hashicorp/terraform · error

State store provider

Error message

State store provider %q (%s) was not approved, so init cannot continue.

What it means

Thrown during `terraform init` after a state-storage provider is installed but before it is trusted. The CLI prompts the user to approve the provider; any response other than the literal string "yes" aborts initialization. It protects against silently delegating state management to an unvetted provider.

Solutions

  1. Enter exactly `yes` (lowercase, full word) at the interactive prompt.
  2. In non-interactive runs, echo the approval: `echo yes | terraform init`, or set `-input=false` and pre-pin the provider in the dependency lock file so approval is bypassed.
  3. Verify the provider's platform, authentication, and hash list shown in the prompt match an officially distributed build before approving.
  4. If the provider is genuinely untrusted, remove or correct the `provider` block referencing it as a state store in the backend configuration.

Example fix

# before (CI hangs / returns empty stdin)
terraform init
# after
echo yes | terraform init -input=false
Defensive patterns

Strategy: validation

Validate before calling

# Before terraform init, ensure the provider is pre-approved or supply approval.
# Pre-pin the state-storage provider in .terraform.lock.hcl so no prompt fires:
terraform providers lock -platform=linux_amd64
# In CI, provide the exact approval and disable the prompt:
echo yes | terraform init -input=false

Try / catch

# In a wrapper script, detect the approval-required condition and fail fast:
if ! terraform init -input=false >/tmp/init.log 2>&1; then
  if grep -q 'was not approved, so init cannot continue' /tmp/init.log; then
    echo "State-store provider needs approval; rerun with 'echo yes | terraform init'" >&2
    exit 2
  fi
  cat /tmp/init.log; exit 1
fi

Prevention

When it happens

Trigger: Reached only when `terraform init` configures a state storage provider that is not yet in the trusted set, input is enabled, and `m.UIInput().Input(...)` returns a value != "yes". The prompt Id is `approve-provider-<type>-<version>`.

Common situations: CI pipelines or scripts where stdin is not a TTY (input returns empty), a user typing "y" or "Y" instead of "yes", declining an unknown provider whose hashes do not match expectations, or a wrapper that answers the prompt with the wrong value.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/3fb53880a0a206fa. Report an issue: GitHub.

Appendix: source

Thrown at internal/command/meta_backend.go:3239

Hashes:
%s
`,
			lock.Provider().Type,
			lock.Provider(),
			lock.Version(),
			getproviders.CurrentPlatform.String(),
			authentication,
			hashList.String(),
		),
		Description: fmt.Sprintf(`Check the details above for provider %q and confirm that you trust the provider.
	Only 'yes' will be accepted to confirm.`, lock.Provider().Type),
	})
	if err != nil {
		return diags.Append(fmt.Errorf("Failed to approve use of state storage provider: %s", err))
	}
	if v != "yes" {
		return diags.Append(
			fmt.Errorf("State store provider %q (%s) was not approved, so init cannot continue.",
				lock.Provider().Type,
				lock.Provider(),
			),
		)
	}
	return diags
}

//-------------------------------------------------------------------
// Output constants and initialization code
//-------------------------------------------------------------------

const inputCloudInitCreateWorkspace = `
There are no workspaces with the configured tags (%s)
in your HCP Terraform organization. To finish initializing, Terraform needs at
least one workspace available.

Terraform can create a properly tagged workspace for you now. Please enter a

View on GitHub (pinned to d32a084675)