hashicorp/terraform · critical
State store provider
Error message
State store provider %q (%s) has unknown supply mode %q. This is a bug in Terraform and should be reported.
What it means
StateStore.VerifyDependencySelection (internal/configs/state_store.go:161) enters a branch when supplyMode.NotManagedByTerraform() is true and switches over the supply mode to log a debug message for BuiltIn/DevOverride/Reattached. Any other value panics. Critically, NotManagedByTerraform() (supplymode.go:31) returns true for everything except ManagedByTerraform — including the Unset/empty-string value — so an undetermined supply mode falls into this branch and hits the panic.
Solutions
- Ensure DetermineProviderSupplyMode(isDevOverride, isReattached, isBuiltin) is invoked and its result is propagated into StateStore.ProviderSupplyMode before VerifyDependencySelection runs.
- Run 'terraform init' so the provider installation is classified and the supply mode is recorded; clear .terraform/ and the CLI config dev_overrides/reattach entries if stale.
- Check your terraformrc / TF_REATTACH_PROVIDERS for partial config that leaves the provider unclassified.
- Report upstream: add an explicit case for getproviders.Unset (or treat Unset as ManagedByTerraform/error) so the panic becomes a diagnostic.
Example fix
// before
switch supplyMode {
case getproviders.BuiltIn:
...
case getproviders.DevOverride:
...
case getproviders.Reattached:
...
default:
panic(fmt.Sprintf("State store provider %q (%s) has unknown supply mode %q. ...", ...))
}
// after (explicit handling of Unset -> actionable diagnostic)
case getproviders.Unset:
return diags.Append(tfdiags.Sourceless(tfdiags.Error,
"State store provider supply mode not determined",
fmt.Sprintf("Run 'terraform init' so %s can be classified.", ss.ProviderAddr))) Defensive patterns
Strategy: validation
Validate before calling
// Ensure the supply mode is determined before calling VerifyDependencySelection.
func classifySupplyMode(installed providerInstallation) getproviders.ProviderSupplyMode {
return getproviders.DetermineProviderSupplyMode(
installed.IsDevOverride, installed.IsReattached, installed.IsBuiltin)
}
if supplyMode == getproviders.Unset {
return diags.Append(tfdiags.Sourceless(tfdiags.Error,
"State store provider supply mode not determined",
"Run 'terraform init' before this operation."))
} Prevention
- Always run 'terraform init' so the provider is installed and its supply mode is recorded.
- Call DetermineProviderSupplyMode and store its result in StateStore.ProviderSupplyMode during config loading.
- Keep TF_REATTACH_PROVIDERS / dev_overrides CLI config consistent and complete so the mode resolves to a known constant.
When it happens
Trigger: VerifyDependencySelection is called with getproviders.Unset (empty ProviderSupplyMode) — i.e. DetermineProviderSupplyMode was never called for the state-store provider, or the provider's supply mode was not propagated from the installer into the state-store config — so NotManagedByTerraform() is true but the inner switch has no case for Unset.
Common situations: A state-store provider referenced in a state_store block whose installation path did not classify it as built-in/reattached/dev_override/managed; misconfigured TF_REATTACH_PROVIDERS or dev_override that leaves the mode unset; a code regression that drops the DetermineProviderSupplyMode call before verification.
Related errors
- errStateStoreInitDiag requires a non-nil reason argument
- init (determineIfProviderTrusted): unexpected provider…
- missing message for InstallingProviderMessage init message…
- nil config passed to…
- State store provider is missing from required providers but…
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/7fae7ba4cc4cbe8e.
Report an issue: GitHub.
Appendix: source
Thrown at internal/configs/state_store.go:173
panic("This run has no dependency lock information provided at all. This is a bug in Terraform and should be reported.")
}
if reqs == nil {
panic("This run has no required providers information provided at all. This is a bug in Terraform and should be reported.")
}
if supplyMode.NotManagedByTerraform() {
// If the provider is not managed by Terraform then it's not lockable.
// If the working directory was initialized in the same way then the PSS provider will not be reflected in the lock file.
// Skip them.
switch supplyMode {
case getproviders.BuiltIn:
log.Printf("[DEBUG] StateStore.VerifyDependencySelection: skipping %s because it's a built-in provider", ss.ProviderAddr)
case getproviders.DevOverride:
log.Printf("[DEBUG] StateStore.VerifyDependencySelection: skipping %s because it's supplied via developer overrides", ss.ProviderAddr)
case getproviders.Reattached:
log.Printf("[DEBUG] StateStore.VerifyDependencySelection: skipping %s because it's re-attached and not managed by Terraform", ss.ProviderAddr)
default:
panic(fmt.Sprintf("State store provider %q (%s) has unknown supply mode %q. This is a bug in Terraform and should be reported.", ss.ProviderAddr.Type, ss.ProviderAddr.ForDisplay(), supplyMode))
}
return diags
}
// From this point on the provider currently in use is managed by Terraform
//
// When the PSS provider is managed, Terraform needs the state storage provider to be present in the lock file,
// and the lock file should not be empty or missing.
if depLocks.Empty() {
diags = diags.Append(tfdiags.Sourceless(
tfdiags.Error,
"Inconsistent dependency lock file",
fmt.Sprintf(`The provider dependency used for state storage is missing from the lock file despite being present in the current configuration:
- provider %s: required by this configuration but no version is selected
To make the initial dependency selections that will initialize the dependency lock file, run:
terraform init`,
ss.ProviderAddr,View on GitHub (pinned to d32a084675)