hashicorp/terraform · critical

State store provider

Error message

State store provider %q (%s) has unknown supply mode %q. This is a bug in Terraform and should be reported.

What it means

StateStore.VerifyDependencySelection (internal/configs/state_store.go:161) enters a branch when supplyMode.NotManagedByTerraform() is true and switches over the supply mode to log a debug message for BuiltIn/DevOverride/Reattached. Any other value panics. Critically, NotManagedByTerraform() (supplymode.go:31) returns true for everything except ManagedByTerraform — including the Unset/empty-string value — so an undetermined supply mode falls into this branch and hits the panic.

Solutions

  1. Ensure DetermineProviderSupplyMode(isDevOverride, isReattached, isBuiltin) is invoked and its result is propagated into StateStore.ProviderSupplyMode before VerifyDependencySelection runs.
  2. Run 'terraform init' so the provider installation is classified and the supply mode is recorded; clear .terraform/ and the CLI config dev_overrides/reattach entries if stale.
  3. Check your terraformrc / TF_REATTACH_PROVIDERS for partial config that leaves the provider unclassified.
  4. Report upstream: add an explicit case for getproviders.Unset (or treat Unset as ManagedByTerraform/error) so the panic becomes a diagnostic.

Example fix

// before
switch supplyMode {
case getproviders.BuiltIn:
    ...
case getproviders.DevOverride:
    ...
case getproviders.Reattached:
    ...
default:
    panic(fmt.Sprintf("State store provider %q (%s) has unknown supply mode %q. ...", ...))
}

// after (explicit handling of Unset -> actionable diagnostic)
case getproviders.Unset:
    return diags.Append(tfdiags.Sourceless(tfdiags.Error,
        "State store provider supply mode not determined",
        fmt.Sprintf("Run 'terraform init' so %s can be classified.", ss.ProviderAddr)))
Defensive patterns

Strategy: validation

Validate before calling

// Ensure the supply mode is determined before calling VerifyDependencySelection.
func classifySupplyMode(installed providerInstallation) getproviders.ProviderSupplyMode {
    return getproviders.DetermineProviderSupplyMode(
        installed.IsDevOverride, installed.IsReattached, installed.IsBuiltin)
}
if supplyMode == getproviders.Unset {
    return diags.Append(tfdiags.Sourceless(tfdiags.Error,
        "State store provider supply mode not determined",
        "Run 'terraform init' before this operation."))
}

Prevention

When it happens

Trigger: VerifyDependencySelection is called with getproviders.Unset (empty ProviderSupplyMode) — i.e. DetermineProviderSupplyMode was never called for the state-store provider, or the provider's supply mode was not propagated from the installer into the state-store config — so NotManagedByTerraform() is true but the inner switch has no case for Unset.

Common situations: A state-store provider referenced in a state_store block whose installation path did not classify it as built-in/reattached/dev_override/managed; misconfigured TF_REATTACH_PROVIDERS or dev_override that leaves the mode unset; a code regression that drops the DetermineProviderSupplyMode call before verification.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/7fae7ba4cc4cbe8e. Report an issue: GitHub.

Appendix: source

Thrown at internal/configs/state_store.go:173

		panic("This run has no dependency lock information provided at all. This is a bug in Terraform and should be reported.")
	}
	if reqs == nil {
		panic("This run has no required providers information provided at all. This is a bug in Terraform and should be reported.")
	}

	if supplyMode.NotManagedByTerraform() {
		// If the provider is not managed by Terraform then it's not lockable.
		// If the working directory was initialized in the same way then the PSS provider will not be reflected in the lock file.
		// Skip them.
		switch supplyMode {
		case getproviders.BuiltIn:
			log.Printf("[DEBUG] StateStore.VerifyDependencySelection: skipping %s because it's a built-in provider", ss.ProviderAddr)
		case getproviders.DevOverride:
			log.Printf("[DEBUG] StateStore.VerifyDependencySelection: skipping %s because it's supplied via developer overrides", ss.ProviderAddr)
		case getproviders.Reattached:
			log.Printf("[DEBUG] StateStore.VerifyDependencySelection: skipping %s because it's re-attached and not managed by Terraform", ss.ProviderAddr)
		default:
			panic(fmt.Sprintf("State store provider %q (%s) has unknown supply mode %q. This is a bug in Terraform and should be reported.", ss.ProviderAddr.Type, ss.ProviderAddr.ForDisplay(), supplyMode))
		}
		return diags
	}

	// From this point on the provider currently in use is managed by Terraform
	//
	// When the PSS provider is managed, Terraform needs the state storage provider to be present in the lock file,
	// and the lock file should not be empty or missing.
	if depLocks.Empty() {
		diags = diags.Append(tfdiags.Sourceless(
			tfdiags.Error,
			"Inconsistent dependency lock file",
			fmt.Sprintf(`The provider dependency used for state storage is missing from the lock file despite being present in the current configuration:
  - provider %s: required by this configuration but no version is selected

To make the initial dependency selections that will initialize the dependency lock file, run:
  terraform init`,
				ss.ProviderAddr,

View on GitHub (pinned to d32a084675)