hashicorp/terraform · error

errored.

Error message

%s errored.

What it means

Returned by the policy-check watcher when a policy check's status is tfe.PolicyErrored. 'Errored' is distinct from failed: the policy engine could not complete evaluation (runtime/Sentinel error), so the result is indeterminate rather than a clear pass/fail.

Solutions

  1. Open the run in the TFC/TFE UI and read the policy check logs for the exact Sentinel error.
  2. Fix the policy syntax/runtime error and publish a new policy version.
  3. Re-run the Terraform plan once the corrected policy is active.
  4. If the engine itself is at fault, check TFE admin/health and the policy-set repository.
Defensive patterns

Strategy: try-catch

Try / catch

// On PolicyErrored, fetch logs and surface a clear remediation path.
if pc.Status == tfe.PolicyErrored {
    logs, _ := b.client.PolicyChecks.Logs(ctx, pc.ID)
    return fmt.Errorf("policy %s errored; review logs:\n%s", pc.ID, logs)
}

Prevention

When it happens

Trigger: pc.Status == tfe.PolicyErrored during checkPolicy. Caused by malformed Sentinel policy source, a runtime exception during evaluation, the policy engine being unavailable, or a referenced data source failing to load.

Common situations: Recently pushed broken Sentinel policy; policy referencing an undefined function/module; TFE policy service degraded; policy using language features unsupported by the TFE Sentinel version.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/c3904c65a18ff44e. Report an issue: GitHub.

Appendix: source

Thrown at internal/backend/remote/backend_common.go:443

						next = false
					}
					line = append(line, l...)
				}

				if next || len(line) > 0 {
					b.CLI.Output(b.Colorize().Color(string(line)))
				}
			}
		}

		switch pc.Status {
		case tfe.PolicyPasses:
			if (r.HasChanges && op.Type == backendrun.OperationTypeApply || i < len(r.PolicyChecks)-1) && b.CLI != nil {
				b.CLI.Output("\n------------------------------------------------------------------------")
			}
			continue
		case tfe.PolicyErrored:
			return fmt.Errorf("%s errored.", msgPrefix)
		case tfe.PolicyHardFailed:
			return fmt.Errorf("%s hard failed.", msgPrefix)
		case tfe.PolicySoftFailed:
			runURL := fmt.Sprintf(runHeaderErr, b.hostname, b.organization, op.Workspace, r.ID)

			if op.Type == backendrun.OperationTypePlan || op.UIOut == nil || op.UIIn == nil ||
				!pc.Actions.IsOverridable || !pc.Permissions.CanOverride {
				return fmt.Errorf("%s soft failed.\n%s", msgPrefix, runURL)
			}

			if op.AutoApprove {
				if _, err = b.client.PolicyChecks.Override(stopCtx, pc.ID); err != nil {
					return generalError(fmt.Sprintf("Failed to override policy check.\n%s", runURL), err)
				}
			} else {
				opts := &terraform.InputOpts{
					Id:          "override",
					Query:       "\nDo you want to override the soft failed policy check?",

View on GitHub (pinned to d32a084675)