hashicorp/terraform · error
retrieving container client
Error message
retrieving container client: %v
What it means
Wrapping error from Workspaces() when b.apiClient.getContainersClient(ctx) fails on first use. Propagates any of the underlying container-client construction errors (145, 146, 147, 148, or invalid base-URI).
Solutions
- Inspect the wrapped %v to identify which container-client error fired (145-148).
- Fix the underlying cause (URL / RBAC / key / AAD).
- Re-run `terraform init -reconfigure` then the workspace command.
Defensive patterns
Strategy: try-catch
Try / catch
// When listing workspaces, surface the underlying error verbosely.
ws, diags := backend.Workspaces()
if diags.HasErrors() {
for _, d := range diags {
if strings.Contains(d.Description().Summary, "retrieving container client") {
// log the inner error and run pre-flight checks for 145-148
}
}
} Prevention
- Resolve container-client errors (145-148) at init time before invoking workspace commands.
- Re-init with `terraform init -reconfigure` after auth changes.
- In CI, run `terraform workspace list` as a smoke test before plan/apply.
When it happens
Trigger: Any code path that lists workspaces (`terraform workspace list`, `terraform workspace select`, internal init enumeration) triggers the lazy container-client build; if that build fails, this wraps it.
Common situations: Workspace listing right after a misconfigured `terraform init`; auth expired between init and the workspace command; transient network failure.
Related errors
- new container client
- can't delete default state
- failed to lock azure state
- failed to retrieve lock info
- listing blobs
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/cc61cc3a452362c8.
Report an issue: GitHub.
Appendix: source
Thrown at internal/backend/remote-state/azure/backend_state.go:37
)
const (
// This will be used as directory name, the odd looking colon is simply to
// reduce the chance of name conflicts with existing objects.
keyEnvPrefix = "env:"
)
func (b *Backend) Workspaces() ([]string, tfdiags.Diagnostics) {
var diags tfdiags.Diagnostics
prefix := b.keyName + keyEnvPrefix
params := containers.ListBlobsInput{
Prefix: &prefix,
}
ctx := newCtx()
client, err := b.apiClient.getContainersClient(ctx)
if err != nil {
return nil, diags.Append(fmt.Errorf("retrieving container client: %v", err))
}
resp, err := client.ListBlobs(ctx, b.containerName, params)
if err != nil {
return nil, diags.Append(fmt.Errorf("listing blobs: %v", err))
}
envs := map[string]struct{}{}
for _, obj := range resp.Blobs.Blobs {
key := obj.Name
if strings.HasPrefix(key, prefix) {
name := strings.TrimPrefix(key, prefix)
// we store the state in a key, not a directory
if strings.Contains(name, "/") {
continue
}
envs[name] = struct{}{}
}View on GitHub (pinned to d32a084675)