Error: Variables not allowed: "Variables may not be used here" in backend blocks
Fixes Terraform's "Error: Variables not allowed ... Variables may not be used here" when variable references appear inside backend blocks. Use when init fails on a backend config using var.*. Backend blocks only accept literal values or -backend-config flags; not for provider config variables.
TL;DR
Backend blocks cannot use variables. Terraform configures the backend before it evaluates any variable blocks, so var.*, local.*, and resource references are all rejected there. Move the values out: use -backend-config flags or a backend config file, and keep the backend block to static keys or an empty stub.
The error
Error: Variables not allowed
on backend.tf line 3, in terraform:
3: bucket = var.state_bucket
Variables may not be used here.Steps to fix
- Remove every
var./local./resource reference from thebackendblock. Leave static values or an empty block:
terraform {
backend "s3" {}
}- Expected: no variable references remain in the backend block.
- Supply the values at init time instead:
terraform init -backend-config="bucket=my-state-bucket" -backend-config="key [your value] -backend-config="region=us-east-1" or keep them in a file: terraform init -backend-config=backend-prod.hcl.
- Expected: init configures the backend from the flags/file.
- Re-run
terraform init.
- Expected: backend initializes without the variables error.
When to use this
terraform initfails withVariables not allowed/Variables may not be used herepointing at abackendblock.
When NOT to use this
- Variables are fine in
providerblocks and everywhere else; this restriction is backend-only.terraform_remote_statedata sources can use variables in theirconfig.
Compatibility
- All Terraform versions; backend evaluation order is fundamental and unchanged.
Root cause
The backend must be configured before Terraform can read state, and state may be needed to evaluate variables. To avoid the chicken-and-egg problem, backend configuration accepts only literal values, environment variables (for some backends), and -backend-config inputs.
Edge cases
- Partial backend configuration (empty
backend "s3" {}) still requires every required argument via-backend-config; missing ones prompt interactively and fail in CI. - Some backends read credentials from environment variables (e.g. AWS_*); those are allowed and often cleaner than flags.
- Changing backend config values later requires
terraform init -reconfigure.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.