hashicorp/terraform · critical

State store provider is missing from required providers but…

Error message

State store provider is missing from required providers but this was not caught during config parsing, which is a bug in Terraform; please report it!

What it means

StateStore.VerifyDependencySelection (internal/configs/state_store.go:197) looks up the state-store provider in reqs.RequiredProviders by its type and panics if missing. The comment states the config parser should already have rejected a state_store block whose provider is not declared in required_providers, so reaching here means an upstream error was swallowed.

Solutions

  1. Confirm the state_store block's provider matches a required_providers entry in the same module; run 'terraform validate' to surface the parse-time diagnostic that should have prevented this.
  2. If you maintain a custom code path that calls VerifyDependencySelection, ensure you propagate ALL parse diagnostics instead of discarding them.
  3. Re-run 'terraform init' after fixing required_providers so the dependency selection is consistent.
  4. Report upstream: include the config (state_store + required_providers) so the swallowed-diagnostic path can be fixed.

Example fix

// before
req, ok := reqs.RequiredProviders[ss.ProviderAddr.Type]
if !ok {
    panic("State store provider is missing from required providers but this was not caught during config parsing, ...")
}

// after (surface a diagnostic instead of crashing)
req, ok := reqs.RequiredProviders[ss.ProviderAddr.Type]
if !ok {
    return diags.Append(tfdiags.Sourceless(tfdiags.Error,
        "State store provider not declared",
        fmt.Sprintf("%s must be declared in required_providers.", ss.ProviderAddr)))
}
Defensive patterns

Strategy: validation

Validate before calling

// Confirm the state-store provider is declared before verifying selections.
func stateStoreProviderDeclared(reqs *configs.RequiredProviders, addr tfaddr.Provider) bool {
    if reqs == nil {
        return false
    }
    _, ok := reqs.RequiredProviders[addr.Type]
    return ok
}
if !stateStoreProviderDeclared(reqs, ss.ProviderAddr) {
    return diags.Append(tfdiags.Sourceless(tfdiags.Error,
        "State store provider not declared",
        fmt.Sprintf("Add %s to required_providers.", ss.ProviderAddr)))
}

Prevention

When it happens

Trigger: A state_store block names a provider that is absent from the required_providers map passed to VerifyDependencySelection, yet no diagnostic was surfaced — e.g. config parsing returned a partial result after discarding an error, or the RequiredProviders map was built from a stale/different config than the state_store block.

Common situations: A state_store block referencing a provider whose required_providers entry was removed or renamed between parse and verify; a custom config-loading path that drops diagnostics; a typo/mismatch between the state_store provider type and the required_providers local name.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/04f432665d1c331a. Report an issue: GitHub.

Appendix: source

Thrown at internal/configs/state_store.go:202

			tfdiags.Error,
			"Inconsistent dependency lock file",
			fmt.Sprintf(`The provider dependency used for state storage is missing from the lock file despite being present in the current configuration:
  - provider %s: required by this configuration but no version is selected

To make the initial dependency selections that will initialize the dependency lock file, run:
  terraform init`,
				ss.ProviderAddr,
			),
		))
		return diags
	}

	req, ok := reqs.RequiredProviders[ss.ProviderAddr.Type]
	if !ok {
		// The provider used for state storage is not in the required providers list.
		// This should have been identified when the block was parsed, so if we get here
		// it suggests that upstream code is swallowing that error.
		panic("State store provider is missing from required providers but this was not caught during config parsing, which is a bug in Terraform; please report it!")
	}

	// Is the provider in the lock file, and is it an appropriate version matching the constraints in required_providers?

	lock := depLocks.Provider(ss.ProviderAddr)
	constraints := providerreqs.MustParseVersionConstraints(req.Requirement.Required.String())
	if lock == nil {
		log.Printf("[TRACE] StateStore.VerifyDependencySelections: provider %s has no lock file entry to satisfy %q", ss.ProviderAddr, providerreqs.VersionConstraintsString(constraints))
		return diags.Append(tfdiags.Sourceless(
			tfdiags.Error,
			"Inconsistent dependency lock file",
			fmt.Sprintf(`The provider dependency used for state storage recorded in the lock file is inconsistent with the current configuration:
  - provider %s: required by this configuration but no version is selected

To make the initial dependency selections that will initialize the dependency lock file, run:
  terraform init`,
				ss.ProviderAddr,
			),

View on GitHub (pinned to d32a084675)