hashicorp/terraform · error
errored.
Error message
%s errored.
What it means
Returned by the policy-check watcher when a policy check's status is tfe.PolicyErrored. 'Errored' is distinct from failed: the policy engine could not complete evaluation (runtime/Sentinel error), so the result is indeterminate rather than a clear pass/fail.
Solutions
- Open the run in the TFC/TFE UI and read the policy check logs for the exact Sentinel error.
- Fix the policy syntax/runtime error and publish a new policy version.
- Re-run the Terraform plan once the corrected policy is active.
- If the engine itself is at fault, check TFE admin/health and the policy-set repository.
Defensive patterns
Strategy: try-catch
Try / catch
// On PolicyErrored, fetch logs and surface a clear remediation path.
if pc.Status == tfe.PolicyErrored {
logs, _ := b.client.PolicyChecks.Logs(ctx, pc.ID)
return fmt.Errorf("policy %s errored; review logs:\n%s", pc.ID, logs)
} Prevention
- Lint/test Sentinel policies in CI (sentinel apply/eval) before publishing to TFC.
- Keep policy sets versioned and roll back on error instead of editing live.
- Monitor policy-error rates and alert the policy owners.
When it happens
Trigger: pc.Status == tfe.PolicyErrored during checkPolicy. Caused by malformed Sentinel policy source, a runtime exception during evaluation, the policy engine being unavailable, or a referenced data source failing to load.
Common situations: Recently pushed broken Sentinel policy; policy referencing an undefined function/module; TFE policy service degraded; policy using language features unsupported by the TFE Sentinel version.
Related errors
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/c3904c65a18ff44e.
Report an issue: GitHub.
Appendix: source
Thrown at internal/backend/remote/backend_common.go:443
next = false
}
line = append(line, l...)
}
if next || len(line) > 0 {
b.CLI.Output(b.Colorize().Color(string(line)))
}
}
}
switch pc.Status {
case tfe.PolicyPasses:
if (r.HasChanges && op.Type == backendrun.OperationTypeApply || i < len(r.PolicyChecks)-1) && b.CLI != nil {
b.CLI.Output("\n------------------------------------------------------------------------")
}
continue
case tfe.PolicyErrored:
return fmt.Errorf("%s errored.", msgPrefix)
case tfe.PolicyHardFailed:
return fmt.Errorf("%s hard failed.", msgPrefix)
case tfe.PolicySoftFailed:
runURL := fmt.Sprintf(runHeaderErr, b.hostname, b.organization, op.Workspace, r.ID)
if op.Type == backendrun.OperationTypePlan || op.UIOut == nil || op.UIIn == nil ||
!pc.Actions.IsOverridable || !pc.Permissions.CanOverride {
return fmt.Errorf("%s soft failed.\n%s", msgPrefix, runURL)
}
if op.AutoApprove {
if _, err = b.client.PolicyChecks.Override(stopCtx, pc.ID); err != nil {
return generalError(fmt.Sprintf("Failed to override policy check.\n%s", runURL), err)
}
} else {
opts := &terraform.InputOpts{
Id: "override",
Query: "\nDo you want to override the soft failed policy check?",View on GitHub (pinned to d32a084675)