hashicorp/terraform · error

hard failed.

Error message

%s hard failed.

What it means

Policy check entered tfe.PolicyHardFailed: a hard-failed policy is a non-overridable enforcement that blocks the run regardless of permissions. The message names the policy stage (msgPrefix) but offers no override path, by design.

Solutions

  1. Read the policy violation output to identify which rule failed and fix the plan accordingly.
  2. If the violation is intentional/exception, request an admin adjust the policy or its enforcement level.
  3. Do not attempt to override—hard-failed policies are non-overridable by design.
Defensive patterns

Strategy: validation

Validate before calling

// preview hard-mandatory policy failures during plan, before apply
func previewHardPolicies(client *tfe.Client, org, ws string) error {
    sets, err := client.PolicySets.List(ctx, org, nil)
    if err != nil { return err }
    for _, ps := range sets.Items {
        if ps.EnforcementLevel == "hard-mandatory" {
            // ensure plan satisfies before apply; this is a reminder hook
        }
    }
    return nil
}

Prevention

When it happens

Trigger: pc.Status == tfe.PolicyHardFailed: an 'advisory'/'mandatory' (hard) policy evaluated to false on a non-overridable policy set; admin marked the policy enforcement level as hard-mandatory.

Common situations: Production guardrail policy (e.g. 'no public S3 buckets') correctly blocks an unsafe plan; policy enforcement level was raised from soft to hard by an admin; new mandatory policy added org-wide.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/c5b87a51bc5f6ec4. Report an issue: GitHub.

Appendix: source

Thrown at internal/cloud/backend_common.go:395

					line = append(line, l...)
				}

				if next || len(line) > 0 {
					b.CLI.Output(b.Colorize().Color(string(line)))
				}
			}
		}

		switch pc.Status {
		case tfe.PolicyPasses:
			if (r.HasChanges && op.Type == backendrun.OperationTypeApply || i < len(r.PolicyChecks)-1) && b.CLI != nil {
				b.CLI.Output("\n------------------------------------------------------------------------")
			}
			continue
		case tfe.PolicyErrored:
			return fmt.Errorf("%s errored.", msgPrefix)
		case tfe.PolicyHardFailed:
			return fmt.Errorf("%s hard failed.", msgPrefix)
		case tfe.PolicySoftFailed:
			runURL := fmt.Sprintf(runHeaderErr, b.Hostname, b.Organization, op.Workspace, r.ID)

			if op.Type == backendrun.OperationTypePlan || op.UIOut == nil || op.UIIn == nil ||
				!pc.Actions.IsOverridable || !pc.Permissions.CanOverride {
				return fmt.Errorf("%s soft failed.\n%s", msgPrefix, runURL)
			}

			if op.AutoApprove {
				if _, err = b.client.PolicyChecks.Override(stopCtx, pc.ID); err != nil {
					return b.generalError(fmt.Sprintf("Failed to override policy check.\n%s", runURL), err)
				}
			} else if !b.input {
				return errPolicyOverrideNeedsUIConfirmation
			} else {
				opts := &terraform.InputOpts{
					Id:          "override",
					Query:       "\nDo you want to override the soft failed policy check?",

View on GitHub (pinned to d32a084675)