hashicorp/terraform · error

Unknown or unexpected policy state

Error message

Unknown or unexpected policy state: %s

What it means

Policy state switch hit its default: pc.Status is a value not present in the enumerated tfe.Policy* constants this binary knows. Same shape as the cost-estimate unknown-state error—almost always a client/server version skew where the server introduced a new policy status.

Solutions

  1. Upgrade the Terraform/OpenTofo binary so its tfe SDK recognizes the new status.
  2. Downgrade TFE to match the client if upgrade is blocked.
  3. Capture the unknown status value from %s and report it to confirm enum vs corruption.
Defensive patterns

Strategy: validation

Validate before calling

func knownPolicyStatus(s tfe.PolicyStatus) bool {
    switch s {
    case tfe.PolicyPasses, tfe.PolicyErrored, tfe.PolicyHardFailed, tfe.PolicySoftFailed,
         tfe.PolicyPending, tfe.PolicyQueued, tfe.PolicyRunning, tfe.PolicyUnreachable:
        return true
    }
    return false
}

Type guard

func isKnownPolicyStatus(s tfe.PolicyStatus) bool {
    // bounded enum range check
    return s >= tfe.PolicyPending && s <= tfe.PolicyUnreachable
}

Prevention

When it happens

Trigger: pc.Status is a value outside {Passes, Errored, HardFailed, SoftFailed, ...}. Typically a newer TFE server returning a status the client's tfe SDK does not enumerate.

Common situations: Older Terraform/OpenTofu binary running against an upgraded TFE that added a policy status (e.g. a new 'pending override' or 'escalated' state).

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/7320662f1181f875. Report an issue: GitHub.

Appendix: source

Thrown at internal/cloud/backend_common.go:435

				if err != nil && err != errRunOverridden {
					return fmt.Errorf("Failed to override: %w\n%s\n", err, runURL)
				}

				if err != errRunOverridden {
					if _, err = b.client.PolicyChecks.Override(stopCtx, pc.ID); err != nil {
						return b.generalError(fmt.Sprintf("Failed to override policy check.\n%s", runURL), err)
					}
				} else {
					runURL := fmt.Sprintf(runHeader, b.Hostname, b.Organization, op.Workspace, r.ID)
					b.CLI.Output(fmt.Sprintf("The run needs to be manually overridden or discarded.\n%s\n", runURL))
				}
			}

			if b.CLI != nil {
				b.CLI.Output("------------------------------------------------------------------------")
			}
		default:
			return fmt.Errorf("Unknown or unexpected policy state: %s", pc.Status)
		}
	}

	return nil
}

func (b *Cloud) confirm(stopCtx context.Context, op *backendrun.Operation, opts *terraform.InputOpts, r *tfe.Run, keyword string) error {
	doneCtx, cancel := context.WithCancel(stopCtx)
	result := make(chan error, 2)

	go func() {
		// Make sure we cancel doneCtx before we return
		// so the input command is also canceled.
		defer cancel()

		for {
			select {
			case <-doneCtx.Done():

View on GitHub (pinned to d32a084675)