VectleSkillsError: Missing required argument

Error: Missing required argument

Export

Fixes OpenTofu's 'Error: Missing required argument' inside encryption key_provider blocks, usually a missing passphrase on pbkdf2. Use when tofu 1.7+ rejects your state-encryption config naming a required argument. Not for 'Unsupported block type encryption' on older tofu.

TL;DR: Your encryption block's key_provider is missing a required argument. The error names it (for pbkdf2 it's passphrase). Add the argument to the key_provider block. If you configure encryption via the TF_ENCRYPTION environment variable, it must contain the full nested block, not just the inner key_provider.

Error: Missing required argument

  on main.tf line 3, in terraform:
   3:     key_provider "pbkdf2" "main" {

The argument "passphrase" is required, but no definition was
found.

Steps

  1. Open the terraform block and find the encryption -> key_provider block the error points at.

Expected: you see the block missing the named argument.

  1. Add the required argument. For pbkdf2, that's a passphrase of at least 16 characters:
   terraform {
     encryption {
       key_provider "pbkdf2" "main" {
         passphrase = "[your passphrase, 16+ chars]"
       }
       method "aes_gcm" "main" {
         keys = key_provider.pbkdf2.main
       }
       state {
         method = method.aes_gcm.main
       }
     }
   }

Expected: the block now defines every required argument.

  1. If you use TF_ENCRYPTION, export the FULL nested block (terraform -> encryption -> keyprovider), not just the inner `keyprovider alone. A bare key_provider at the top of the env var value fails with Unsupported block type` or drops required arguments.

Expected: tofu plan no longer complains about the encryption config.

  1. Run tofu plan to verify.

Expected: plan proceeds; no encryption errors.

When this applies

  • OpenTofu 1.7 or later with a terraform { encryption { ... } } block.
  • The error names a specific argument (passphrase, key_id, etc.) inside a key_provider or method block.

When it doesn't apply

  • Error: Unsupported block type "encryption" means your tofu is older than 1.7; upgrade instead.
  • Error: Failed to retrieve key from key provider means the config parsed but the key itself couldn't be loaded; that's a credentials problem, not a missing argument.

Tool versions

OpenTofu 1.7+, which introduced state encryption. Each key_provider type (pbkdf2, aws_kms, gcp_kms, openbao, azure_key_vault) has its own required arguments; check the docs for the one you use.

Why it happens

Encryption key providers need real secrets to derive data keys, so their arguments are required, not optional. A missing argument fails closed at config load: tofu would rather refuse than silently run with unencrypted state.

Edge cases

  • Don't commit a real passphrase in the config file. Use TF_ENCRYPTION or a separate vars file excluded from version control.
  • pbkdf2 needs 16+ characters; shorter values fail validation with a different error.
  • Changing encryption settings on a backend that already holds state requires migrating the state; read the encryption docs' migration section before flipping it on an existing workspace.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=Error%3A+Missing+required+argument&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.