# Error: load converter plugin: install "terraform": could not find latest version for provider terraform: rate limit exceeded

## TL;DR
GitHub rate-limited the converter plugin download. Wait out the limit, or set `GITHUB_TOKEN` so the plugin fetch uses authenticated rate limits, then retry the import.

## The error

```
error: load converter plugin: install "terraform": could not find latest version for provider terraform: rate limit exceeded: 403 HTTP error fetching plugin from https://api.github.com/repos/pulumi/pulumi-converter-terraform/releases/latest
```

## Fix it

1. Note the wait time in the log line just above: `GitHub rate limit exceeded ... try again in 7m51s`.
   - Success check: you know exactly how long to wait.
2. For an immediate fix, export a GitHub token -  `export GITHUB_TOKEN [your value] token]` and re-run.
   - Success check: the plugin download uses authenticated limits (much higher) and succeeds.
3. Or simply wait out the window and retry `pulumi import --from terraform`.
   - Success check: the converter plugin installs and the import proceeds.
4. In CI, always set `GITHUB_TOKEN` (the built-in `secrets.GITHUB_TOKEN` works) before any Pulumi plugin or converter download.
   - Success check: scheduled runs stop flaking on rate limits.

## When to use this
You hit this on `pulumi import --from terraform` or `pulumi convert --from terraform` when the converter plugin cannot be downloaded.

## When NOT to use this
Do not use this for "could not find mapping information for provider" errors. That is a missing provider mapping, not a download failure.

## Compatibility
Pulumi CLI 3.x, the `pulumi-converter-terraform` plugin. GitHub API rate limits apply to all plugin downloads.

## Variants
- `GitHub rate limit exceeded for https://api.github.com/repos/pulumi/pulumi-converter-terraform/releases/latest, try again in [duration]`
- The same 403 on regular provider plugin downloads (`pulumi plugin install`) under heavy CI load

## Root cause
Pulumi downloads converter and provider plugins from GitHub releases. Unauthenticated API requests are limited to 60/hour per IP; shared CI runners and fresh builds burn through that fast, and the plugin version lookup 403s.

## Edge cases
- Building Pulumi-adjacent tooling (e.g. Nix builds) can exhaust the limit before you even run the import. The token fixes that too.
- `pulumi convert` (not `import`) is the right command for converting configuration; using the wrong one produces confusing follow-on errors.
