hashicorp/terraform · error
object schema nesting mode is invalid
Error message
object schema nesting mode is invalid
What it means
Returned by Object.InternalValidate when the Object's Nesting field equals the sentinel nestingModeInvalid. This is the top-level guard before any attribute recursion — it short-circuits because every other operation on the Object assumes a valid nesting mode. As with [843], this is a schema-construction defect, not a user-input issue.
Solutions
- Set Object.Nesting to a valid mode (typically NestingSingle for a resource's top-level block) before calling InternalValidate.
- If the Object is built by a factory, fail construction early when Nesting is nestingModeInvalid instead of letting InternalValidate surface it.
- Add a constructor (NewObject(nestingMode)) so an unset mode is impossible at the type level.
Example fix
// before
obj := &configschema.Object{Attributes: attrs}
// after
obj := &configschema.Object{Nesting: configschema.NestingSingle, Attributes: attrs} Defensive patterns
Strategy: validation
Validate before calling
func assertObjectNestingValid(o *configschema.Object) error {
if o == nil { return fmt.Errorf("nil object schema") }
if o.Nesting == configschema.nestingModeInvalid { // or zero value depending on pkg
return fmt.Errorf("object nesting mode is invalid/unset")
}
return nil
} Type guard
func isObjectNestingSet(o *configschema.Object) bool {
return o != nil && o.Nesting != configschema.nestingModeInvalid
} Prevention
- Construct Objects via a factory that mandates a Nesting argument.
- Treat the zero value of Nesting as a programmer error to be caught in tests.
- Validate the schema tree once at provider startup, not per-request.
When it happens
Trigger: Constructing a *configschema.Object (e.g. as the schema for a Block or a top-level resource schema) without setting Nesting, then calling InternalValidate. nestingModeInvalid is the zero/sentinel value used to flag 'unset'.
Common situations: Hand-rolled schema literals in provider tests; deserializing a schema from an older format that did not carry a Nesting field; refactoring that introduces nestingModeInvalid as a default but forgets to overwrite it before validation.
Related errors
- : attribute schema is nil
- : NestingSet attributes may not contain attributes of…
- : NestingSet attributes may not contain WriteOnly attributes
- : Type and NestedType cannot both be set
- Apply discarded.
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/11d4b1feb22ec6a8.
Report an issue: GitHub.
Appendix: source
Thrown at internal/configs/configschema/internal_validate.go:208
err = errors.Join(err, fmt.Errorf("%s%s: invalid nesting mode %s", prefix, name, a.NestedType.Nesting))
}
for name, attrS := range a.NestedType.Attributes {
if attrS == nil {
err = errors.Join(err, fmt.Errorf("%s%s: attribute schema is nil", prefix, name))
continue
}
err = errors.Join(err, attrS.internalValidate(name, prefix))
}
}
return err
}
func (o *Object) InternalValidate() error {
var err error
if o.Nesting == nestingModeInvalid {
return fmt.Errorf("object schema nesting mode is invalid")
}
for name, attrS := range o.Attributes {
if attrS == nil {
err = errors.Join(err, fmt.Errorf("%s: attribute schema is nil", name))
continue
}
err = errors.Join(err, attrS.internalValidate(name, ""))
}
return err
}
View on GitHub (pinned to d32a084675)