Error: Failed to get existing workspaces
Fixes terraform's "Error: Failed to get existing workspaces" against the S3 backend. Use when terraform init fails listing backend workspaces because the state bucket is missing, the region is wrong, or IAM permissions are short. Not for apply-time lock errors or backend configuration change prompts.
Fix terraform "Error: Failed to get existing workspaces" (S3 backend)
TL;DR: terraform init cannot list workspaces in your S3 backend. Almost always the bucket does not exist yet, the region in the backend block is wrong, or your IAM identity lacks s3:ListBucket. Backend resources must exist before init, so create the bucket first, then re-run terraform init -reconfigure.
The error
Error: Failed to get existing workspaces: error listing S3 Bucket Objects:
NoSuchBucket: The specified bucket does not existSteps
- Check the bucket exists:
aws s3 ls s3://YOUR_STATE_BUCKET. Expected: the bucket is listed. If not, it was never created or the name is wrong. - Check the region in your
backend "s3"block matches the bucket's real region. Expected: they match; a mismatch givesBucketRegionErrorinstead. - Create the bucket:
aws s3api create-bucket --bucket YOUR_STATE_BUCKET --region YOUR_REGION. Expected: the bucket is created. - Re-run
terraform init -reconfigure. Expected:Terraform has been successfully initialized!
When this applies
terraform initfails at "Initializing the backend" with "Failed to get existing workspaces" and an S3 error underneath.- You just wired up the S3 backend and never created the bucket.
When it does NOT apply
- State lock errors at apply time. That is a locking problem on an existing backend, not a missing bucket.
- "Backend configuration changed". That is init noticing you edited the backend block; it wants
-reconfigureor-migrate-state.
Tool and version compatibility
- Terraform CLI 0.12+ through 1.x. No provider needed; the S3 backend is built into the CLI. AWS CLI for the bucket checks.
Why it happens
Backend initialization is the first thing init does, and it lists existing workspaces to understand the state layout. Listing requires a bucket that exists, in the region you named, readable by your credentials. Any of those missing fails the listing before providers or modules are even considered.
Edge cases and pitfalls
- IAM needs
s3:ListBucket,s3:GetObject, ands3:PutObjecton the bucket andbucket/*.AccessDeniedon init is the permissions variant of this same failure. - Bucket names are globally unique. A name that "should" exist might belong to another account.
- This error also appears when the backend block uses variables or interpolation. Backend blocks only take literals; pass values with
-backend-config=backend.hclinstead.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.