# Reported issues for Terraform

Pod holds 23 of 62 problems reported by people outside the maintainer team. Issues filed by the project's own owners, members and collaborators are excluded entirely — a maintainer's release checklist is not a warning to a prospective user.

Back to [Terraform](/mcp/terraform).

## Most discussed

### Feature request: Add team, project, and team access management tools

#### Use-cases

When automating Terraform Cloud/Enterprise setup for new teams or projects, three operations are always required but currently missing from the MCP server:

1. **Create a project**
2. **Create a team**
3. **Grant team access to a project or workspace**

Today these must be done via raw API calls (`curl`) or the TFC UI, which breaks the automation flow when using an MCP client. An agent can create workspaces, manage variables, and trigger runs, but cannot set up the organizational

[Read the thread](https://github.com/hashicorp/terraform-mcp-server/issues/368) · 2026-05-21 · open · external user · 3 comments

### Provider search for 'keycloak' returns community provider instead of official

## Description
When searching for 'keycloak' in the Terraform Provider Registry via terraform-mcp-server, the top result is a community provider from the user `mrparkers` rather than the official Keycloak provider. This leads to confusion for users who expect official providers to be prioritized.

## Testing plan
1. Search for 'keycloak' using the provider search functionality in terraform-mcp-server.
2. Observe the returned providers and note that the community provider (mrparkers/keycloak) app

[Read the thread](https://github.com/hashicorp/terraform-mcp-server/issues/178) · 2025-09-23 · open · external user · 3 comments

### [FEAT] Terraform documentation tool

**Suggestion:**
Can you please make additional toolset that would be able to pull latest terraform configuration documentation from https://github.com/hashicorp/terraform or https://developer.hashicorp.com/terraform/language?
Something like _#getTerraformDocs_.

**Use case:**
For example it is very hard to use Copilot and included with it LLM's to write terraform tests. Without actual tests schema they don't know how to write native terraform tests and create some non usable hybrids with terrafo

[Read the thread](https://github.com/hashicorp/terraform-mcp-server/issues/111) · 2025-07-09 · closed · external user · 6 comments

### Unable to use MCP behind Zscaler Internet Access proxy

We leverage Zscaler Internet Access with TLS inspection as part of our base desktop images. Because of this, all requests to external sites receive an intermediate certificate anchored in a Zscaler root and is causing the MCP server calls out to the registry to fail:

`tls: failed to verify certificate: x509: certificate signed by unknown authority`

We either need the image to include known trusted intermediates (like the different Zscaler intermediates) or a way to pass in our own .pem file to

[Read the thread](https://github.com/hashicorp/terraform-mcp-server/issues/89) · 2025-06-12 · closed · external user · 3 comments

### [FEAT] Add support for fetching the latest provider version

First, I would like to thank you for contributing this MCP server.

A request I often ask to my coding agent is "include the latest version of this provider". It would be helpful if the MCP server could expose the provider "metadata".

[Read the thread](https://github.com/hashicorp/terraform-mcp-server/issues/79) · 2025-06-04 · closed · external user · 4 comments

### how to config terraform mcp server with docker opening port and mcp protocol as sse or streamhttp?

how to config terraform mcp server with docker opening port and mcp protocol as sse or streamhttp?
because i deploy my local app is not the same server with terraform mcsp server ,so net network to call ,how to config mcp server configure?

[Read the thread](https://github.com/hashicorp/terraform-mcp-server/issues/68) · 2025-05-23 · closed · external user · 3 comments

### add support for Terraform Cloud Private Registry

Can we utilize the MCP server to provide documentation and context behind Terraform Cloud's Private Registry vs the public one? If I provide my TFC URL and an appropriate API key, it would be great to provide details on private organization resources.

[Read the thread](https://github.com/hashicorp/terraform-mcp-server/issues/63) · 2025-05-20 · closed · external user · 13 comments

### cleanup HCP_TF_TOKEN requirement and repo README to match with initial release PRD

we are launching the TF MCP Server with initial support only for non-auth endpoints on TF Registry. 

the current repository structure has some framework code for TF Enterprise added to it and the README has examples that depict requirement of HCP_TF_TOKEN when configuring the MCP server into AI chat apps or IDEs.

for release-prep, cleanup the README documentation and also ensure MCP server can run without the HCP_TF_TOKEN env variable exported.

