hashicorp/terraform · error
cannot be lower than
Error message
%q cannot be lower than %d: %d
What it means
validateIntegerInRange emits this when a ranged integer attribute is below its minimum. Today the function backs assume_role.session_duration (0..43200 seconds). The error names the attribute (k), the minimum, and the supplied value.
Solutions
- Set session_duration to a value within the documented range (0..43200 seconds for assume_role).
- Re-run terraform init.
Example fix
// before
assume_role {
session_duration = -1
}
// after
assume_role {
session_duration = 7200
} Defensive patterns
Strategy: validation
Validate before calling
// Validate an integer is within [min,max] before passing it to the schema.
func validateIntInRange(min, max int64, v int) error {
if int64(v) < min {
return fmt.Errorf("value %d cannot be lower than %d", v, min)
}
if int64(v) > max {
return fmt.Errorf("value %d cannot be higher than %d", v, max)
}
return nil
} Prevention
- Read the schema docs: assume_role.session_duration is seconds in [0,43200].
- Lint backend blocks in CI to catch out-of-range integers.
- Don't confuse seconds with minutes/hours when filling durations.
- Prefer env-var defaults (TENCENTCLOUD_ASSUME_ROLE_SESSION_DURATION) consistent across team.
When it happens
Trigger: terraform init with assume_role.session_duration (or another ranged int) set below the schema minimum (e.g. negative or below 0 for session_duration).
Common situations: Mis-typed duration; assumed minutes instead of seconds; attempted to disable sessions with a negative number.
Related errors
- cannot be higher than
- acl value invalid, expected
- Invalid URL: must be
- key can not start and end with '/'
- prefix must not start with '/' or './'
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/43e7c1d77bb6a760.
Report an issue: GitHub.
Appendix: source
Thrown at internal/backend/remote-state/cos/backend.go:256
Type: schema.TypeString,
Optional: true,
DefaultFunc: schema.EnvDefaultFunc(PROVIDER_CAM_ROLE_NAME, nil),
Description: "The name of the CVM instance CAM role. It can be sourced from the `TENCENTCLOUD_CAM_ROLE_NAME` environment variable.",
},
},
}
result := &Backend{Backend: s}
result.Backend.ConfigureFunc = result.configure
return result
}
func validateIntegerInRange(min, max int64) schema.SchemaValidateFunc {
return func(v interface{}, k string) (ws []string, errors []error) {
value := int64(v.(int))
if value < min {
errors = append(errors, fmt.Errorf(
"%q cannot be lower than %d: %d", k, min, value))
}
if value > max {
errors = append(errors, fmt.Errorf(
"%q cannot be higher than %d: %d", k, max, value))
}
return
}
}
// configure init cos client
func (b *Backend) configure(ctx context.Context) error {
if b.cosClient != nil {
return nil
}
b.cosContext = ctx
data := schema.FromContextBackendConfig(b.cosContext)View on GitHub (pinned to d32a084675)