hashicorp/terraform · error

there is no package for

Error message

there is no package for %s %s cached in %s

What it means

In Meta.providerFactoriesFromLocks, for each provider recorded in the lock file the installer looks up cacheDir.ProviderVersion(provider, version). If that returns nil (no matching package directory in the local plugin cache), reportError records this message and installs a stub factory that will re-emit the error if invoked. The lock file promises a version that is not present on disk.

Solutions

  1. Run terraform init to download and unpack the locked provider versions into the cache.
  2. Verify TF_PLUGIN_CACHE_DIR points at the directory that actually holds the packages, or unset it to use the default .terraform/providers.
  3. Check that the cache directory is writable and not on a read-only or ephemeral mount.
  4. Confirm the lock file version still exists upstream if init still fails, then terraform init -upgrade if the version was withdrawn.

Example fix

# before: cache missing for locked version
# after
terraform init
Defensive patterns

Strategy: fallback

Validate before calling

// Check the cache before invoking commands that need providers.
for p, v := range lockedVersions {
    if cacheDir.ProviderVersion(p, v) == nil {
        return fmt.Errorf("run 'terraform init' to cache %s %s", p, v)
    }
}

Prevention

When it happens

Trigger: providerFactoriesFromLocks iterates providerLocks; for a provider not overridden and not dev-overridden, cacheDir.ProviderVersion(provider, lock.Version()) returns nil. This happens when the lock file lists a version but the .terraform/providers cache lacks the unpacked package.

Common situations: Fresh clone without terraform init; CI runner with a cold or cleared plugin cache; cache directory moved or on a different TF_PLUGIN_CACHE_DIR; package deleted manually or by a cleanup job; switching machines after committing .terraform.lock.hcl but not the cache.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/976146fec085f412. Report an issue: GitHub.

Appendix: source

Thrown at internal/command/meta_providers.go:402

		reportError := func(thisErr error) {
			errs[provider] = thisErr
			// We'll populate a provider factory that just echoes our error
			// again if called, which allows us to still report a helpful
			// error even if it gets detected downstream somewhere from the
			// caller using our partial result.
			factories[provider] = providerFactoryError(thisErr)
		}

		if locks.ProviderIsOverridden(provider) {
			// Overridden providers we'll handle with the other separate
			// loops below, for dev overrides etc.
			continue
		}

		version := lock.Version()
		cached := cacheDir.ProviderVersion(provider, version)
		if cached == nil {
			reportError(fmt.Errorf(
				"there is no package for %s %s cached in %s",
				provider, version, cacheDir.BasePath(),
			))
			continue
		}
		// The cached package must match one of the checksums recorded in
		// the lock file, if any.
		if allowedHashes := lock.PreferredHashes(); len(allowedHashes) != 0 {
			matched, err := cached.MatchesAnyHash(allowedHashes)
			if err != nil {
				reportError(fmt.Errorf(
					"failed to verify checksum of %s %s package cached in in %s: %s",
					provider, version, cacheDir.BasePath(), err,
				))
				continue
			}
			if !matched {
				reportError(fmt.Errorf(

View on GitHub (pinned to d32a084675)