hashicorp/terraform · error
cannot be higher than
Error message
%q cannot be higher than %d: %d
What it means
Companion of 191 from the same validateIntegerInRange: emits when the ranged integer exceeds its maximum. For assume_role.session_duration the cap is 43200 seconds (12h).
Solutions
- Lower session_duration to <= 43200 seconds.
- Re-run terraform init.
Example fix
// before
assume_role {
session_duration = 86400
}
// after
assume_role {
session_duration = 43200
} Defensive patterns
Strategy: validation
Validate before calling
// Reuse the same validator as 191.
func validateIntInRange(min, max int64, v int) error {
if int64(v) < min {
return fmt.Errorf("value %d cannot be lower than %d", v, min)
}
if int64(v) > max {
return fmt.Errorf("value %d cannot be higher than %d", v, max)
}
return nil
} Prevention
- Cap session_duration at 43200 (12h); use shorter-lived sessions where possible.
- Lint backend blocks in CI.
- Document the unit (seconds) next to every duration field.
- Use CAM session policies instead of stretching duration.
When it happens
Trigger: terraform init with assume_role.session_duration > 43200.
Common situations: User enters seconds assuming a larger unit; intends 12h+; typos an extra digit.
Related errors
- cannot be lower than
- acl value invalid, expected
- Invalid URL: must be
- key can not start and end with '/'
- prefix must not start with '/' or './'
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/a6800872dceeded4.
Report an issue: GitHub.
Appendix: source
Thrown at internal/backend/remote-state/cos/backend.go:260
},
},
}
result := &Backend{Backend: s}
result.Backend.ConfigureFunc = result.configure
return result
}
func validateIntegerInRange(min, max int64) schema.SchemaValidateFunc {
return func(v interface{}, k string) (ws []string, errors []error) {
value := int64(v.(int))
if value < min {
errors = append(errors, fmt.Errorf(
"%q cannot be lower than %d: %d", k, min, value))
}
if value > max {
errors = append(errors, fmt.Errorf(
"%q cannot be higher than %d: %d", k, max, value))
}
return
}
}
// configure init cos client
func (b *Backend) configure(ctx context.Context) error {
if b.cosClient != nil {
return nil
}
b.cosContext = ctx
data := schema.FromContextBackendConfig(b.cosContext)
b.region = data.Get("region").(string)
b.bucket = data.Get("bucket").(string)
b.prefix = data.Get("prefix").(string)View on GitHub (pinned to d32a084675)