hashicorp/terraform · error

populating details for

Error message

populating details for %s: %+v

What it means

Thrown by buildClient when, after fetching the Storage Account via storageAccountsClient.GetProperties, the helper populateAccountDetails returns an error. That helper fails only when the ARM response is missing nested payloads: account.Properties == nil or account.Properties.PrimaryEndpoints == nil. In other words the ARM GetProperties call succeeded (HTTP 200) but the returned model is missing the data-plane endpoint information the backend needs to build the blob/container clients.

Solutions

  1. Wait a few minutes and re-run `terraform init` (transient ARM state during account provisioning).
  2. Confirm via `az storage account show -g <rg> -n <acct>` that properties.primaryEndpoints.blob is populated; if not, the account is unhealthy.
  3. Provide an explicit access_key or sas_token in the backend block to bypass ARM lookup entirely.
  4. If reproducible, set use_azuread_auth = true to skip the populateAccountDetails code path.
  5. Open an Azure support ticket if the ARM API consistently returns nil properties for a healthy account.
Defensive patterns

Strategy: retry

Validate before calling

// Pre-flight: confirm the ARM StorageAccount has the nested payloads buildClient needs.
func storageAccountHasEndpoints(ctx context.Context, c *storageaccounts.StorageAccountsClient, id commonids.StorageAccountId) error {
    resp, err := c.GetProperties(ctx, id, storageaccounts.DefaultGetPropertiesOperationOptions())
    if err != nil { return err }
    if resp.Model == nil || resp.Model.Properties == nil || resp.Model.Properties.PrimaryEndpoints == nil {
        return fmt.Errorf("storage account %s missing Properties/PrimaryEndpoints", id)
    }
    return nil
}

Try / catch

// buildClient wraps populateAccountDetails; retry with backoff for transient ARM nil-properties.
var client *azure.Client
err := backoff.Retry(func() error {
    c, err := azure.BuildClient(ctx, cfg)
    if err != nil {
        if strings.Contains(err.Error(), "populating details") { return err }
        return backoff.Permanent(err)
    }
    client = c
    return nil
}, backoff.NewExponentialBackOff())

Prevention

When it happens

Trigger: buildClient reaches populateAccountDetails (requires armAuthRequired == true, i.e. lookup_blob_endpoint set, or no access_key/sas/aad). The ARM-returned StorageAccount has nil Properties or nil Properties.PrimaryEndpoints.

Common situations: Storage account still provisioning (transient ARM state); ARM returned a stale or degraded response during a region incident; account was created by tooling that produced a non-standard SKU layout (e.g. premium-only) exposing no blob PrimaryEndpoints; rare SDK contract violation across API versions.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/df6daa238b31ffa0. Report an issue: GitHub.

Appendix: source

Thrown at internal/backend/remote-state/azure/api_client.go:113

		// Setup the SA client.
		client.storageAccountsClient, err = storageaccounts.NewStorageAccountsClientWithBaseURI(config.AuthConfig.Environment.ResourceManager)
		if err != nil {
			return nil, fmt.Errorf("building Storage Accounts client: %+v", err)
		}
		client.configureClient(client.storageAccountsClient.Client, resourceManagerAuth)

		// Populating the storage account detail
		storageAccountId := commonids.NewStorageAccountID(config.SubscriptionID, config.ResourceGroupName, client.storageAccountName)
		resp, err := client.storageAccountsClient.GetProperties(ctx, storageAccountId, storageaccounts.DefaultGetPropertiesOperationOptions())
		if err != nil {
			return nil, fmt.Errorf("retrieving %s: %+v", storageAccountId, err)
		}
		if resp.Model == nil {
			return nil, fmt.Errorf("retrieving %s: model was nil", storageAccountId)
		}
		client.accountDetail, err = populateAccountDetails(storageAccountId, *resp.Model)
		if err != nil {
			return nil, fmt.Errorf("populating details for %s: %+v", storageAccountId, err)
		}
	}

	return &client, nil
}

func (c *Client) getBlobClient(ctx context.Context) (bc *blobs.Client, err error) {
	if c.blobsClient != nil {
		return c.blobsClient, nil
	}

	defer func() {
		if err == nil {
			c.blobsClient = bc
		}
	}()

	var baseUri string

View on GitHub (pinned to d32a084675)