hashicorp/terraform · error

no resource identity schema found for

Error message

no resource identity schema found for %s (in provider %s)

What it means

Thrown by jsonstate when identity JSON is present and its version matches, but the provider schema has no identity schema definition (schema.Identity == nil). Terraform has identity bytes to decode but no schema describing their shape, so it cannot serialize them to JSON state.

Solutions

  1. Upgrade the provider to a version that defines identity for the resource.
  2. Run `terraform init -upgrade` to rebuild the schema cache if the provider should support identity.
  3. Remove the identity data from state (targeted refresh once the provider clears it, or `terraform state pull`/edit/`push`).
  4. Align the configured provider source/version with the one that wrote the identity.
Defensive patterns

Strategy: validation

Validate before calling

if ri.Current.IdentityJSON != nil && schema.Identity == nil {
    return fmt.Errorf("state has identity for %s but provider %s defines no identity schema; upgrade the provider or clear identity from state", resAddr, r.ProviderConfig.Provider)
}

Prevention

When it happens

Trigger: A provider version that removed resource-identity support while the state still contains identity JSON; provider downgrade from an identity-aware version to one without identity; partial provider schema load that dropped the identity block.

Common situations: Downgrading a provider below the version that introduced identity for a resource; using a forked provider that lacks identity support against state produced by the upstream provider.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/2e2bbae41883e16e. Report an issue: GitHub.

Appendix: source

Thrown at internal/command/jsonstate/state.go:437

			if ri.Current != nil {
				if schema.Version != int64(ri.Current.SchemaVersion) {
					return nil, fmt.Errorf("schema version %d for %s in state does not match version %d from the provider", ri.Current.SchemaVersion, resAddr, schema.Version)
				}

				current.SchemaVersion = ri.Current.SchemaVersion

				if schema.Body == nil {
					return nil, fmt.Errorf("no schema found for %s (in provider %s)", resAddr.String(), r.ProviderConfig.Provider)
				}

				// Check if we have an identity in the state
				if ri.Current.IdentityJSON != nil {
					if schema.IdentityVersion != int64(ri.Current.IdentitySchemaVersion) {
						return nil, fmt.Errorf("resource identity schema version %d for %s in state does not match version %d from the provider", ri.Current.IdentitySchemaVersion, resAddr, schema.IdentityVersion)
					}

					if schema.Identity == nil {
						return nil, fmt.Errorf("no resource identity schema found for %s (in provider %s)", resAddr.String(), r.ProviderConfig.Provider)
					}

					current.IdentitySchemaVersion = &ri.Current.IdentitySchemaVersion
				}

				riObj, err := ri.Current.Decode(schema)
				if err != nil {
					return nil, err
				}

				var value cty.Value
				var sensitivePaths []cty.Path
				value, current.AttributeValues, sensitivePaths, err = marshalAttributeValues(riObj.Value)
				if err != nil {
					return nil, fmt.Errorf("preparing attribute values for %s: %w", current.Address, err)
				}
				sensitivePaths = append(sensitivePaths, schema.Body.SensitivePaths(value, nil)...)
				s := SensitiveAsBool(marks.MarkPaths(value, marks.Sensitive, sensitivePaths))

View on GitHub (pinned to d32a084675)