hashicorp/terraform · error

Unknown or unexpected policy state

Error message

Unknown or unexpected policy state: %s

What it means

Default branch of the policy-check status switch in checkPolicy. pc.Status did not match any known tfe.Policy* constant (Passes/Errored/HardFailed/SoftFailed/...). Like the cost-estimate equivalent, this signals the server and client disagree on possible policy statuses - typically a version-skew issue.

Solutions

  1. Upgrade the Terraform CLI to match or exceed the TFE/TFC version.
  2. Pin TFE to a version compatible with the installed CLI until you can upgrade.
  3. Capture the unknown status string and report it upstream if it recurs on a current CLI.
Defensive patterns

Strategy: validation

Validate before calling

// Ensure CLI >= TFE version before running policy-backed plans.
func versionsOK(cli, tfe string) bool { return !semverLessThan(cli, tfe) }

Prevention

When it happens

Trigger: pc.Status is a value the running Terraform client's tfe package does not recognize. Happens when a newer TFE/TFC emits a new policy status (e.g. a new post-condition or override state) unknown to an older CLI.

Common situations: TFE/TFC upgraded ahead of the Terraform CLI; very old CLI against new TFC; preview policy features; custom build with a stale tfe dependency.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/72b9db4c25006026. Report an issue: GitHub.

Appendix: source

Thrown at internal/backend/remote/backend_common.go:483

				if err != nil && err != errRunOverridden {
					return fmt.Errorf("Failed to override: %w\n%s\n", err, runURL)
				}

				if err != errRunOverridden {
					if _, err = b.client.PolicyChecks.Override(stopCtx, pc.ID); err != nil {
						return generalError(fmt.Sprintf("Failed to override policy check.\n%s", runURL), err)
					}
				} else {
					runURL := fmt.Sprintf(runHeader, b.hostname, b.organization, op.Workspace, r.ID)
					b.CLI.Output(fmt.Sprintf("The run needs to be manually overridden or discarded.\n%s\n", runURL))
				}
			}

			if b.CLI != nil {
				b.CLI.Output("------------------------------------------------------------------------")
			}
		default:
			return fmt.Errorf("Unknown or unexpected policy state: %s", pc.Status)
		}
	}

	return nil
}

func (b *Remote) confirm(stopCtx context.Context, op *backendrun.Operation, opts *terraform.InputOpts, r *tfe.Run, keyword string) error {
	doneCtx, cancel := context.WithCancel(stopCtx)
	result := make(chan error, 2)

	go func() {
		defer logging.PanicHandler()

		// Make sure we cancel doneCtx before we return
		// so the input command is also canceled.
		defer cancel()

		for {

View on GitHub (pinned to d32a084675)