hashicorp/terraform · error

cannot be higher than

Error message

%q cannot be higher than %d: %d

What it means

Companion of 191 from the same validateIntegerInRange: emits when the ranged integer exceeds its maximum. For assume_role.session_duration the cap is 43200 seconds (12h).

Solutions

  1. Lower session_duration to <= 43200 seconds.
  2. Re-run terraform init.

Example fix

// before
assume_role {
  session_duration = 86400
}

// after
assume_role {
  session_duration = 43200
}
Defensive patterns

Strategy: validation

Validate before calling

// Reuse the same validator as 191.
func validateIntInRange(min, max int64, v int) error {
    if int64(v) < min {
        return fmt.Errorf("value %d cannot be lower than %d", v, min)
    }
    if int64(v) > max {
        return fmt.Errorf("value %d cannot be higher than %d", v, max)
    }
    return nil
}

Prevention

When it happens

Trigger: terraform init with assume_role.session_duration > 43200.

Common situations: User enters seconds assuming a larger unit; intends 12h+; typos an extra digit.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/a6800872dceeded4. Report an issue: GitHub.

Appendix: source

Thrown at internal/backend/remote-state/cos/backend.go:260

			},
		},
	}

	result := &Backend{Backend: s}
	result.Backend.ConfigureFunc = result.configure

	return result
}

func validateIntegerInRange(min, max int64) schema.SchemaValidateFunc {
	return func(v interface{}, k string) (ws []string, errors []error) {
		value := int64(v.(int))
		if value < min {
			errors = append(errors, fmt.Errorf(
				"%q cannot be lower than %d: %d", k, min, value))
		}
		if value > max {
			errors = append(errors, fmt.Errorf(
				"%q cannot be higher than %d: %d", k, max, value))
		}
		return
	}
}

// configure init cos client
func (b *Backend) configure(ctx context.Context) error {
	if b.cosClient != nil {
		return nil
	}

	b.cosContext = ctx
	data := schema.FromContextBackendConfig(b.cosContext)

	b.region = data.Get("region").(string)
	b.bucket = data.Get("bucket").(string)
	b.prefix = data.Get("prefix").(string)

View on GitHub (pinned to d32a084675)