# Fix terraform "Error: Failed to get existing workspaces" (S3 backend)

**TL;DR:** `terraform init` cannot list workspaces in your S3 backend. Almost always the bucket does not exist yet, the region in the backend block is wrong, or your IAM identity lacks `s3:ListBucket`. Backend resources must exist before init, so create the bucket first, then re-run `terraform init -reconfigure`.

## The error

```text
Error: Failed to get existing workspaces: error listing S3 Bucket Objects:
NoSuchBucket: The specified bucket does not exist
```

## Steps

1. Check the bucket exists: `aws s3 ls s3://YOUR_STATE_BUCKET`. Expected: the bucket is listed. If not, it was never created or the name is wrong.
2. Check the region in your `backend "s3"` block matches the bucket's real region. Expected: they match; a mismatch gives `BucketRegionError` instead.
3. Create the bucket: `aws s3api create-bucket --bucket YOUR_STATE_BUCKET --region YOUR_REGION`. Expected: the bucket is created.
4. Re-run `terraform init -reconfigure`. Expected: `Terraform has been successfully initialized!`

## When this applies

- `terraform init` fails at "Initializing the backend" with "Failed to get existing workspaces" and an S3 error underneath.
- You just wired up the S3 backend and never created the bucket.

## When it does NOT apply

- State lock errors at apply time. That is a locking problem on an existing backend, not a missing bucket.
- "Backend configuration changed". That is init noticing you edited the backend block; it wants `-reconfigure` or `-migrate-state`.

## Tool and version compatibility

- Terraform CLI 0.12+ through 1.x. No provider needed; the S3 backend is built into the CLI. AWS CLI for the bucket checks.

## Why it happens

Backend initialization is the first thing init does, and it lists existing workspaces to understand the state layout. Listing requires a bucket that exists, in the region you named, readable by your credentials. Any of those missing fails the listing before providers or modules are even considered.

## Edge cases and pitfalls

- IAM needs `s3:ListBucket`, `s3:GetObject`, and `s3:PutObject` on the bucket and `bucket/*`. `AccessDenied` on init is the permissions variant of this same failure.
- Bucket names are globally unique. A name that "should" exist might belong to another account.
- This error also appears when the backend block uses variables or interpolation. Backend blocks only take literals; pass values with `-backend-config=backend.hcl` instead.