hashicorp/terraform · error
`resource_group_name` is required when…
Error message
`resource_group_name` is required when `lookup_blob_endpoint` is set
What it means
Validation error in Backend.Configure when resource_group_name is empty AND lookup_blob_endpoint = true, but the user did supply an auth method (so error 149 did not fire). lookup_blob_endpoint forces an ARM call to discover the real blob endpoint, and that ARM call needs the resource group to address the storage account; without it, the lookup cannot happen.
Solutions
- Add resource_group_name to the backend block.
- If naive URL is acceptable, remove lookup_blob_endpoint (or set it false).
- Re-run `terraform init -reconfigure` after fixing.
Example fix
// before
terraform {
backend "azurerm" {
storage_account_name = "acct"
container_name = "tfstate"
key = "prod.tfstate"
access_key = "<key>"
lookup_blob_endpoint = true
}
}
// after
terraform {
backend "azurerm" {
resource_group_name = "rg-tfstate"
storage_account_name = "acct"
container_name = "tfstate"
key = "prod.tfstate"
access_key = "<key>"
lookup_blob_endpoint = true
}
} Defensive patterns
Strategy: validation
Validate before calling
// Validate: lookup_blob_endpoint requires resource_group_name regardless of auth method.
func validateLookupEndpoint(b BackendConfig) error {
if b.LookupBlobEndpoint && b.ResourceGroupName == "" {
return fmt.Errorf("`resource_group_name` is required when `lookup_blob_endpoint` is set")
}
return nil
} Prevention
- When enabling lookup_blob_endpoint, also set resource_group_name by default.
- Document the dependency between lookup_blob_endpoint and resource_group_name in the backend module README.
- Use a config-lint rule (e.g. conftest/OPA) to flag lookup_blob_endpoint without resource_group_name.
When it happens
Trigger: Backend block sets lookup_blob_endpoint = true plus an auth method (access_key/sas/aad) but omits resource_group_name.
Common situations: Operator using private DNS or non-default endpoint needs the real endpoint discovered from ARM, but forgot the resource group; copied a config with lookup_blob_endpoint left enabled.
Related errors
- One of `access_key`, `sas_token`, `use_azuread_auth` and…
- auth must be one of ' ' or ' ' or ' ' or ' ' or ' ' or
- building Storage Accounts client: %+v
- can't delete default state
- failed to parse address URL
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/25d09300dc159c03.
Report an issue: GitHub.
Appendix: source
Thrown at internal/backend/remote-state/azure/backend.go:459
backendConfig := BackendConfig{
AuthConfig: authConfig,
SubscriptionID: data.String("subscription_id"),
ResourceGroupName: data.String("resource_group_name"),
StorageAccountName: data.String("storage_account_name"),
LookupBlobEndpoint: data.Bool("lookup_blob_endpoint"),
AccessKey: data.String("access_key"),
SasToken: data.String("sas_token"),
UseAzureADAuthentication: data.Bool("use_azuread_auth"),
}
needToLookupAccessKey := backendConfig.AccessKey == "" && backendConfig.SasToken == "" && !backendConfig.UseAzureADAuthentication
if backendConfig.ResourceGroupName == "" {
if needToLookupAccessKey {
return backendbase.ErrorAsDiagnostics(fmt.Errorf("One of `access_key`, `sas_token`, `use_azuread_auth` and `resource_group_name` must be specified"))
}
if backendConfig.LookupBlobEndpoint {
return backendbase.ErrorAsDiagnostics(fmt.Errorf("`resource_group_name` is required when `lookup_blob_endpoint` is set"))
}
}
client, err := buildClient(ctx, backendConfig)
if err != nil {
return backendbase.ErrorAsDiagnostics(err)
}
b.apiClient = client
return nil
}
View on GitHub (pinned to d32a084675)