace(input)
if !regexp.MustCompile(`^[0-9a-f]{8}$`).MatchString(raw) {
    return fmt.Errorf("deposed key must be 8 lowercase hex digits")
}

Type guard

func isValidDeposedKey(s string) bool {
    return regexp.MustCompile(`^[0-9a-f]{8}$`).MatchString(strings.TrimSpace(s))
}

Try / catch

if !isValidDeposedKey(input) {
    return fmt.Errorf("invalid deposed key %q", input)
}
k, err := addrs.ParseDeposedKey(input)

Prevention

When it happens

Trigger: ParseDeposedKey at resource.go:619-621 (length != 8) or resource.go:625-627 (hex.DecodeString error). Reached when parsing a deposed key from CLI args, state, or serialized addresses.

Common situations: Manually typed deposed key of wrong length; truncated/extra characters from copy-paste; key passed with surrounding whitespace; non-hex characters (e.g. 'g' or 'z'); uppercase letters fall through to a different message (115).

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/0ddd28e294426e51. Report an issue: GitHub.

Appendix: source

Thrown at internal/addrs/resource.go:620

// key.
const NotDeposed = DeposedKey("")

var deposedKeyRand = rand.New(rand.NewSource(time.Now().UnixNano()))

// NewDeposedKey generates a pseudo-random deposed key. Because of the short
// length of these keys, uniqueness is not a natural consequence and so the
// caller should test to see if the generated key is already in use and generate
// another if so, until a unique key is found.
func NewDeposedKey() DeposedKey {
	v := deposedKeyRand.Uint32()
	return DeposedKey(fmt.Sprintf("%08x", v))
}

// ParseDeposedKey parses a string that is expected to be a deposed key,
// returning an error if it doesn't conform to the expected syntax.
func ParseDeposedKey(raw string) (DeposedKey, error) {
	if len(raw) != 8 {
		return "00000000", fmt.Errorf("must be eight hexadecimal digits")
	}
	if raw != strings.ToLower(raw) {
		return "00000000", fmt.Errorf("must use lowercase hex digits")
	}
	_, err := hex.DecodeString(raw)
	if err != nil {
		return "00000000", fmt.Errorf("must be eight hexadecimal digits")
	}
	return DeposedKey(raw), nil
}

func (k DeposedKey) String() string {
	return string(k)
}

func (k DeposedKey) GoString() string {
	ks := string(k)
	switch {

View on GitHub (pinned to d32a084675)