hashicorp/terraform · error

preparing identity values for

Error message

preparing identity values for %s: %w

What it means

Thrown by jsonstate right after the attribute-values step: marshalIdentityValues(riObj.Identity) failed and the error is wrapped with the resource address. It means the resource's identity cty value could not be converted to the JSON identity representation, usually because the identity value's type disagrees with the identity schema or it is malformed.

Solutions

  1. Run `terraform apply -refresh-only` to refresh identity from the provider.
  2. Align the provider version with the state's identity schema.
  3. Examine the wrapped (%w) error for the specific marshal failure.
  4. Clear or repair the identity entry via `terraform state pull`/edit/`push` if it is corrupt.
Defensive patterns

Strategy: try-catch

Try / catch

if _, err := jsonstate.Marshal(state, schemas); err != nil {
    if strings.Contains(err.Error(), "preparing identity values") {
        log.Printf("identity marshal failed for a resource; run 'terraform apply -refresh-only' or align provider version: %v", err)
    }
    return err
}

Prevention

When it happens

Trigger: Identity value decoded with a schema whose shape differs from the stored bytes; identity value carries marks/types marshalIdentityValues rejects; provider identity schema/value mismatch after a version change.

Common situations: Provider upgrade changing identity shape without a matching identity-schema-version bump; corrupt identity bytes in state; forked provider with divergent identity handling.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/afcc5a4e95522502. Report an issue: GitHub.

Appendix: source

Thrown at internal/command/jsonstate/state.go:464

				}

				var value cty.Value
				var sensitivePaths []cty.Path
				value, current.AttributeValues, sensitivePaths, err = marshalAttributeValues(riObj.Value)
				if err != nil {
					return nil, fmt.Errorf("preparing attribute values for %s: %w", current.Address, err)
				}
				sensitivePaths = append(sensitivePaths, schema.Body.SensitivePaths(value, nil)...)
				s := SensitiveAsBool(marks.MarkPaths(value, marks.Sensitive, sensitivePaths))
				v, err := ctyjson.Marshal(s, s.Type())
				if err != nil {
					return nil, err
				}
				current.SensitiveValues = v

				current.IdentityValues, err = marshalIdentityValues(riObj.Identity)
				if err != nil {
					return nil, fmt.Errorf("preparing identity values for %s: %w", current.Address, err)
				}

				if len(riObj.Dependencies) > 0 {
					dependencies := make([]string, len(riObj.Dependencies))
					for i, v := range riObj.Dependencies {
						dependencies[i] = v.String()
					}
					current.DependsOn = dependencies
				}

				if riObj.Status == states.ObjectTainted {
					current.Tainted = true
				}
				ret = append(ret, current)
			}

			for _, deposedKey := range slices.Sorted(maps.Keys(ri.Deposed)) {
				rios := ri.Deposed[states.DeposedKey(deposedKey)]

View on GitHub (pinned to d32a084675)