hashicorp/terraform · critical
State store provider is missing from required providers but…
Error message
State store provider is missing from required providers but this was not caught during config parsing, which is a bug in Terraform; please report it!
What it means
StateStore.VerifyDependencySelection (internal/configs/state_store.go:197) looks up the state-store provider in reqs.RequiredProviders by its type and panics if missing. The comment states the config parser should already have rejected a state_store block whose provider is not declared in required_providers, so reaching here means an upstream error was swallowed.
Solutions
- Confirm the state_store block's provider matches a required_providers entry in the same module; run 'terraform validate' to surface the parse-time diagnostic that should have prevented this.
- If you maintain a custom code path that calls VerifyDependencySelection, ensure you propagate ALL parse diagnostics instead of discarding them.
- Re-run 'terraform init' after fixing required_providers so the dependency selection is consistent.
- Report upstream: include the config (state_store + required_providers) so the swallowed-diagnostic path can be fixed.
Example fix
// before
req, ok := reqs.RequiredProviders[ss.ProviderAddr.Type]
if !ok {
panic("State store provider is missing from required providers but this was not caught during config parsing, ...")
}
// after (surface a diagnostic instead of crashing)
req, ok := reqs.RequiredProviders[ss.ProviderAddr.Type]
if !ok {
return diags.Append(tfdiags.Sourceless(tfdiags.Error,
"State store provider not declared",
fmt.Sprintf("%s must be declared in required_providers.", ss.ProviderAddr)))
} Defensive patterns
Strategy: validation
Validate before calling
// Confirm the state-store provider is declared before verifying selections.
func stateStoreProviderDeclared(reqs *configs.RequiredProviders, addr tfaddr.Provider) bool {
if reqs == nil {
return false
}
_, ok := reqs.RequiredProviders[addr.Type]
return ok
}
if !stateStoreProviderDeclared(reqs, ss.ProviderAddr) {
return diags.Append(tfdiags.Sourceless(tfdiags.Error,
"State store provider not declared",
fmt.Sprintf("Add %s to required_providers.", ss.ProviderAddr)))
} Prevention
- Always declare the state-store provider in a required_providers block of the same module.
- Run 'terraform validate' after editing state_store / required_providers to catch mismatches at parse time.
- If you maintain a custom config-loading path, never discard parse diagnostics before calling VerifyDependencySelection.
When it happens
Trigger: A state_store block names a provider that is absent from the required_providers map passed to VerifyDependencySelection, yet no diagnostic was surfaced — e.g. config parsing returned a partial result after discarding an error, or the RequiredProviders map was built from a stale/different config than the state_store block.
Common situations: A state_store block referencing a provider whose required_providers entry was removed or renamed between parse and verify; a custom config-loading path that drops diagnostics; a typo/mismatch between the state_store provider type and the required_providers local name.
Related errors
- errStateStoreInitDiag requires a non-nil reason argument
- expected exactly one provider requirement for the…
- expected exactly one provider requirement for the…
- expected one provider requirement for the destination state…
- init (determineIfProviderTrusted): unexpected provider…
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/04f432665d1c331a.
Report an issue: GitHub.
Appendix: source
Thrown at internal/configs/state_store.go:202
tfdiags.Error,
"Inconsistent dependency lock file",
fmt.Sprintf(`The provider dependency used for state storage is missing from the lock file despite being present in the current configuration:
- provider %s: required by this configuration but no version is selected
To make the initial dependency selections that will initialize the dependency lock file, run:
terraform init`,
ss.ProviderAddr,
),
))
return diags
}
req, ok := reqs.RequiredProviders[ss.ProviderAddr.Type]
if !ok {
// The provider used for state storage is not in the required providers list.
// This should have been identified when the block was parsed, so if we get here
// it suggests that upstream code is swallowing that error.
panic("State store provider is missing from required providers but this was not caught during config parsing, which is a bug in Terraform; please report it!")
}
// Is the provider in the lock file, and is it an appropriate version matching the constraints in required_providers?
lock := depLocks.Provider(ss.ProviderAddr)
constraints := providerreqs.MustParseVersionConstraints(req.Requirement.Required.String())
if lock == nil {
log.Printf("[TRACE] StateStore.VerifyDependencySelections: provider %s has no lock file entry to satisfy %q", ss.ProviderAddr, providerreqs.VersionConstraintsString(constraints))
return diags.Append(tfdiags.Sourceless(
tfdiags.Error,
"Inconsistent dependency lock file",
fmt.Sprintf(`The provider dependency used for state storage recorded in the lock file is inconsistent with the current configuration:
- provider %s: required by this configuration but no version is selected
To make the initial dependency selections that will initialize the dependency lock file, run:
terraform init`,
ss.ProviderAddr,
),View on GitHub (pinned to d32a084675)