[Read the thread](https://github.com/hashicorp/terraform-mcp-server/issues/29) · 2025-05-07 · closed · outside contributor · 5 comments

## Most recent

### Add a `whoami` tool

<!--
Hi there,

Thank you for opening an issue! Please note that we try to keep the this issue tracker reserved for
bug reports and feature requests related to the terraform-mcp-server. If you know
your issue relates to the HCP Terraform, Terraform Enterprise platform or Terraform itself, please contact
HashiCorp support. For general usage questions, please post to our community forum:
https://discuss.hashicorp.com.
-->

#### Use-cases

I have more than one token that I use for accessing differ

[Read the thread](https://github.com/hashicorp/terraform-mcp-server/issues/463) · 2026-08-11 · closed · outside contributor · 1 comment

### `get_apply_logs` hangs then times out if the apply is in a pending state.

<!--
Hi there,

Thank you for opening an issue! Please note that we try to keep the this issue tracker reserved for
bug reports and feature requests related to the terraform-mcp-server. If you know
your issue relates to the HCP Terraform, Terraform Enterprise platform or Terraform itself, please contact
HashiCorp support. For general usage questions, please post to our community forum:
https://discuss.hashicorp.com.
-->

#### terraform-mcp-server version
<!---
What version of terraform-mcp-serve

[Read the thread](https://github.com/hashicorp/terraform-mcp-server/issues/462) · 2026-08-11 · closed · outside contributor · 1 comment

### Module Deprecation/Revocation Status

<!--
Hi there,

Thank you for opening an issue! Please note that we try to keep the this issue tracker reserved for
bug reports and feature requests related to the terraform-mcp-server. If you know
your issue relates to the HCP Terraform, Terraform Enterprise platform or Terraform itself, please contact
HashiCorp support. For general usage questions, please post to our community forum:
https://discuss.hashicorp.com.
-->

#### Use-cases
As a module publisher in our private registry, we need to p

[Read the thread](https://github.com/hashicorp/terraform-mcp-server/issues/455) · 2026-08-07 · open · external user · 0 comments

### retrieve private registry submodule information

currently the `get_private_module_details` tool only returns top-level module info and does not expose any additional information at the individual submodule level

expected outcome: expose private registry submodule information in the same manner as top-level modules.

[Read the thread](https://github.com/hashicorp/terraform-mcp-server/issues/438) · 2026-07-31 · open · external user · 0 comments

### create_no_code_workspace: elicitation marks every module variable required and rejects empty values (defaults/optionality not honoured

**Version**

hashicorp/terraform-mcp-server:latest
(code analysis against main @ ab3929d44fe2a8c37d3cf8d267335f1a8e4f7f01)

**Description**
create_no_code_workspace collects module variables via an elicitation/create request. The way that request is built and validated makes it impossible to create most real no-code modules — any module with an optional or defaulted input variable — even from a client that fully supports elicitation.

Two code paths combine to cause this:

Every input variable i

[Read the thread](https://github.com/hashicorp/terraform-mcp-server/issues/426) · 2026-07-28 · closed · external user · 0 comments

### Not all logs are outputted as JSON when using LOG_FORMAT=json in http-streamable mode

<!--
Hi there,

Thank you for opening an issue! Please note that we try to keep the this issue tracker reserved for
bug reports and feature requests related to the terraform-mcp-server. If you know
your issue relates to the HCP Terraform, Terraform Enterprise platform or Terraform itself, please contact
HashiCorp support. For general usage questions, please post to our community forum:
https://discuss.hashicorp.com.
-->

#### terraform-mcp-server version
<!---
What version of terraform-mcp-serve

[Read the thread](https://github.com/hashicorp/terraform-mcp-server/issues/400) · 2026-07-14 · closed · outside contributor · 1 comment

### stdio mode: server does not exit on stdin EOF, leaking docker run --rm containers

## Problem

When the server runs in stdio mode inside Docker — the documented pattern, and the one shipped in the `hashicorp/agent-skills` Claude Code plugins:

```bash
docker run -i --rm -e TFE_TOKEN -e TFE_ADDRESS hashicorp/terraform-mcp-server
```

the container **does not exit when the MCP client goes away**. When a Claude Code session ends, the client side of the stdin pipe closes, but the server keeps running, so `--rm` never triggers and the container is orphaned. Every new session starts

[Read the thread](https://github.com/hashicorp/terraform-mcp-server/issues/397) · 2026-07-13 · open · external user · 1 comment

### StreamableHTTP: TLS silently not enabled — server sets TLSConfig but calls ListenAndServe() instead of ListenAndServeTLS()

## Summary

When running the server in `streamable-http` mode with `MCP_TLS_CERT_FILE` and
`MCP_TLS_KEY_FILE` set, the server logs `TLS enabled with certificate: ...` but
actually serves **plaintext HTTP**. The TLS configuration is silently ignored.

