TL;DR: `render-json` isn't pure config rendering: evaluating your `locals` can require reading remote state, which needs working AWS credentials AND an initialized backend. Fix auth (and backend init) first, then render.

```text
ERRO[0002] Could not convert include to the execution context to evaluate additional locals
ERRO[0002] Encountered error while evaluating locals in file .../terragrunt.hcl
ERRO[0002] exit status 1
```

(often preceded by `Error: Backend initialization required` or followed by `Error: Failed to load state: AccessDenied`)

## Steps

1. Read the FULL output, not just the last lines: the root cause is usually above (`Backend initialization required` = run init; `AccessDenied` = auth).
   Expected: you know whether it's init or credentials.
2. If backend: run `terragrunt init` (or `init -reconfigure`/`-migrate-state` if the backend changed).
   Expected: backend initializes.
3. If auth: configure AWS credentials for the right account (`aws sts get-caller-identity` to verify).
   Expected: you are the principal you think you are.
4. Re-run `terragrunt render-json`.
   Expected: it renders.

## When this applies

- `render-json` / `render` fails with `Could not convert include to the execution context` or `Encountered error while evaluating locals`.
- Locals (or the include chain) read remote state, `terraform output`, or anything credentialed.

## When it doesn't apply

- Pure HCL syntax errors: `terragrunt hcl validate` is the tool, and the error names the line.
- `ParentFileNotFoundError` / `Include configuration not found`: path problems, not auth.

## Tool versions

All Terragrunt versions with `render-json`.

## Why it happens

Rendering resolves the full configuration including `locals`, and locals can call functions that reach out to the world (`read_terragrunt_config` on state-backed files, outputs via the backend). The "could not convert include" message is Terragrunt giving up on building the evaluation context, not the actual error; the actual error is the init/auth failure above it.

## Edge cases

- In CI, `render-json` needs the same credentials as `plan`; don't assume it's safe to run credential-less.
- If the backend was never initialized in that working copy, even valid credentials won't help until init runs.