hashicorp/terraform · error

`resource_group_name` is required when…

Error message

`resource_group_name` is required when `lookup_blob_endpoint` is set

What it means

Validation error in Backend.Configure when resource_group_name is empty AND lookup_blob_endpoint = true, but the user did supply an auth method (so error 149 did not fire). lookup_blob_endpoint forces an ARM call to discover the real blob endpoint, and that ARM call needs the resource group to address the storage account; without it, the lookup cannot happen.

Solutions

  1. Add resource_group_name to the backend block.
  2. If naive URL is acceptable, remove lookup_blob_endpoint (or set it false).
  3. Re-run `terraform init -reconfigure` after fixing.

Example fix

// before
terraform {
  backend "azurerm" {
    storage_account_name = "acct"
    container_name       = "tfstate"
    key                  = "prod.tfstate"
    access_key           = "<key>"
    lookup_blob_endpoint = true
  }
}
// after
terraform {
  backend "azurerm" {
    resource_group_name  = "rg-tfstate"
    storage_account_name = "acct"
    container_name       = "tfstate"
    key                  = "prod.tfstate"
    access_key           = "<key>"
    lookup_blob_endpoint = true
  }
}
Defensive patterns

Strategy: validation

Validate before calling

// Validate: lookup_blob_endpoint requires resource_group_name regardless of auth method.
func validateLookupEndpoint(b BackendConfig) error {
    if b.LookupBlobEndpoint && b.ResourceGroupName == "" {
        return fmt.Errorf("`resource_group_name` is required when `lookup_blob_endpoint` is set")
    }
    return nil
}

Prevention

When it happens

Trigger: Backend block sets lookup_blob_endpoint = true plus an auth method (access_key/sas/aad) but omits resource_group_name.

Common situations: Operator using private DNS or non-default endpoint needs the real endpoint discovered from ARM, but forgot the resource group; copied a config with lookup_blob_endpoint left enabled.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/25d09300dc159c03. Report an issue: GitHub.

Appendix: source

Thrown at internal/backend/remote-state/azure/backend.go:459

	backendConfig := BackendConfig{
		AuthConfig:               authConfig,
		SubscriptionID:           data.String("subscription_id"),
		ResourceGroupName:        data.String("resource_group_name"),
		StorageAccountName:       data.String("storage_account_name"),
		LookupBlobEndpoint:       data.Bool("lookup_blob_endpoint"),
		AccessKey:                data.String("access_key"),
		SasToken:                 data.String("sas_token"),
		UseAzureADAuthentication: data.Bool("use_azuread_auth"),
	}

	needToLookupAccessKey := backendConfig.AccessKey == "" && backendConfig.SasToken == "" && !backendConfig.UseAzureADAuthentication
	if backendConfig.ResourceGroupName == "" {
		if needToLookupAccessKey {
			return backendbase.ErrorAsDiagnostics(fmt.Errorf("One of `access_key`, `sas_token`, `use_azuread_auth` and `resource_group_name` must be specified"))
		}
		if backendConfig.LookupBlobEndpoint {
			return backendbase.ErrorAsDiagnostics(fmt.Errorf("`resource_group_name` is required when `lookup_blob_endpoint` is set"))
		}
	}

	client, err := buildClient(ctx, backendConfig)
	if err != nil {
		return backendbase.ErrorAsDiagnostics(err)
	}

	b.apiClient = client
	return nil
}

View on GitHub (pinned to d32a084675)