hashicorp/terraform · error
errored.
Error message
%s errored.
What it means
Policy check entered tfe.PolicyErrored: the policy worker itself crashed/timed out without producing pass/fail. Unlike soft/hard failed, 'errored' means the policy engine could not evaluate, so the backend treats the run as failed without offering override.
Solutions
- Inspect the policy check logs in the TFE UI for the underlying runtime error.
- Fix policy syntax/module references and re-run.
- Increase policy worker resources / timeout if the cause is memory or time.
- Temporarily disable the broken policy set to unblock, then restore.
Defensive patterns
Strategy: validation
Validate before calling
// surface policy errors before they abort the run
func policySetHealthy(client *tfe.Client, org string) error {
sets, err := client.PolicySets.List(ctx, org, nil)
if err != nil { return err }
for _, ps := range sets.Items {
if ps.Status == "error" || ps.Status == "errored" {
return fmt.Errorf("policy set %s errored; check logs", ps.Name)
}
}
return nil
} Prevention
- Test policies in an advisory policy set before promoting to mandatory.
- Keep VCS keys for policy sets current.
- Monitor policy worker resources; raise limits on OOM.
- Validate sentinel syntax in CI before pushing.
When it happens
Trigger: pc.Status == tfe.PolicyErrored after the policy check completes: policy container OOM/killed; sentinel/opa runtime panic; policy worker timeout; misconfigured policy set referencing a missing module.
Common situations: Policy set points at a private VCS repo whose key rotated; sentinel policy syntax error; policy worker pod restarted during evaluation; large plan exceeded policy eval memory.
Related errors
- hard failed.
- soft failed.
- Failed to override
- Unknown or unexpected policy state
- backend does not support key/value tags. Try using key-only…
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/492d238357a0758d.
Report an issue: GitHub.
Appendix: source
Thrown at internal/cloud/backend_common.go:393
next = false
}
line = append(line, l...)
}
if next || len(line) > 0 {
b.CLI.Output(b.Colorize().Color(string(line)))
}
}
}
switch pc.Status {
case tfe.PolicyPasses:
if (r.HasChanges && op.Type == backendrun.OperationTypeApply || i < len(r.PolicyChecks)-1) && b.CLI != nil {
b.CLI.Output("\n------------------------------------------------------------------------")
}
continue
case tfe.PolicyErrored:
return fmt.Errorf("%s errored.", msgPrefix)
case tfe.PolicyHardFailed:
return fmt.Errorf("%s hard failed.", msgPrefix)
case tfe.PolicySoftFailed:
runURL := fmt.Sprintf(runHeaderErr, b.Hostname, b.Organization, op.Workspace, r.ID)
if op.Type == backendrun.OperationTypePlan || op.UIOut == nil || op.UIIn == nil ||
!pc.Actions.IsOverridable || !pc.Permissions.CanOverride {
return fmt.Errorf("%s soft failed.\n%s", msgPrefix, runURL)
}
if op.AutoApprove {
if _, err = b.client.PolicyChecks.Override(stopCtx, pc.ID); err != nil {
return b.generalError(fmt.Sprintf("Failed to override policy check.\n%s", runURL), err)
}
} else if !b.input {
return errPolicyOverrideNeedsUIConfirmation
} else {
opts := &terraform.InputOpts{View on GitHub (pinned to d32a084675)