Error: Inconsistent dependency lock file
Fixes OpenTofu's 'Error: Inconsistent dependency lock file' by re-resolving provider versions with tofu init -upgrade. Use when tofu init, plan, or apply refuses because .terraform.lock.hcl doesn't match the providers in your configuration. Not for registry network failures or unknown provider sources.
TL;DR: Run tofu init -upgrade. It re-resolves your providers against the current configuration and rewrites .terraform.lock.hcl so the recorded selections match. You hit this when a provider was added to the config, or its version constraint changed, after the lock file was written.
Error: Inconsistent dependency lock file
The following dependency selections recorded in the lock file are
inconsistent with the current configuration:
- provider registry.opentofu.org/hashicorp/random: required by this
configuration but no version is selected
To update the locked dependency selections to match a changed
configuration, run:
tofu init -upgradeSteps
- Run
tofu init -upgradein the root module directory.
Expected: tofu downloads the missing providers and prints - Installing hashicorp/random v[version]..., ending with OpenTofu has been successfully initialized!
- Confirm
.terraform.lock.hclnow lists the provider with a selected version and hashes.
Expected: a provider "registry.opentofu.org/hashicorp/random" block with version and hashes entries.
- Commit the updated lock file so CI and teammates get the same pins.
Expected: git diff --stat shows .terraform.lock.hcl modified.
- Re-run your original command (
tofu plan/tofu apply).
Expected: no lock error; the plan proceeds.
When this applies
- Right after adding a provider, or a resource from a new provider, to your config.
- After changing a
versionconstraint inrequired_providers. - CI fails on
tofu initortofu planwhile it works on your machine (stale committed lock file).
When it doesn't apply
Error: Failed to query available provider packagesmeans tofu can't reach the registry or the provider doesn't exist. That's a network or naming problem, not a lock mismatch.Error: Failed to install providerwith checksum complaints means the lock file hashes don't match the downloads. Different fix.
Tool versions
OpenTofu 1.6 and later. The lock file mechanism is inherited from Terraform 0.14 and up; tofu writes the same .terraform.lock.hcl format.
Why it happens
The lock file records the exact provider versions chosen at the last successful init. When the configuration changes (new provider, new constraint), the recorded selections no longer describe the config, and tofu refuses to guess. -upgrade tells it to pick fresh versions inside your constraints instead of reusing the recorded ones.
Edge cases
- Don't just delete the lock file and re-init. That works locally but throws away the pins your team relies on for reproducible builds. Prefer
-upgrade. - Multi-platform teams: after
-upgradeon one OS, runtofu providers lock -platform=linux_amd64 -platform=darwin_amd64 -platform=darwin_arm64so runners on other platforms don't hit hash mismatches. - If the lock file is gitignored, every fresh clone can hit this. Either commit it, or make
tofu init -upgradepart of your setup script.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.