Terraform provider authentication fails because workspace variable sets are missing¶
When a preview workspace lacks its provider credential variable sets, run the Global stage of the project's main API pipeline, then retry the preview deployment. The Global stage applies the Terraform Cloud bootstrap workspace that attaches those sets; this fix applies to projects using that bootstrap workflow.
🚨 Symptom¶
An Azure DevOps preview deployment fails during terraform plan or terraform apply with one of the following provider authentication errors.
AzureRM provider falls back to Azure CLI¶
Error: unable to build authorizer for Resource Manager API: could not configure AzureCli Authorizer: could not parse Azure CLI version: launching Azure CLI: exec: "az": executable file not found in $PATH
with module.saif-appservices.provider["registry.terraform.io/hashicorp/azurerm"],
on .terraform/modules/saif-appservices/provider.tf line 23, in provider "azurerm":
23: provider "azurerm" {
Okta provider reports a missing API token¶
Error: [ERROR] failed to load sdk clients: your Okta API token is missing.
with module.saif-appservices.provider["registry.terraform.io/okta/okta"],
on .terraform/modules/saif-appservices/provider.tf line 68, in provider "okta":
68: provider "okta" {}
A Terraform Enterprise warning that recommends the provider token argument or TFE_TOKEN may precede the Okta failure. That warning is not the cause of the missing Okta credentials.
📌 Applies to¶
Use this guidance for azurerm or Okta providers in downstream service modules such as saif-appservices, backed by HCP Terraform or Terraform Enterprise. It applies to any Forge version using a bootstrap-* workspace to attach credential variable sets to the dependent app workspace, not every environment where az is missing. See the version compatibility matrix for related versions.
- Identify the failed preview workspace and the project's main API pipeline. Confirm that its Global stage applies the bootstrap workspace responsible for the missing attachments.
- Confirm you have access to inspect the workspace's variable-set attachments and permission to run that pipeline stage.
- Do not edit the generated module's
provider.tfin the consuming repository or copy credential values into logs to work around this symptom.
Check the bootstrap target
The Global stage applies the bootstrap workspace and changes variable-set attachments. Confirm the project and target workspaces before running it; use the intended main API pipeline, not an unrelated environment's pipeline.
✅ Fix¶
- Open the project's main API pipeline in Azure DevOps.
- Run the Global stage and allow its Terraform Cloud bootstrap apply to finish. This attaches the required provider credential variable sets to the app workspaces.
- Re-run the failed preview deployment.
🔬 Verify¶
The preview deployment's terraform plan or terraform apply completes without either of these errors:
could not configure AzureCli Authorizeryour Okta API token is missing
If the deployment still fails, inspect the affected app workspace's Azure and Okta variable-set attachments in Terraform Cloud. If attachments remain missing, confirm the bootstrap target and Global-stage result before re-running the stage. If the expected attachments exist, do not assume another Global run will resolve a different provider error.
🧠 Cause¶
Terraform Cloud variable sets supply provider credentials to app workspaces. The project's bootstrap-* workspace creates or attaches those sets, and the Global stage of the main API pipeline applies that workspace.
If the Global stage has not run after someone created or updated the project or its workspaces, a preview workspace can lack one or more variable-set attachments:
- Without the expected Azure service-principal variables,
azurermfalls back to Azure CLI authentication. The pipeline agent does not have theazexecutable, so that fallback fails. - Without the Okta client variable set, the provider cannot read
OKTA_ORG_NAME,OKTA_BASE_URL,OKTA_API_CLIENT_ID,OKTA_API_PRIVATE_KEY_ID,OKTA_API_PRIVATE_KEY, andOKTA_API_SCOPES, so it reports a missing API token.
The error location in the generated module's provider.tf points to the symptom, not a provider configuration to edit in the consuming repository.