hashicorp/terraform · error

state store is not valid

Error message

state store is not valid: %w

What it means

StateStoreConfigState.Validate() called Provider.Source.Validate() (the getproviders SourceAddress validator) and it failed; the %w wraps that error. This is the state_store's nested provider source address being malformed (e.g. invalid hostname, illegal characters in namespace/name).

Solutions

  1. Inspect the wrapped error for the specific SourceAddress validation rule that failed.
  2. Fix the provider source FQN in the state_store block (e.g. `registry.opentofu.org/namespace/name`).
  3. Re-run `terraform init` after correcting the configuration.

Example fix

# before — invalid provider source
terraform {
  state_store {
    provider = "foo bar/baz"
  }
}

# after — valid FQN
terraform {
  state_store {
    provider = "registry.opentofu.org/hashicorp/kubernetes"
  }
}
Defensive patterns

Strategy: validation

Validate before calling

// pre-flight: validate provider source before encode
if s.Provider != nil {
    if err := s.Provider.Source.Validate(); err != nil {
        return fmt.Errorf("fix provider source FQN in state_store block: %w", err)
    }
}

Type guard

func isValidProviderSource(s getproviders.Source) bool { return s.Validate() == nil }

Prevention

When it happens

Trigger: Constructing a state_store whose provider source is something like `foo/bar baz` (space), `terraform-` (trailing dash), or an unparseable FQN. Surfaces on `terraform init`/plan when the state file is being validated.

Common situations: Hand-edited backend state with a typo'd provider source, a fork/experiment using a non-standard source address, or copy-paste from docs with smart-quotes.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/90ccf2d48125897e. Report an issue: GitHub.

Appendix: source

Thrown at internal/command/workdir/statestore_config_state.go:61

func (s *StateStoreConfigState) Validate() error {
	// Are any bits of data totally missing?
	if s.Empty() {
		return fmt.Errorf("attempted to encode a malformed backend state file; data is empty")
	}
	if s.Type == "" {
		return fmt.Errorf("attempted to encode a malformed backend state file; state store type is missing")
	}
	if s.Provider == nil {
		return fmt.Errorf("attempted to encode a malformed backend state file; provider data is missing")
	}
	if s.ConfigRaw == nil {
		return fmt.Errorf("attempted to encode a malformed backend state file; state_store configuration data is missing")
	}

	// Validity of data that is there
	err := s.Provider.Source.Validate()
	if err != nil {
		return fmt.Errorf("state store is not valid: %w", err)
	}

	// Version information is required if the provider isn't builtin or unmanaged by Terraform
	switch s.ProviderSupplyMode {
	case getproviders.BuiltIn, getproviders.Reattached, getproviders.DevOverride:
		// These modes do not require version information
	case getproviders.ManagedByTerraform:
		if s.Provider.Version == nil {
			return fmt.Errorf("state store is not valid: provider version data is missing despite provider %s being managed by Terraform.", s.Provider.Source.ForDisplay())
		}
	default:
		panic(fmt.Sprintf("State store provider %q (%s) has unknown supply mode %q. This is a bug in Terraform and should be reported.", s.Provider.Source.Type, s.Provider.Source.ForDisplay(), s.ProviderSupplyMode))
	}

	return nil
}

// Config decodes the type-specific configuration object using the provided

View on GitHub (pinned to d32a084675)