Skip to content

Terraform provider authentication fails because workspace variable sets are missing

When a preview workspace lacks its provider credential variable sets, run the Global stage of the project's main API pipeline, then retry the preview deployment. The Global stage applies the Terraform Cloud bootstrap workspace that attaches those sets; this fix applies to projects using that bootstrap workflow.


🚨 Symptom

An Azure DevOps preview deployment fails during terraform plan or terraform apply with one of the following provider authentication errors.

AzureRM provider falls back to Azure CLI

Error: unable to build authorizer for Resource Manager API: could not configure AzureCli Authorizer: could not parse Azure CLI version: launching Azure CLI: exec: "az": executable file not found in $PATH

  with module.saif-appservices.provider["registry.terraform.io/hashicorp/azurerm"],
  on .terraform/modules/saif-appservices/provider.tf line 23, in provider "azurerm":
  23: provider "azurerm" {

Okta provider reports a missing API token

Error: [ERROR] failed to load sdk clients: your Okta API token is missing.

  with module.saif-appservices.provider["registry.terraform.io/okta/okta"],
  on .terraform/modules/saif-appservices/provider.tf line 68, in provider "okta":
  68: provider "okta" {}

A Terraform Enterprise warning that recommends the provider token argument or TFE_TOKEN may precede the Okta failure. That warning is not the cause of the missing Okta credentials.


📌 Applies to

Use this guidance for azurerm or Okta providers in downstream service modules such as saif-appservices, backed by HCP Terraform or Terraform Enterprise. It applies to any Forge version using a bootstrap-* workspace to attach credential variable sets to the dependent app workspace, not every environment where az is missing. See the version compatibility matrix for related versions.

  • Identify the failed preview workspace and the project's main API pipeline. Confirm that its Global stage applies the bootstrap workspace responsible for the missing attachments.
  • Confirm you have access to inspect the workspace's variable-set attachments and permission to run that pipeline stage.
  • Do not edit the generated module's provider.tf in the consuming repository or copy credential values into logs to work around this symptom.

Check the bootstrap target

The Global stage applies the bootstrap workspace and changes variable-set attachments. Confirm the project and target workspaces before running it; use the intended main API pipeline, not an unrelated environment's pipeline.


✅ Fix

  1. Open the project's main API pipeline in Azure DevOps.
  2. Run the Global stage and allow its Terraform Cloud bootstrap apply to finish. This attaches the required provider credential variable sets to the app workspaces.
  3. Re-run the failed preview deployment.

🔬 Verify

The preview deployment's terraform plan or terraform apply completes without either of these errors:

  • could not configure AzureCli Authorizer
  • your Okta API token is missing

If the deployment still fails, inspect the affected app workspace's Azure and Okta variable-set attachments in Terraform Cloud. If attachments remain missing, confirm the bootstrap target and Global-stage result before re-running the stage. If the expected attachments exist, do not assume another Global run will resolve a different provider error.


🧠 Cause

Terraform Cloud variable sets supply provider credentials to app workspaces. The project's bootstrap-* workspace creates or attaches those sets, and the Global stage of the main API pipeline applies that workspace.

If the Global stage has not run after someone created or updated the project or its workspaces, a preview workspace can lack one or more variable-set attachments:

  • Without the expected Azure service-principal variables, azurerm falls back to Azure CLI authentication. The pipeline agent does not have the az executable, so that fallback fails.
  • Without the Okta client variable set, the provider cannot read OKTA_ORG_NAME, OKTA_BASE_URL, OKTA_API_CLIENT_ID, OKTA_API_PRIVATE_KEY_ID, OKTA_API_PRIVATE_KEY, and OKTA_API_SCOPES, so it reports a missing API token.

The error location in the generated module's provider.tf points to the symptom, not a provider configuration to edit in the consuming repository.