hashicorp/terraform · error

errored.

Error message

%s errored.

What it means

Policy check entered tfe.PolicyErrored: the policy worker itself crashed/timed out without producing pass/fail. Unlike soft/hard failed, 'errored' means the policy engine could not evaluate, so the backend treats the run as failed without offering override.

Solutions

  1. Inspect the policy check logs in the TFE UI for the underlying runtime error.
  2. Fix policy syntax/module references and re-run.
  3. Increase policy worker resources / timeout if the cause is memory or time.
  4. Temporarily disable the broken policy set to unblock, then restore.
Defensive patterns

Strategy: validation

Validate before calling

// surface policy errors before they abort the run
func policySetHealthy(client *tfe.Client, org string) error {
    sets, err := client.PolicySets.List(ctx, org, nil)
    if err != nil { return err }
    for _, ps := range sets.Items {
        if ps.Status == "error" || ps.Status == "errored" {
            return fmt.Errorf("policy set %s errored; check logs", ps.Name)
        }
    }
    return nil
}

Prevention

When it happens

Trigger: pc.Status == tfe.PolicyErrored after the policy check completes: policy container OOM/killed; sentinel/opa runtime panic; policy worker timeout; misconfigured policy set referencing a missing module.

Common situations: Policy set points at a private VCS repo whose key rotated; sentinel policy syntax error; policy worker pod restarted during evaluation; large plan exceeded policy eval memory.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/492d238357a0758d. Report an issue: GitHub.

Appendix: source

Thrown at internal/cloud/backend_common.go:393

						next = false
					}
					line = append(line, l...)
				}

				if next || len(line) > 0 {
					b.CLI.Output(b.Colorize().Color(string(line)))
				}
			}
		}

		switch pc.Status {
		case tfe.PolicyPasses:
			if (r.HasChanges && op.Type == backendrun.OperationTypeApply || i < len(r.PolicyChecks)-1) && b.CLI != nil {
				b.CLI.Output("\n------------------------------------------------------------------------")
			}
			continue
		case tfe.PolicyErrored:
			return fmt.Errorf("%s errored.", msgPrefix)
		case tfe.PolicyHardFailed:
			return fmt.Errorf("%s hard failed.", msgPrefix)
		case tfe.PolicySoftFailed:
			runURL := fmt.Sprintf(runHeaderErr, b.Hostname, b.Organization, op.Workspace, r.ID)

			if op.Type == backendrun.OperationTypePlan || op.UIOut == nil || op.UIIn == nil ||
				!pc.Actions.IsOverridable || !pc.Permissions.CanOverride {
				return fmt.Errorf("%s soft failed.\n%s", msgPrefix, runURL)
			}

			if op.AutoApprove {
				if _, err = b.client.PolicyChecks.Override(stopCtx, pc.ID); err != nil {
					return b.generalError(fmt.Sprintf("Failed to override policy check.\n%s", runURL), err)
				}
			} else if !b.input {
				return errPolicyOverrideNeedsUIConfirmation
			} else {
				opts := &terraform.InputOpts{

View on GitHub (pinned to d32a084675)