hashicorp/terraform · error
Unknown or unexpected policy state
Error message
Unknown or unexpected policy state: %s
What it means
Policy state switch hit its default: pc.Status is a value not present in the enumerated tfe.Policy* constants this binary knows. Same shape as the cost-estimate unknown-state error—almost always a client/server version skew where the server introduced a new policy status.
Solutions
- Upgrade the Terraform/OpenTofo binary so its tfe SDK recognizes the new status.
- Downgrade TFE to match the client if upgrade is blocked.
- Capture the unknown status value from %s and report it to confirm enum vs corruption.
Defensive patterns
Strategy: validation
Validate before calling
func knownPolicyStatus(s tfe.PolicyStatus) bool {
switch s {
case tfe.PolicyPasses, tfe.PolicyErrored, tfe.PolicyHardFailed, tfe.PolicySoftFailed,
tfe.PolicyPending, tfe.PolicyQueued, tfe.PolicyRunning, tfe.PolicyUnreachable:
return true
}
return false
} Type guard
func isKnownPolicyStatus(s tfe.PolicyStatus) bool {
// bounded enum range check
return s >= tfe.PolicyPending && s <= tfe.PolicyUnreachable
} Prevention
- Keep the binary's tfe SDK version compatible with the TFE server.
- Log raw policy status values for diagnostics.
- Upgrade the binary when TFE adds new policy states.
When it happens
Trigger: pc.Status is a value outside {Passes, Errored, HardFailed, SoftFailed, ...}. Typically a newer TFE server returning a status the client's tfe SDK does not enumerate.
Common situations: Older Terraform/OpenTofu binary running against an upgraded TFE that added a policy status (e.g. a new 'pending override' or 'escalated' state).
Related errors
- backend does not support key/value tags. Try using key-only…
- Failed to override
- errored.
- hard failed.
- soft failed.
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/7320662f1181f875.
Report an issue: GitHub.
Appendix: source
Thrown at internal/cloud/backend_common.go:435
if err != nil && err != errRunOverridden {
return fmt.Errorf("Failed to override: %w\n%s\n", err, runURL)
}
if err != errRunOverridden {
if _, err = b.client.PolicyChecks.Override(stopCtx, pc.ID); err != nil {
return b.generalError(fmt.Sprintf("Failed to override policy check.\n%s", runURL), err)
}
} else {
runURL := fmt.Sprintf(runHeader, b.Hostname, b.Organization, op.Workspace, r.ID)
b.CLI.Output(fmt.Sprintf("The run needs to be manually overridden or discarded.\n%s\n", runURL))
}
}
if b.CLI != nil {
b.CLI.Output("------------------------------------------------------------------------")
}
default:
return fmt.Errorf("Unknown or unexpected policy state: %s", pc.Status)
}
}
return nil
}
func (b *Cloud) confirm(stopCtx context.Context, op *backendrun.Operation, opts *terraform.InputOpts, r *tfe.Run, keyword string) error {
doneCtx, cancel := context.WithCancel(stopCtx)
result := make(chan error, 2)
go func() {
// Make sure we cancel doneCtx before we return
// so the input command is also canceled.
defer cancel()
for {
select {
case <-doneCtx.Done():View on GitHub (pinned to d32a084675)