hashicorp/terraform · error

resource identity schema version

Error message

resource identity schema version %d for %s in state does not match version %d from the provider

What it means

Thrown by jsonstate when the state instance carries identity JSON (ri.Current.IdentityJSON != nil) and its identity schema version (IdentitySchemaVersion) does not match the provider's current identity schema version (schema.IdentityVersion). Identity is versioned separately from the main resource schema; a mismatch means the stored identity layout cannot be interpreted by the active provider.

Solutions

  1. Run `terraform apply -refresh-only` so the provider upgrades identity state to the current schema version.
  2. Align the provider version with the one that wrote the identity data.
  3. If identity is obsolete, clear it from state through a targeted state edit/refresh once the provider supports it.
  4. Restore a state backup whose identity schema version matches the configured provider.

Example fix

# state carries identity from provider 1.x; provider pinned to 2.x
required_providers { p = { version = "~> 1.0" } }  # match writer
# then terraform init && terraform apply -refresh-only to upgrade identity state
Defensive patterns

Strategy: validation

Validate before calling

if ri.Current.IdentityJSON != nil && int64(ri.Current.IdentitySchemaVersion) != schema.IdentityVersion {
    return fmt.Errorf("identity schema version %d for %s is stale (provider has %d); run 'terraform apply -refresh-only'", ri.Current.IdentitySchemaVersion, resAddr, schema.IdentityVersion)
}

Prevention

When it happens

Trigger: A provider upgrade changed its resource-identity schema version; state was written by a provider version with a different identity schema; identity state upgrade did not run (e.g. raw state push without refresh).

Common situations: Provider release that restructured resource identity; enabling/disabling an identity feature across provider versions; restoring identity-bearing state from a newer stack onto an older provider.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/d88e29ec154c7e3d. Report an issue: GitHub.

Appendix: source

Thrown at internal/command/jsonstate/state.go:433

				resAddr.Type,
			)

			// It is possible that the only instance is deposed
			if ri.Current != nil {
				if schema.Version != int64(ri.Current.SchemaVersion) {
					return nil, fmt.Errorf("schema version %d for %s in state does not match version %d from the provider", ri.Current.SchemaVersion, resAddr, schema.Version)
				}

				current.SchemaVersion = ri.Current.SchemaVersion

				if schema.Body == nil {
					return nil, fmt.Errorf("no schema found for %s (in provider %s)", resAddr.String(), r.ProviderConfig.Provider)
				}

				// Check if we have an identity in the state
				if ri.Current.IdentityJSON != nil {
					if schema.IdentityVersion != int64(ri.Current.IdentitySchemaVersion) {
						return nil, fmt.Errorf("resource identity schema version %d for %s in state does not match version %d from the provider", ri.Current.IdentitySchemaVersion, resAddr, schema.IdentityVersion)
					}

					if schema.Identity == nil {
						return nil, fmt.Errorf("no resource identity schema found for %s (in provider %s)", resAddr.String(), r.ProviderConfig.Provider)
					}

					current.IdentitySchemaVersion = &ri.Current.IdentitySchemaVersion
				}

				riObj, err := ri.Current.Decode(schema)
				if err != nil {
					return nil, err
				}

				var value cty.Value
				var sensitivePaths []cty.Path
				value, current.AttributeValues, sensitivePaths, err = marshalAttributeValues(riObj.Value)
				if err != nil {

View on GitHub (pinned to d32a084675)