hashicorp/terraform · error

preparing attribute values for

Error message

preparing attribute values for %s: %w

What it means

Thrown by jsonstate while marshaling the current resource instance: marshalAttributeValues(riObj.Value) failed and the error is wrapped with the resource address. The underlying cause is a cty value (decoded via ri.Current.Decode(schema)) that cannot be transcoded into the JSON attribute map, typically because its type/shape disagrees with what marshalAttributeValues expects or it carries unhandled marks.

Solutions

  1. Run `terraform apply -refresh-only` to recompute the instance value from the provider.
  2. Align provider and Terraform versions with the state's origin.
  3. Inspect the wrapped error (the %w) for the precise marshal failure and address that root cause.
  4. If state is corrupt, restore from backup or use `terraform state pull`/edit/`push` to repair the instance.
Defensive patterns

Strategy: try-catch

Try / catch

if _, err := jsonstate.Marshal(state, schemas); err != nil {
    var se interface{ Unwrap() error }
    if errors.As(err, &se) {
        // inspect the wrapped marshal failure to pinpoint the attribute/type
        log.Printf("attribute marshal failed: %v", se.Unwrap())
    }
    return err
}

Prevention

When it happens

Trigger: The decoded resource value has a nested type marshalAttributeValues cannot walk; a value carries an unhandled cty mark; provider schema/data mismatch producing a malformed value; corrupt state bytes that decode to an unexpected shape.

Common situations: State written by an incompatible provider/Terraform version; provider returning attributes whose types changed without a schema-version bump; manually edited state.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/28adbda454861e96. Report an issue: GitHub.

Appendix: source

Thrown at internal/command/jsonstate/state.go:452

					}

					if schema.Identity == nil {
						return nil, fmt.Errorf("no resource identity schema found for %s (in provider %s)", resAddr.String(), r.ProviderConfig.Provider)
					}

					current.IdentitySchemaVersion = &ri.Current.IdentitySchemaVersion
				}

				riObj, err := ri.Current.Decode(schema)
				if err != nil {
					return nil, err
				}

				var value cty.Value
				var sensitivePaths []cty.Path
				value, current.AttributeValues, sensitivePaths, err = marshalAttributeValues(riObj.Value)
				if err != nil {
					return nil, fmt.Errorf("preparing attribute values for %s: %w", current.Address, err)
				}
				sensitivePaths = append(sensitivePaths, schema.Body.SensitivePaths(value, nil)...)
				s := SensitiveAsBool(marks.MarkPaths(value, marks.Sensitive, sensitivePaths))
				v, err := ctyjson.Marshal(s, s.Type())
				if err != nil {
					return nil, err
				}
				current.SensitiveValues = v

				current.IdentityValues, err = marshalIdentityValues(riObj.Identity)
				if err != nil {
					return nil, fmt.Errorf("preparing identity values for %s: %w", current.Address, err)
				}

				if len(riObj.Dependencies) > 0 {
					dependencies := make([]string, len(riObj.Dependencies))
					for i, v := range riObj.Dependencies {
						dependencies[i] = v.String()

View on GitHub (pinned to d32a084675)