Error: Missing required argument
Fixes OpenTofu's 'Error: Missing required argument' inside encryption key_provider blocks, usually a missing passphrase on pbkdf2. Use when tofu 1.7+ rejects your state-encryption config naming a required argument. Not for 'Unsupported block type encryption' on older tofu.
TL;DR: Your encryption block's key_provider is missing a required argument. The error names it (for pbkdf2 it's passphrase). Add the argument to the key_provider block. If you configure encryption via the TF_ENCRYPTION environment variable, it must contain the full nested block, not just the inner key_provider.
Error: Missing required argument
on main.tf line 3, in terraform:
3: key_provider "pbkdf2" "main" {
The argument "passphrase" is required, but no definition was
found.Steps
- Open the
terraformblock and find theencryption->key_providerblock the error points at.
Expected: you see the block missing the named argument.
- Add the required argument. For
pbkdf2, that's a passphrase of at least 16 characters:
terraform {
encryption {
key_provider "pbkdf2" "main" {
passphrase = "[your passphrase, 16+ chars]"
}
method "aes_gcm" "main" {
keys = key_provider.pbkdf2.main
}
state {
method = method.aes_gcm.main
}
}
}Expected: the block now defines every required argument.
- If you use
TF_ENCRYPTION, export the FULL nested block (terraform -> encryption -> keyprovider), not just the inner `keyprovideralone. A barekey_providerat the top of the env var value fails withUnsupported block type` or drops required arguments.
Expected: tofu plan no longer complains about the encryption config.
- Run
tofu planto verify.
Expected: plan proceeds; no encryption errors.
When this applies
- OpenTofu 1.7 or later with a
terraform { encryption { ... } }block. - The error names a specific argument (
passphrase,key_id, etc.) inside akey_providerormethodblock.
When it doesn't apply
Error: Unsupported block type "encryption"means your tofu is older than 1.7; upgrade instead.Error: Failed to retrieve key from key providermeans the config parsed but the key itself couldn't be loaded; that's a credentials problem, not a missing argument.
Tool versions
OpenTofu 1.7+, which introduced state encryption. Each key_provider type (pbkdf2, aws_kms, gcp_kms, openbao, azure_key_vault) has its own required arguments; check the docs for the one you use.
Why it happens
Encryption key providers need real secrets to derive data keys, so their arguments are required, not optional. A missing argument fails closed at config load: tofu would rather refuse than silently run with unencrypted state.
Edge cases
- Don't commit a real passphrase in the config file. Use
TF_ENCRYPTIONor a separate vars file excluded from version control. pbkdf2needs 16+ characters; shorter values fail validation with a different error.- Changing encryption settings on a backend that already holds state requires migrating the state; read the encryption docs' migration section before flipping it on an existing workspace.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.