hashicorp/terraform · error

attribute is read-only

Error message

%q attribute is read-only

What it means

The terraform_data resource's config validator rejects any attempt to set the 'id' or 'output' attributes in HCL configuration. Both attributes are declared Computed in the schema (resource_data.go:22,30), meaning they are provider-managed outputs, not user inputs. Because Terraform Core does not currently enforce 'do not set computed attributes in config', this provider performs the check manually.

Solutions

  1. Remove the 'id' and 'output' attributes from your terraform_data resource configuration blocks.
  2. Use the 'input' attribute for providing values to terraform_data; 'output' will reflect 'input' after apply.
  3. If you need to import a terraform_data resource, use `terraform import` and let the provider manage the ID.

Example fix

# before
resource "terraform_data" "example" {
  id     = "my-id"
  output = "some-value"
  input  = "hello"
}

# after — id and output are read-only
resource "terraform_data" "example" {
  input = "hello"
}
Defensive patterns

Strategy: validation

Validate before calling

# In HCL, do not set computed attributes:
// Before applying, verify no computed attributes are in config
for _, attr := range []string{"id", "output"} {
    if !config.GetAttr(attr).IsNull() {
        return fmt.Errorf("%q is computed and cannot be set in configuration", attr)
    }
}

Prevention

When it happens

Trigger: Calling validateDataStoreResourceConfig (resource_data.go:80-93) when req.Config has a non-null value for either 'id' or 'output'. This happens when a user writes `resource "terraform_data" "x" { id = "..." }` or `output = "..."` in their HCL.

Common situations: Copying an imported resource's ID back into the configuration block. Attempting to pre-set the output value of a terraform_data resource. Misunderstanding the Computed semantics and trying to supply these as inputs.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/51522a69f8ba4fb1. Report an issue: GitHub.

Appendix: source

Thrown at internal/builtin/providers/terraform/resource_data.go:89

					Description: "The unique identifier for the data store.",
					Required:    true,
				},
			},
			Nesting: configschema.NestingSingle,
		},
	}
}

func validateDataStoreResourceConfig(req providers.ValidateResourceConfigRequest) (resp providers.ValidateResourceConfigResponse) {
	if req.Config.IsNull() {
		return resp
	}

	// Core does not currently validate computed values are not set in the
	// configuration.
	for _, attr := range []string{"id", "output"} {
		if !req.Config.GetAttr(attr).IsNull() {
			resp.Diagnostics = resp.Diagnostics.Append(fmt.Errorf(`%q attribute is read-only`, attr))
		}
	}
	return resp
}

func upgradeDataStoreResourceState(req providers.UpgradeResourceStateRequest) (resp providers.UpgradeResourceStateResponse) {
	// We've only added new nullable block attributes, so unmarshaling from json
	// will complete the data structure correctly.
	val, err := ctyjson.Unmarshal(req.RawStateJSON, dataStoreResourceSchema().Body.ImpliedType())
	if err != nil {
		resp.Diagnostics = resp.Diagnostics.Append(err)
		return resp
	}

	resp.UpgradedState = val
	return resp
}

View on GitHub (pinned to d32a084675)