Error: registered checksum for provider does not match
Fixes OpenTofu's 'registered checksum for provider does not match' by recording hashes for every platform. Use when the lock file was generated on one OS/arch and CI runs on another. Not for genuinely tampered downloads.
TL;DR: Your lock file only has hashes for the platform it was generated on (e.g. macOS arm64), and CI runs on another (linux amd64). Record hashes for ALL your platforms with tofu providers lock -platform=... and commit the result. Never delete the lock file.
Error: registered checksum for provider ... does not matchSteps
- Confirm it's a platform gap: the error appears on a different OS/arch than the machine that generated
.terraform.lock.hcl.
Expected: local init works, CI init fails (or vice versa).
- Record every platform you use:
tofu providers lock \
-platform=linux_amd64 \
-platform=darwin_arm64 \
-platform=linux_arm64 Expected: the lock file gains zh: hashes for each platform.
- Commit the updated
.terraform.lock.hcl.
Expected: CI and local both init clean.
When this applies
- Checksum mismatch that appears only on a specific platform.
- Mixed team (macOS + Linux) or CI on a different arch than dev machines.
When it doesn't apply
Error: Inconsistent dependency lock file: that's a version-selection conflict, fixed by re-resolving, not by adding platforms.- Mismatch on the SAME platform after no upgrade: investigate a tampered mirror or corrupted cache before accepting new hashes.
Tool versions
All OpenTofu versions.
Why it happens
The lock file pins hashes per platform. A lock generated on one machine only knows that machine's platform; any other platform's download has no recorded hash to compare against, so init refuses rather than trusting an unpinned binary.
Edge cases
- If you DID upgrade a provider intentionally,
tofu init -upgraderegenerates hashes; use that instead of hand-editing. - Deleting the lock file "fixes" it by removing all pins, which moves the problem to the next person and every future CI run. Don't.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.