hashicorp/terraform · error
attribute is read-only
Error message
%q attribute is read-only
What it means
The terraform_data resource's config validator rejects any attempt to set the 'id' or 'output' attributes in HCL configuration. Both attributes are declared Computed in the schema (resource_data.go:22,30), meaning they are provider-managed outputs, not user inputs. Because Terraform Core does not currently enforce 'do not set computed attributes in config', this provider performs the check manually.
Solutions
- Remove the 'id' and 'output' attributes from your terraform_data resource configuration blocks.
- Use the 'input' attribute for providing values to terraform_data; 'output' will reflect 'input' after apply.
- If you need to import a terraform_data resource, use `terraform import` and let the provider manage the ID.
Example fix
# before
resource "terraform_data" "example" {
id = "my-id"
output = "some-value"
input = "hello"
}
# after — id and output are read-only
resource "terraform_data" "example" {
input = "hello"
} Defensive patterns
Strategy: validation
Validate before calling
# In HCL, do not set computed attributes:
// Before applying, verify no computed attributes are in config
for _, attr := range []string{"id", "output"} {
if !config.GetAttr(attr).IsNull() {
return fmt.Errorf("%q is computed and cannot be set in configuration", attr)
}
} Prevention
- Never set 'id' or 'output' in a terraform_data resource block — both are Computed.
- Use 'terraform import' to bring existing terraform_data resources under management rather than hardcoding IDs.
- Rely on the 'input' attribute for providing values; 'output' is automatically derived.
When it happens
Trigger: Calling validateDataStoreResourceConfig (resource_data.go:80-93) when req.Config has a non-null value for either 'id' or 'output'. This happens when a user writes `resource "terraform_data" "x" { id = "..." }` or `output = "..."` in their HCL.
Common situations: Copying an imported resource's ID back into the configuration block. Attempting to pre-set the output value of a terraform_data resource. Misunderstanding the Computed semantics and trying to supply these as inputs.
Related errors
- all arguments must have the same type
- argument must be a list or tuple
- argument must be a string, a collection type, or a…
- at most 1 action can be invoked per operation
- can't delete default state
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/51522a69f8ba4fb1.
Report an issue: GitHub.
Appendix: source
Thrown at internal/builtin/providers/terraform/resource_data.go:89
Description: "The unique identifier for the data store.",
Required: true,
},
},
Nesting: configschema.NestingSingle,
},
}
}
func validateDataStoreResourceConfig(req providers.ValidateResourceConfigRequest) (resp providers.ValidateResourceConfigResponse) {
if req.Config.IsNull() {
return resp
}
// Core does not currently validate computed values are not set in the
// configuration.
for _, attr := range []string{"id", "output"} {
if !req.Config.GetAttr(attr).IsNull() {
resp.Diagnostics = resp.Diagnostics.Append(fmt.Errorf(`%q attribute is read-only`, attr))
}
}
return resp
}
func upgradeDataStoreResourceState(req providers.UpgradeResourceStateRequest) (resp providers.UpgradeResourceStateResponse) {
// We've only added new nullable block attributes, so unmarshaling from json
// will complete the data structure correctly.
val, err := ctyjson.Unmarshal(req.RawStateJSON, dataStoreResourceSchema().Body.ImpliedType())
if err != nil {
resp.Diagnostics = resp.Diagnostics.Append(err)
return resp
}
resp.UpgradedState = val
return resp
}
View on GitHub (pinned to d32a084675)