---
id: SAIFTRBL0014
moved_from:
  - guides/troubleshooting/terraform-azurecli-authorizer-az-not-found.md
title: "Terraform provider authentication fails because workspace variable sets are missing"
description: Resolve AzureRM and Okta provider authentication failures by running the Global stage of the main API pipeline to attach the required Terraform Cloud variable sets.
tags:
  - troubleshooting
  - terraform
  - pipelines
---

# Terraform provider authentication fails because workspace variable sets are missing

When a preview workspace lacks its provider credential variable sets, run the **Global** stage of the project's main API pipeline, then retry the preview deployment. The Global stage applies the Terraform Cloud bootstrap workspace that attaches those sets; this fix applies to projects using that bootstrap workflow.

---

## 🚨 Symptom

An Azure DevOps preview deployment fails during `terraform plan` or `terraform apply` with one of the following provider authentication errors.

### AzureRM provider falls back to Azure CLI

```text
Error: unable to build authorizer for Resource Manager API: could not configure AzureCli Authorizer: could not parse Azure CLI version: launching Azure CLI: exec: "az": executable file not found in $PATH

  with module.saif-appservices.provider["registry.terraform.io/hashicorp/azurerm"],
  on .terraform/modules/saif-appservices/provider.tf line 23, in provider "azurerm":
  23: provider "azurerm" {
```

### Okta provider reports a missing API token

```text
Error: [ERROR] failed to load sdk clients: your Okta API token is missing.

  with module.saif-appservices.provider["registry.terraform.io/okta/okta"],
  on .terraform/modules/saif-appservices/provider.tf line 68, in provider "okta":
  68: provider "okta" {}
```

A Terraform Enterprise warning that recommends the provider `token` argument or `TFE_TOKEN` may precede the Okta failure. That warning is not the cause of the missing Okta credentials.

---

## 📌 Applies to

Use this guidance for `azurerm` or Okta providers in downstream service modules such as `saif-appservices`, backed by HCP Terraform or Terraform Enterprise. It applies to any Forge version using a `bootstrap-*` workspace to attach credential variable sets to the dependent app workspace, not every environment where `az` is missing. See the [version compatibility matrix](../reference/version-compatibility.md) for related versions.

- Identify the failed preview workspace and the project's main API pipeline. Confirm that its Global stage applies the bootstrap workspace responsible for the missing attachments.
- Confirm you have access to inspect the workspace's variable-set attachments and permission to run that pipeline stage.
- Do not edit the generated module's `provider.tf` in the consuming repository or copy credential values into logs to work around this symptom.

!!! warning "Check the bootstrap target"
    The Global stage applies the bootstrap workspace and changes variable-set attachments. Confirm the project and target workspaces before running it; use the intended main API pipeline, not an unrelated environment's pipeline.

---

## ✅ Fix

1. Open the project's main API pipeline in Azure DevOps.
2. Run the **Global** stage and allow its Terraform Cloud bootstrap apply to finish. This attaches the required provider credential variable sets to the app workspaces.
3. Re-run the failed preview deployment.

---

## 🔬 Verify

The preview deployment's `terraform plan` or `terraform apply` completes without either of these errors:

- `could not configure AzureCli Authorizer`
- `your Okta API token is missing`

If the deployment still fails, inspect the affected app workspace's Azure and Okta variable-set attachments in Terraform Cloud. If attachments remain missing, confirm the bootstrap target and Global-stage result before re-running the stage. If the expected attachments exist, do not assume another Global run will resolve a different provider error.

---

## 🧠 Cause

Terraform Cloud variable sets supply provider credentials to app workspaces. The project's `bootstrap-*` workspace creates or attaches those sets, and the **Global** stage of the main API pipeline applies that workspace.

If the Global stage has not run after someone created or updated the project or its workspaces, a preview workspace can lack one or more variable-set attachments:

- Without the expected Azure service-principal variables, `azurerm` falls back to Azure CLI authentication. The pipeline agent does not have the `az` executable, so that fallback fails.
- Without the Okta client variable set, the provider cannot read `OKTA_ORG_NAME`, `OKTA_BASE_URL`, `OKTA_API_CLIENT_ID`, `OKTA_API_PRIVATE_KEY_ID`, `OKTA_API_PRIVATE_KEY`, and `OKTA_API_SCOPES`, so it reports a missing API token.

The error location in the generated module's `provider.tf` points to the symptom, not a provider configuration to edit in the consuming repository.

---

## 📚 Related

- [tfe-bootstrapper module README](https://github.com/saif-corp/forge/blob/main/src/terraform/tfe-bootstrapper/README.md)
