Could not convert include to the execution context to evaluate additional locals
Fixes Terragrunt's 'Could not convert include to the execution context' during render-json by checking AWS auth. Use when terragrunt render-json fails evaluating locals that read remote state or outputs. Not for HCL syntax errors.
TL;DR: render-json isn't pure config rendering: evaluating your locals can require reading remote state, which needs working AWS credentials AND an initialized backend. Fix auth (and backend init) first, then render.
ERRO[0002] Could not convert include to the execution context to evaluate additional locals
ERRO[0002] Encountered error while evaluating locals in file .../terragrunt.hcl
ERRO[0002] exit status 1(often preceded by Error: Backend initialization required or followed by Error: Failed to load state: AccessDenied)
Steps
- Read the FULL output, not just the last lines: the root cause is usually above (
Backend initialization required= run init;AccessDenied= auth).
Expected: you know whether it's init or credentials.
- If backend: run
terragrunt init(orinit -reconfigure/-migrate-stateif the backend changed).
Expected: backend initializes.
- If auth: configure AWS credentials for the right account (
aws sts get-caller-identityto verify).
Expected: you are the principal you think you are.
- Re-run
terragrunt render-json.
Expected: it renders.
When this applies
render-json/renderfails withCould not convert include to the execution contextorEncountered error while evaluating locals.- Locals (or the include chain) read remote state,
terraform output, or anything credentialed.
When it doesn't apply
- Pure HCL syntax errors:
terragrunt hcl validateis the tool, and the error names the line. ParentFileNotFoundError/Include configuration not found: path problems, not auth.
Tool versions
All Terragrunt versions with render-json.
Why it happens
Rendering resolves the full configuration including locals, and locals can call functions that reach out to the world (read_terragrunt_config on state-backed files, outputs via the backend). The "could not convert include" message is Terragrunt giving up on building the evaluation context, not the actual error; the actual error is the init/auth failure above it.
Edge cases
- In CI,
render-jsonneeds the same credentials asplan; don't assume it's safe to run credential-less. - If the backend was never initialized in that working copy, even valid credentials won't help until init runs.