hashicorp/terraform · error
must be eight hexadecimal digits
Error message
must be eight hexadecimal digits
What it means
Returned by addrs.ParseDeposedKey when the raw string is not exactly 8 characters long, OR when it is 8 chars but hex.DecodeString rejects it (non-hex characters). A DeposedKey must be exactly eight lowercase hexadecimal digits (e.g. 'a1b2c3d4'). On failure the function returns the zero key "00000000".
Solutions
- Supply exactly 8 lowercase hex digits (0-9, a-f).
- Trim whitespace and strip any surrounding quotes/punctuation before parsing.
- If you generated the key yourself, use NewDeposedKey() which always produces a valid key.
- Validate with a regex like ^[0-9a-f]{8}$ before calling ParseDeposedKey.
Example fix
// before
k, err := addrs.ParseDeposedKey(strings.TrimSpace(input))
// after
input = strings.TrimSpace(input)
if !regexp.MustCompile(`^[0-9a-f]{8}$`).MatchString(input) {
return addrs.DeposedKey(""), fmt.Errorf("invalid deposed key %q: need 8 lowercase hex digits", input)
}
k, err := addrs.ParseDeposedKey(input) Defensive patterns
Strategy: validation
Validate before calling
raw := strings.TrimSpace(input)
if !regexp.MustCompile(`^[0-9a-f]{8}$`).MatchString(raw) {
return fmt.Errorf("deposed key must be 8 lowercase hex digits")
} Type guard
func isValidDeposedKey(s string) bool {
return regexp.MustCompile(`^[0-9a-f]{8}$`).MatchString(strings.TrimSpace(s))
} Try / catch
if !isValidDeposedKey(input) {
return fmt.Errorf("invalid deposed key %q", input)
}
k, err := addrs.ParseDeposedKey(input) Prevention
- Prefer NewDeposedKey() over hand-typed keys.
- Trim whitespace and validate with ^[0-9a-f]{8}$ before parsing.
- Display deposed keys in lowercase to avoid round-trip issues.
When it happens
Trigger: ParseDeposedKey at resource.go:619-621 (length != 8) or resource.go:625-627 (hex.DecodeString error). Reached when parsing a deposed key from CLI args, state, or serialized addresses.
Common situations: Manually typed deposed key of wrong length; truncated/extra characters from copy-paste; key passed with surrounding whitespace; non-hex characters (e.g. 'g' or 'z'); uppercase letters fall through to a different message (115).
Related errors
- must use lowercase hex digits
- at most 1 action can be invoked per operation
- can't delete default state
- can't set both encryption_key and kms_encryption_key
- Cannot quote scp command, target platform unknown
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/0ddd28e294426e51.
Report an issue: GitHub.
Appendix: source
Thrown at internal/addrs/resource.go:620
// key.
const NotDeposed = DeposedKey("")
var deposedKeyRand = rand.New(rand.NewSource(time.Now().UnixNano()))
// NewDeposedKey generates a pseudo-random deposed key. Because of the short
// length of these keys, uniqueness is not a natural consequence and so the
// caller should test to see if the generated key is already in use and generate
// another if so, until a unique key is found.
func NewDeposedKey() DeposedKey {
v := deposedKeyRand.Uint32()
return DeposedKey(fmt.Sprintf("%08x", v))
}
// ParseDeposedKey parses a string that is expected to be a deposed key,
// returning an error if it doesn't conform to the expected syntax.
func ParseDeposedKey(raw string) (DeposedKey, error) {
if len(raw) != 8 {
return "00000000", fmt.Errorf("must be eight hexadecimal digits")
}
if raw != strings.ToLower(raw) {
return "00000000", fmt.Errorf("must use lowercase hex digits")
}
_, err := hex.DecodeString(raw)
if err != nil {
return "00000000", fmt.Errorf("must be eight hexadecimal digits")
}
return DeposedKey(raw), nil
}
func (k DeposedKey) String() string {
return string(k)
}
func (k DeposedKey) GoString() string {
ks := string(k)
switch {View on GitHub (pinned to d32a084675)