## Environment

- terraform-mcp-server **v1.0.0** (official Docker image `hashicorp/terraform-mcp-server:1.0.0`)
- Reproduced on Kubernetes (k3s) and plain Docker; behavior is platform-independent

## Steps to reproduce

1. Run the server with TLS c

[Read the thread](https://github.com/hashicorp/terraform-mcp-server/issues/390) · 2026-07-06 · closed · external user · 0 comments

### --tools alone exits with "Cannot use both --tools and --toolsets flags together"

## Summary

Passing only `--tools` (without `--toolsets`) on the command line causes the server to exit immediately with:

```
Cannot use both --tools and --toolsets flags together
```

## Repro

```
$ go build -o ./terraform-mcp-server ./cmd/terraform-mcp-server/
$ ./terraform-mcp-server --tools=search_providers,get_provider_details
time="..." level=fatal msg="Cannot use both --tools and --toolsets flags together"
$ echo $?
1
```

The same Fatal fires whether the transport is `stdio`, the `stre

[Read the thread](https://github.com/hashicorp/terraform-mcp-server/issues/379) · 2026-06-02 · closed · outside contributor · 1 comment

### --tools and --toolsets flags silently ignored in streamable-HTTP env-var mode

## Summary

`--tools` and `--toolsets` CLI flags are silently ignored when the server is started in streamable-HTTP mode via the `TRANSPORT_MODE` env var. The flags always fall back to their declared defaults (`--toolsets="all"`, `--tools=""`), regardless of what is passed on the command line. The flags work as expected with the explicit `terraform-mcp-server streamable-http …` subcommand invocation — only the env-var-driven shortcut is affected.

This is a regression for anyone running the serv

[Read the thread](https://github.com/hashicorp/terraform-mcp-server/issues/376) · 2026-05-28 · open · outside contributor · 0 comments

### Add force_unlock_workspace MCP tool

#### Use-cases

When a Terraform workspace lock gets stuck (e.g. a run crashes or is interrupted and the lock isn't released, or the locking session times out without releasing), there is no way today to recover from inside an AI assistant context.

Operators have to leave their MCP-driven flow and either:

- Click "Force unlock" in the HCP Terraform/TFE UI, or
- Hand-roll `POST /api/v2/workspaces/:id/actions/force-unlock` via curl with their TFE token.

Both options break the assistant loop and

[Read the thread](https://github.com/hashicorp/terraform-mcp-server/issues/372) · 2026-05-25 · closed · outside contributor · 1 comment

### Security scan results for terraform-mcp-server — MCPSafe AIVSS 94/100 (Grade B)

Hi team 👋

I ran a free security scan of **hashicorp/terraform-mcp-server** using [MCPSafe](https://mcpsafe.io) — a purpose-built scanner for MCP servers that uses a 5-LLM consensus panel to detect prompt injection risks, over-scoped tool schemas, supply chain issues, and more.

## Results: 94/100 · Grade B

| Severity | Count |
|----------|-------|
| 🔴 Critical | 0 |
| 🟠 High | 0 |
| 🟡 Medium | 5 |
| 🟢 Low | 0 |

**Summary:** 5 medium-severity findings — strong security posture

📋 **Full report

[Read the thread](https://github.com/hashicorp/terraform-mcp-server/issues/361) · 2026-05-12 · closed · external user · 0 comments

### Feature request: Add tool to read/list run comments

## Summary

There is currently no way to retrieve comments attached to a Terraform run via the MCP server. The `action_run` tool supports *writing* a comment when applying/discarding/canceling a run, but there is no tool to *read* existing comments.

## Use Case

When an AI agent inspects a run (e.g., via `get_run_details`), it can see that comments exist (the workspace comment ID is returned), but cannot retrieve the actual comment text. This limits the agent's ability to understand context lef

[Read the thread](https://github.com/hashicorp/terraform-mcp-server/issues/347) · 2026-04-29 · closed · external user · 1 comment

### Fall-back option for No-Code Workspaces where client does not support MCP Elicitation

#### Use-cases
Currently neither Claude.ai / Desktop nor OpenClaw support the MCP elicitation function.   This means that while they can see the tools for creating no-code workspaces, they fail when asked to surface variable requests  to the end user.

#### Attempted Solutions
MCP Elicitation does not seem to be widely supported at the moment.  I have looked into options with both OpenClaw and Claude but have had no success.

#### Proposal
I would like to see an alternative where the LLM can que

[Read the thread](https://github.com/hashicorp/terraform-mcp-server/issues/343) · 2026-04-25 · open · external user · 1 comment

### v0.5.0+ breaks `go install` due to replace directives in go.mod

## Description

Starting with v0.5.0, `go install` no longer works because `go.mod` contains `replace` directives. Go rejects `replace` directives when installing a module remotely (i.e., not as the main module) as a security measure.

## Steps to reproduce

```bash
go install github.com/hashicorp/terraform-mcp-server/cmd/terraform-mcp-server@v0.5.1
```

## Error

```
go: github.com/hashicorp/terraform-mcp-server/cmd/terraform-mcp-server@latest (in github.com/hashicorp/terraform-mcp-server@v0.5.

[Read the thread](https://github.com/hashicorp/terraform-mcp-server/issues/331) · 2026-04-16 · closed · external user · 0 comments

The remaining reports are on [the project's issue tracker](https://github.com/hashicorp/terraform-mcp-server/issues).
