hashicorp/terraform · error
soft failed.
Error message
%s soft failed. %s
What it means
Policy soft-failed (tfe.PolicySoftFailed) AND the run cannot show the interactive override prompt: the op is a plan, there is no UI, or the policy/workspace lacks override permissions. Soft failures are overridable, but only when UIIn/UIOut exist and the user has CanOverride; otherwise this error fires with the run URL.
Solutions
- Grant the token's team the 'Override Soft Failed Policies' workspace permission and pass --auto-approve if overrides are desired.
- Fix the configuration to satisfy the soft policy rather than overriding.
- Run the apply interactively on a workstation to be prompted for override.
- Adjust the policy enforcement level from soft-mandatory to advisory if override should be routine.
Example fix
# before: CI token lacks override permission, run blocks on soft policy # Workspace -> Settings -> Permissions -> grant team 'Override Soft Failed Policies' # then run with auto-approve: terraform apply -auto-approve
Defensive patterns
Strategy: validation
Validate before calling
// before running apply in CI, ensure override capability or fix policies
func canOverrideSoftFail(client *tfe.Client, ws *tfe.Workspace) bool {
return ws.Permissions.CanOverride && ws.Actions.IsOverridable
}
// if false and you need override, grant the team 'Override Soft Failed Policies' Prevention
- Grant the CI token's team 'Override Soft Failed Policies' when override is intended.
- Use --auto-approve in CI when override is desired and permitted.
- Prefer fixing the config over overriding soft policies.
- Lower enforcement to 'advisory' for policies you routinely override.
When it happens
Trigger: pc.Status == tfe.PolicySoftFailed AND (op.Type == plan OR op.UIOut == nil OR op.UIIn == nil OR !pc.Actions.IsOverridable OR !pc.Permissions.CanOverride). Typical in non-interactive CI: no TTY, no override permission, or running `plan` only.
Common situations: CI runner without interactive input hits a soft-mandatory policy; the token's team lacks 'Override Soft Failed Policies' permission; running a plan-only check that surfaces a soft policy violation.
Related errors
- Failed to override
- errored.
- hard failed.
- Unknown or unexpected policy state
- backend does not support key/value tags. Try using key-only…
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/3ed6555f4002ca15.
Report an issue: GitHub.
Appendix: source
Thrown at internal/cloud/backend_common.go:401
}
}
switch pc.Status {
case tfe.PolicyPasses:
if (r.HasChanges && op.Type == backendrun.OperationTypeApply || i < len(r.PolicyChecks)-1) && b.CLI != nil {
b.CLI.Output("\n------------------------------------------------------------------------")
}
continue
case tfe.PolicyErrored:
return fmt.Errorf("%s errored.", msgPrefix)
case tfe.PolicyHardFailed:
return fmt.Errorf("%s hard failed.", msgPrefix)
case tfe.PolicySoftFailed:
runURL := fmt.Sprintf(runHeaderErr, b.Hostname, b.Organization, op.Workspace, r.ID)
if op.Type == backendrun.OperationTypePlan || op.UIOut == nil || op.UIIn == nil ||
!pc.Actions.IsOverridable || !pc.Permissions.CanOverride {
return fmt.Errorf("%s soft failed.\n%s", msgPrefix, runURL)
}
if op.AutoApprove {
if _, err = b.client.PolicyChecks.Override(stopCtx, pc.ID); err != nil {
return b.generalError(fmt.Sprintf("Failed to override policy check.\n%s", runURL), err)
}
} else if !b.input {
return errPolicyOverrideNeedsUIConfirmation
} else {
opts := &terraform.InputOpts{
Id: "override",
Query: "\nDo you want to override the soft failed policy check?",
Description: "Only 'override' will be accepted to override.",
}
err = b.confirm(stopCtx, op, opts, r, "override")
if err != nil && err != errRunOverridden {
return fmt.Errorf("Failed to override: %w\n%s\n", err, runURL)
}View on GitHub (pinned to d32a084675)