hashicorp/terraform · error
populating details for
Error message
populating details for %s: %+v
What it means
Thrown by buildClient when, after fetching the Storage Account via storageAccountsClient.GetProperties, the helper populateAccountDetails returns an error. That helper fails only when the ARM response is missing nested payloads: account.Properties == nil or account.Properties.PrimaryEndpoints == nil. In other words the ARM GetProperties call succeeded (HTTP 200) but the returned model is missing the data-plane endpoint information the backend needs to build the blob/container clients.
Solutions
- Wait a few minutes and re-run `terraform init` (transient ARM state during account provisioning).
- Confirm via `az storage account show -g <rg> -n <acct>` that properties.primaryEndpoints.blob is populated; if not, the account is unhealthy.
- Provide an explicit access_key or sas_token in the backend block to bypass ARM lookup entirely.
- If reproducible, set use_azuread_auth = true to skip the populateAccountDetails code path.
- Open an Azure support ticket if the ARM API consistently returns nil properties for a healthy account.
Defensive patterns
Strategy: retry
Validate before calling
// Pre-flight: confirm the ARM StorageAccount has the nested payloads buildClient needs.
func storageAccountHasEndpoints(ctx context.Context, c *storageaccounts.StorageAccountsClient, id commonids.StorageAccountId) error {
resp, err := c.GetProperties(ctx, id, storageaccounts.DefaultGetPropertiesOperationOptions())
if err != nil { return err }
if resp.Model == nil || resp.Model.Properties == nil || resp.Model.Properties.PrimaryEndpoints == nil {
return fmt.Errorf("storage account %s missing Properties/PrimaryEndpoints", id)
}
return nil
} Try / catch
// buildClient wraps populateAccountDetails; retry with backoff for transient ARM nil-properties.
var client *azure.Client
err := backoff.Retry(func() error {
c, err := azure.BuildClient(ctx, cfg)
if err != nil {
if strings.Contains(err.Error(), "populating details") { return err }
return backoff.Permanent(err)
}
client = c
return nil
}, backoff.NewExponentialBackOff()) Prevention
- Pre-warm new storage accounts: wait until `az storage account show` returns populated primaryEndpoints before running terraform init.
- Provide access_key or sas_token in CI to bypass the ARM lookup path entirely.
- Prefer use_azuread_auth = true to skip populateAccountDetails.
When it happens
Trigger: buildClient reaches populateAccountDetails (requires armAuthRequired == true, i.e. lookup_blob_endpoint set, or no access_key/sas/aad). The ARM-returned StorageAccount has nil Properties or nil Properties.PrimaryEndpoints.
Common situations: Storage account still provisioning (transient ARM state); ARM returned a stale or degraded response during a region incident; account was created by tooling that produced a non-standard SKU layout (e.g. premium-only) exposing no blob PrimaryEndpoints; rare SDK contract violation across API versions.
Related errors
- building Storage Accounts client: %+v
- new blob client
- new container client
- One of `access_key`, `sas_token`, `use_azuread_auth` and…
- retrieving key for Storage Account
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/df6daa238b31ffa0.
Report an issue: GitHub.
Appendix: source
Thrown at internal/backend/remote-state/azure/api_client.go:113
// Setup the SA client.
client.storageAccountsClient, err = storageaccounts.NewStorageAccountsClientWithBaseURI(config.AuthConfig.Environment.ResourceManager)
if err != nil {
return nil, fmt.Errorf("building Storage Accounts client: %+v", err)
}
client.configureClient(client.storageAccountsClient.Client, resourceManagerAuth)
// Populating the storage account detail
storageAccountId := commonids.NewStorageAccountID(config.SubscriptionID, config.ResourceGroupName, client.storageAccountName)
resp, err := client.storageAccountsClient.GetProperties(ctx, storageAccountId, storageaccounts.DefaultGetPropertiesOperationOptions())
if err != nil {
return nil, fmt.Errorf("retrieving %s: %+v", storageAccountId, err)
}
if resp.Model == nil {
return nil, fmt.Errorf("retrieving %s: model was nil", storageAccountId)
}
client.accountDetail, err = populateAccountDetails(storageAccountId, *resp.Model)
if err != nil {
return nil, fmt.Errorf("populating details for %s: %+v", storageAccountId, err)
}
}
return &client, nil
}
func (c *Client) getBlobClient(ctx context.Context) (bc *blobs.Client, err error) {
if c.blobsClient != nil {
return c.blobsClient, nil
}
defer func() {
if err == nil {
c.blobsClient = bc
}
}()
var baseUri stringView on GitHub (pinned to d32a084675)