hashicorp/terraform · error
State store provider
Error message
State store provider %q (%s) was not approved, so init cannot continue.
What it means
Thrown during `terraform init` after a state-storage provider is installed but before it is trusted. The CLI prompts the user to approve the provider; any response other than the literal string "yes" aborts initialization. It protects against silently delegating state management to an unvetted provider.
Solutions
- Enter exactly `yes` (lowercase, full word) at the interactive prompt.
- In non-interactive runs, echo the approval: `echo yes | terraform init`, or set `-input=false` and pre-pin the provider in the dependency lock file so approval is bypassed.
- Verify the provider's platform, authentication, and hash list shown in the prompt match an officially distributed build before approving.
- If the provider is genuinely untrusted, remove or correct the `provider` block referencing it as a state store in the backend configuration.
Example fix
# before (CI hangs / returns empty stdin) terraform init # after echo yes | terraform init -input=false
Defensive patterns
Strategy: validation
Validate before calling
# Before terraform init, ensure the provider is pre-approved or supply approval. # Pre-pin the state-storage provider in .terraform.lock.hcl so no prompt fires: terraform providers lock -platform=linux_amd64 # In CI, provide the exact approval and disable the prompt: echo yes | terraform init -input=false
Try / catch
# In a wrapper script, detect the approval-required condition and fail fast:
if ! terraform init -input=false >/tmp/init.log 2>&1; then
if grep -q 'was not approved, so init cannot continue' /tmp/init.log; then
echo "State-store provider needs approval; rerun with 'echo yes | terraform init'" >&2
exit 2
fi
cat /tmp/init.log; exit 1
fi Prevention
- Commit .terraform.lock.hcl so provider hashes are pinned and trusted up front.
- Run init with -input=false in automation and supply explicit approval via stdin.
- Document which provider manages state so reviewers recognize the approval prompt.
When it happens
Trigger: Reached only when `terraform init` configures a state storage provider that is not yet in the trusted set, input is enabled, and `m.UIInput().Input(...)` returns a value != "yes". The prompt Id is `approve-provider-<type>-<version>`.
Common situations: CI pipelines or scripts where stdin is not a TTY (input returns empty), a user typing "y" or "Y" instead of "yes", declining an unknown provider whose hashes do not match expectations, or a wrapper that answers the prompt with the wrong value.
Related errors
- Failed to approve use of state storage provider
- Failed to select a workspace
- attempted to encode a malformed backend state file…
- encountered a malformed backend state file that contains…
- encountered a malformed backend state file with a…
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/3fb53880a0a206fa.
Report an issue: GitHub.
Appendix: source
Thrown at internal/command/meta_backend.go:3239
Hashes:
%s
`,
lock.Provider().Type,
lock.Provider(),
lock.Version(),
getproviders.CurrentPlatform.String(),
authentication,
hashList.String(),
),
Description: fmt.Sprintf(`Check the details above for provider %q and confirm that you trust the provider.
Only 'yes' will be accepted to confirm.`, lock.Provider().Type),
})
if err != nil {
return diags.Append(fmt.Errorf("Failed to approve use of state storage provider: %s", err))
}
if v != "yes" {
return diags.Append(
fmt.Errorf("State store provider %q (%s) was not approved, so init cannot continue.",
lock.Provider().Type,
lock.Provider(),
),
)
}
return diags
}
//-------------------------------------------------------------------
// Output constants and initialization code
//-------------------------------------------------------------------
const inputCloudInitCreateWorkspace = `
There are no workspaces with the configured tags (%s)
in your HCP Terraform organization. To finish initializing, Terraform needs at
least one workspace available.
Terraform can create a properly tagged workspace for you now. Please enter aView on GitHub (pinned to d32a084675)