hashicorp/terraform · error
Unknown or unexpected policy state
Error message
Unknown or unexpected policy state: %s
What it means
Default branch of the policy-check status switch in checkPolicy. pc.Status did not match any known tfe.Policy* constant (Passes/Errored/HardFailed/SoftFailed/...). Like the cost-estimate equivalent, this signals the server and client disagree on possible policy statuses - typically a version-skew issue.
Solutions
- Upgrade the Terraform CLI to match or exceed the TFE/TFC version.
- Pin TFE to a version compatible with the installed CLI until you can upgrade.
- Capture the unknown status string and report it upstream if it recurs on a current CLI.
Defensive patterns
Strategy: validation
Validate before calling
// Ensure CLI >= TFE version before running policy-backed plans.
func versionsOK(cli, tfe string) bool { return !semverLessThan(cli, tfe) } Prevention
- Upgrade the Terraform CLI in lockstep with TFE/TFC upgrades.
- Pin CLI/TFE versions together in CI.
- Capture unknown status strings in logs to fast-track upstream reports.
When it happens
Trigger: pc.Status is a value the running Terraform client's tfe package does not recognize. Happens when a newer TFE/TFC emits a new policy status (e.g. a new post-condition or override state) unknown to an older CLI.
Common situations: TFE/TFC upgraded ahead of the Terraform CLI; very old CLI against new TFC; preview policy features; custom build with a stale tfe dependency.
Related errors
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/72b9db4c25006026.
Report an issue: GitHub.
Appendix: source
Thrown at internal/backend/remote/backend_common.go:483
if err != nil && err != errRunOverridden {
return fmt.Errorf("Failed to override: %w\n%s\n", err, runURL)
}
if err != errRunOverridden {
if _, err = b.client.PolicyChecks.Override(stopCtx, pc.ID); err != nil {
return generalError(fmt.Sprintf("Failed to override policy check.\n%s", runURL), err)
}
} else {
runURL := fmt.Sprintf(runHeader, b.hostname, b.organization, op.Workspace, r.ID)
b.CLI.Output(fmt.Sprintf("The run needs to be manually overridden or discarded.\n%s\n", runURL))
}
}
if b.CLI != nil {
b.CLI.Output("------------------------------------------------------------------------")
}
default:
return fmt.Errorf("Unknown or unexpected policy state: %s", pc.Status)
}
}
return nil
}
func (b *Remote) confirm(stopCtx context.Context, op *backendrun.Operation, opts *terraform.InputOpts, r *tfe.Run, keyword string) error {
doneCtx, cancel := context.WithCancel(stopCtx)
result := make(chan error, 2)
go func() {
defer logging.PanicHandler()
// Make sure we cancel doneCtx before we return
// so the input command is also canceled.
defer cancel()
for {View on GitHub (pinned to d32a084675)