hashicorp/terraform · error
Provider download blocked due to policy violations. Please…
Error message
Provider download blocked due to policy violations. Please review other diagnostics for details.
What it means
Returned by the provider policy hook (providerPolicyHook.ProviderVersionSelected) during terraform init when a configured policy client evaluates the selected provider version and result.Diagnostics.HasErrors() is true. Policy evaluation is advisory-aware: a deny without a hard error diagnostic still blocks, so init uses the diagnostics error flag as the gate. The actual violation details are emitted as separate diagnostics; this message is only the blocking summary telling the user to read them.
Solutions
- Read the companion diagnostics printed immediately before this error — they name the exact policy rule and provider attribute that failed.
- Adjust the required_provider version/source in the configuration to satisfy the policy (e.g. pin to an allowed version or switch namespace).
- If the violation is intentional and policy is wrong, update the policy rules in the policy source, then re-run terraform init.
- Confirm the policy client is pointed at the intended policy bundle; a stale or wrong endpoint can produce spurious denies.
Example fix
// before: policy denies version
terraform {
required_providers {
aws = { source = "hashicorp/aws", version = "~> 5.0" }
}
}
// after: pin to policy-approved version
terraform {
required_providers {
aws = { source = "hashicorp/aws", version = "= 5.40.0" }
}
} Defensive patterns
Strategy: validation
Validate before calling
// Pre-flight: check provider/version against the policy source before init.
// Requires the same policy client the init hook uses; evaluate and inspect result.Overall.
res := policyClient.EvaluateProvider(ctx, req)
if res.Overall == policy.Deny || res.Diagnostics.HasErrors() {
return fmt.Errorf("would be blocked by provider policy: %s", res.Diagnostics)
} Try / catch
// Wrap init in automation; on this specific error, surface the policy diagnostics
// and halt rather than retrying, since retry cannot change policy outcome.
out, err := runTerraform("init")
if err != nil && strings.Contains(out, "Provider download blocked due to policy violations") {
return extractPolicyDiagnostics(out) // parse the preceding diagnostics
} Prevention
- Keep provider versions within the centrally approved allow-list.
- Run policy evaluation in CI on the required_providers block before merging.
- Document the policy source so developers can self-diagnose denials.
When it happens
Trigger: terraform init (or any provider installation path) is run in a configuration with a provider policy client configured; policy.EvaluationRequest against provider metadata returns a result whose Diagnostics contain an Error severity, or result.Overall is deny with accompanying error diagnostics.
Common situations: Enterprise/regulated environments enforcing OPA/Sentinel-style provider allow-lists; a policy forbidding a provider namespace (e.g. community vs hashicorp), a specific version with a known CVE, or an untrusted registry; policy rules pushed centrally that the local config now violates.
Related errors
- failed to read dependency lock file
- the cached package for
- there is no package for
- action schema not found for action
- downloaded archive does not match the release checksum
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/1367a8800b3e5fff.
Report an issue: GitHub.
Appendix: source
Thrown at internal/command/meta_policy.go:175
Version: version,
},
})
// We use the root module as the module for provider configs since the version resolution
// is ambiguous, and we do not know which module the provider config belongs to.
addr := addrs.AbsProviderConfig{Provider: provider, Module: addrs.RootModule}
providerConfig := p.rootModule.ProviderConfigs[provider.Type]
if providerConfig != nil {
// Annotate the result diagnostics with the local range so that diagnostics can be rendered with both the
// policy source and the object being enforced.
result = result.WithLocalRange(providerConfig.DeclRange.Ptr())
}
p.view.PolicyResult(addr.String(), result)
log.Println("[DEBUG] init: policy result for provider", provider.String(), version, "overall", result.Overall)
// Init uses diagnostics as the blocking signal because advisory policies
// may return deny without any error diagnostics.
if result.Diagnostics.HasErrors() {
return fmt.Errorf("Provider download blocked due to policy violations. Please review other diagnostics for details.")
}
return nil
}
View on GitHub (pinned to d32a084675)