## TL;DR

The value you passed failed the variable's own `validation` block. The error message is the custom `error_message` from the config, so it tells you exactly what is wrong. Pass a value that satisfies the condition, or fix the condition.

## The error

```text
Error: Invalid value for variable

Environment must be dev, staging, or production.
```

## Steps to fix

1. Read the message after the header: it is the `error_message` from the variable's `validation` block (here: must be dev, staging, or production).
   - Expected: you know the allowed values.
2. Find where you set the value: `-var` flag, `.tfvars` file, or environment variable `TF_VAR_[name]`.
   - Expected: you locate the offending input (e.g. `-var="environment=prod"`).
3. Either pass an allowed value, or if the validation is wrong, update the `condition` in `variables.tf`.
   - Expected: the value satisfies the condition.
4. Re-run `terraform plan`.
   - Expected: validation passes and planning continues.

## When to use this

- `plan`/`apply` fails with `Invalid value for variable` plus a human-written message, after someone added a `validation` block or changed inputs.

## When NOT to use this

- `Invalid default value for variable` is about the *default* in the config, not your input. `Value for undeclared variable` means the variable does not exist at the root at all.

## Compatibility

- Variable validation blocks: Terraform 0.13+. Behavior stable across 1.x.

## Root cause

`validation` blocks are assertions the module author writes about acceptable inputs. Terraform evaluates the `condition` against the final value (default overridden by caller input); a false result fails the run with the author's message before any planning.

## Edge cases

- The condition can reference other variables, but not resources or data sources.
- `nullable` variables: validation is skipped when the value is null unless the condition handles it.
- Passing the variable at the wrong level (module instead of root) gives `Value for undeclared variable`, a different error with a different fix.