hashicorp/terraform · error
hard failed.
Error message
%s hard failed.
What it means
Policy check entered tfe.PolicyHardFailed: a hard-failed policy is a non-overridable enforcement that blocks the run regardless of permissions. The message names the policy stage (msgPrefix) but offers no override path, by design.
Solutions
- Read the policy violation output to identify which rule failed and fix the plan accordingly.
- If the violation is intentional/exception, request an admin adjust the policy or its enforcement level.
- Do not attempt to override—hard-failed policies are non-overridable by design.
Defensive patterns
Strategy: validation
Validate before calling
// preview hard-mandatory policy failures during plan, before apply
func previewHardPolicies(client *tfe.Client, org, ws string) error {
sets, err := client.PolicySets.List(ctx, org, nil)
if err != nil { return err }
for _, ps := range sets.Items {
if ps.EnforcementLevel == "hard-mandatory" {
// ensure plan satisfies before apply; this is a reminder hook
}
}
return nil
} Prevention
- Treat hard-mandatory policies as non-negotiable; fix the plan instead of trying to override.
- Run `terraform plan` first to see policy violations before apply.
- Document which policies are hard-mandatory per workspace.
When it happens
Trigger: pc.Status == tfe.PolicyHardFailed: an 'advisory'/'mandatory' (hard) policy evaluated to false on a non-overridable policy set; admin marked the policy enforcement level as hard-mandatory.
Common situations: Production guardrail policy (e.g. 'no public S3 buckets') correctly blocks an unsafe plan; policy enforcement level was raised from soft to hard by an admin; new mandatory policy added org-wide.
Related errors
- errored.
- soft failed.
- Failed to override
- Unknown or unexpected policy state
- backend does not support key/value tags. Try using key-only…
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/c5b87a51bc5f6ec4.
Report an issue: GitHub.
Appendix: source
Thrown at internal/cloud/backend_common.go:395
line = append(line, l...)
}
if next || len(line) > 0 {
b.CLI.Output(b.Colorize().Color(string(line)))
}
}
}
switch pc.Status {
case tfe.PolicyPasses:
if (r.HasChanges && op.Type == backendrun.OperationTypeApply || i < len(r.PolicyChecks)-1) && b.CLI != nil {
b.CLI.Output("\n------------------------------------------------------------------------")
}
continue
case tfe.PolicyErrored:
return fmt.Errorf("%s errored.", msgPrefix)
case tfe.PolicyHardFailed:
return fmt.Errorf("%s hard failed.", msgPrefix)
case tfe.PolicySoftFailed:
runURL := fmt.Sprintf(runHeaderErr, b.Hostname, b.Organization, op.Workspace, r.ID)
if op.Type == backendrun.OperationTypePlan || op.UIOut == nil || op.UIIn == nil ||
!pc.Actions.IsOverridable || !pc.Permissions.CanOverride {
return fmt.Errorf("%s soft failed.\n%s", msgPrefix, runURL)
}
if op.AutoApprove {
if _, err = b.client.PolicyChecks.Override(stopCtx, pc.ID); err != nil {
return b.generalError(fmt.Sprintf("Failed to override policy check.\n%s", runURL), err)
}
} else if !b.input {
return errPolicyOverrideNeedsUIConfirmation
} else {
opts := &terraform.InputOpts{
Id: "override",
Query: "\nDo you want to override the soft failed policy check?",View on GitHub (pinned to d32a084675)