hashicorp/terraform · error

resource identity schema not found for type

Error message

resource identity schema not found for type %q

What it means

Returned by the tfplugin6 UpgradeResourceIdentity handler when the type is absent from p.identitySchemas.IdentityTypes (the dedicated identity-schema map, separate from ResourceTypes). Without a registered identity schema there is no target type to encode the upgraded identity into, so the upgrade is refused.

Solutions

  1. Confirm via `terraform providers schema -json` that the type exposes an identity schema.
  2. Upgrade the provider to a version that declares identity for the type.
  3. Clear stale identity state for the resource if identity is no longer supported.
  4. If developing the provider, register the type in identitySchemas.IdentityTypes.

Example fix

// before
p.identitySchemas.IdentityTypes = map[string]*config.Block{}
// after
p.identitySchemas.IdentityTypes = map[string]*config.Block{
    "aws_example_thing": identitySchema,
}
Defensive patterns

Strategy: validation

Validate before calling

// Before upgrading identity, confirm the type is registered for identity.
schemas, err := client.GetProviderIdentitySchema(ctx, &tfplugin6.GetProviderIdentitySchema_Request{})
if err != nil {
    return err
}
if _, ok := schemas.IdentitySchemas[typeName]; !ok {
    // nothing to upgrade; skip
    return nil
}
return client.UpgradeResourceIdentity(ctx, req)

Type guard

func identityUpgradeable(s *tfplugin6.GetProviderIdentitySchema_Response, typeName string) bool {
    _, ok := s.IdentitySchemas[typeName]
    return ok
}

Prevention

When it happens

Trigger: An UpgradeResourceIdentity RPC whose req.TypeName is missing from p.identitySchemas.IdentityTypes; the map lookup returns ok=false.

Common situations: Terraform core asks to upgrade identity for a resource that never declared one; identity state referencing a type the provider no longer knows; version skew where core has identity state but provider lacks identity schema.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/a27451cacdd33f71. Report an issue: GitHub.

Appendix: source

Thrown at internal/grpcwrap/provider6.go:821

func (p *provider6) GetResourceIdentitySchemas(_ context.Context, req *tfplugin6.GetResourceIdentitySchemas_Request) (*tfplugin6.GetResourceIdentitySchemas_Response, error) {
	resp := &tfplugin6.GetResourceIdentitySchemas_Response{
		IdentitySchemas: map[string]*tfplugin6.ResourceIdentitySchema{},
		Diagnostics:     []*tfplugin6.Diagnostic{},
	}

	for name, schema := range p.identitySchemas.IdentityTypes {
		resp.IdentitySchemas[name] = convert.ResourceIdentitySchemaToProto(schema)
	}

	resp.Diagnostics = convert.AppendProtoDiag(resp.Diagnostics, p.identitySchemas.Diagnostics)
	return resp, nil
}

func (p *provider6) UpgradeResourceIdentity(_ context.Context, req *tfplugin6.UpgradeResourceIdentity_Request) (*tfplugin6.UpgradeResourceIdentity_Response, error) {
	resp := &tfplugin6.UpgradeResourceIdentity_Response{}
	resource, ok := p.identitySchemas.IdentityTypes[req.TypeName]
	if !ok {
		return nil, fmt.Errorf("resource identity schema not found for type %q", req.TypeName)
	}
	ty := resource.Body.ImpliedType()

	upgradeResp := p.provider.UpgradeResourceIdentity(providers.UpgradeResourceIdentityRequest{
		TypeName:        req.TypeName,
		Version:         req.Version,
		RawIdentityJSON: req.RawIdentity.Json,
	})
	resp.Diagnostics = convert.AppendProtoDiag(resp.Diagnostics, upgradeResp.Diagnostics)

	if upgradeResp.Diagnostics.HasErrors() {
		return resp, nil
	}

	dv, err := encodeDynamicValue6(upgradeResp.UpgradedIdentity, ty)
	if err != nil {
		resp.Diagnostics = convert.AppendProtoDiag(resp.Diagnostics, err)
		return resp, nil

View on GitHub (pinned to d32a084675)