Skip to content

Type to search pages.

View .md

Error reference

Every user facing error carries a code of the form AF-<AREA>-<NNN>. This page is generated from engine/internal/errors/catalog.yaml, so it cannot fall behind the code: a code with no entry here fails the build, and an entry that nothing returns fails it too.

Scripts can branch on these. They are stable.

Code Meaning
0 Success.
1 A generic failure. The message says what.
2 The command was used incorrectly.
3 Configuration is wrong or incomplete.
4 Authentication or authorization failed.
5 A provider failed. Often retryable.
6 A policy denied the operation.
7 Verification failed. Masking or an invariant.
8 A test failed. Agent verdicts or load thresholds.
9 Nothing was measured. No workflow reached a verdict, or a workload did not finish.
10 Interrupted, or a teardown left resources recorded. Run af down again.

27 further codes are reserved for features this version does not have. They are in engine/internal/errors/catalog.yaml and are left out here because this page is for looking up an error you have actually seen.

The agent runner could not be started: {detail}

What to do. Run ‘af doctor’ to check that the runner and its browsers are installed.

Exit code 1
Retryable Yes. The engine retries automatically where it can.
More concepts/agents

Workflow {workflow} failed: the application did not do what the workflow expected.

What to do. Read that workflow’s steps and trace for what the page showed instead. A failure is evidence about the application, so fix the application or the expectation rather than the budget.

Exit code 8
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/workflows

The agent runner produced no readable output: {detail}

What to do. This is the runner’s own failure and not the application’s; the output above is what it printed.

Exit code 1
Retryable Yes. The engine retries automatically where it can.
More concepts/agents

The agent runner could not be found: {detail}

What to do. Install it with ‘af runner install’, or point at a checkout with –runner.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/agents

The {provider} key was not accepted: {detail}

What to do. {next_step}

Exit code 4
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/model-keys

The {provider} endpoint could not be reached: {detail}

What to do. {next_step}

Exit code 5
Retryable Yes. The engine retries automatically where it can.
More guides/model-keys

No workflow reached a verdict about the application: {detail}

What to do. Read the workflow rows above for what stopped each one. A run that verified nothing is not a passing run, and ‘policy.workflows_unverified: warn’ records the choice if the project has no workflows yet.

Exit code 9
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/verdicts

Invariant {invariant} did not finish within {timeout}.

What to do. Make the invariant cheaper; it runs after every workflow and must be a quick read.

Exit code 8
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/invariants

Invariant {invariant} is not read only.

What to do. Rewrite it as a single SELECT; invariants run inside a read only transaction.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/invariants

Invariant {invariant} does not hold: {detail}

What to do. The rows the statement returned are the violation. Run it against the branch to see them all.

Exit code 8
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/invariants

There is nothing to explore: {detail}

What to do. Add a goal under explore in the manifest, and set explore.enabled to true.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/exploration

No goal named {goal} is declared under explore.

What to do. Run ‘af explain’ to see the goals this manifest declares, then check the spelling.

Exit code 2
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/exploration

The exploration cannot run as {persona}: the manifest declares {personas}.

What to do. Pass one of the declared persona names to –persona, or add the persona to the manifest and run ‘af up’ so it exists.

Exit code 2
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/exploration

The exploration cannot be steered that way: {detail}

What to do. A start path begins with /, a viewport is phone, tablet, desktop or WIDTHxHEIGHT, and a budget is a step count or a duration such as 5m. ‘af explore –help’ states the sizes.

Exit code 2
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/exploration

Workflow {workflow} was stopped by its budget before it reached a verdict: {detail}

What to do. Raise budget.steps or budget.duration for {workflow} if the flow is genuinely that long, or read its trace to see where it waited or went in circles. A workflow stopped by its budget is blocked, never a pass and never a failure of the change.

Exit code 9
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/workflows

The build for service {service} failed after {duration}.

What to do. Read the build log above; the first error line names the step that failed.

Exit code 1
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/build

The Dockerfile for {service} is not valid at line {line}: {detail}

What to do. Fix the line and run ‘af up’ again.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/build

The build context for {service} is {size}, above the {limit} limit.

What to do. Add large directories to .dockerignore; the build does not need them.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/build

The build context for {service} holds more than {count} files; {path} is where the count was reached.

What to do. Add the generated directories to .dockerignore; a build context should hold source, not output.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/build

The build for service {service} failed after {duration}, and its Dockerfile is {dockerfile} inside a build context rooted at the repository.

What to do. If the Dockerfile expects to be built from its own directory, which is what ‘docker build {dir}’ does, set build.context to {dir} for this service. Otherwise read the build log above; the first error line names the step that failed.

Exit code 1
Retryable No. Retrying the same operation unchanged will fail the same way.
More reference/manifest

The Docker endpoint refused the build request for service {service} before opening a build log: {detail}

What to do. Nothing was built and no build log exists. Correct what the message names, then run ‘af up’ again. If it names a Dockerfile, its path is resolved inside build.context, and .dockerignore can exclude it.

Exit code 1
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/build

The build request for service {service} ended before a build log opened: {detail}

What to do. Nothing was built and no build log exists. If Docker is unreachable, run ‘af doctor’. For a cancellation or temporary Docker failure, run ‘af up’ again.

Exit code 1
Retryable Yes. The engine retries automatically where it can.
More guides/build

No build strategy could be detected for {service}.

What to do. Add a Dockerfile to {path}, or set services.{service}.build to a strategy the reference lists.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/build

The Dockerfile {dockerfile} for {service} is excluded from the build context by .dockerignore.

What to do. Add ‘!{dockerfile}’ to .dockerignore. The file exists, and the build sends a filtered copy of the tree to the daemon, so a path the ignore file excludes is not there to build from.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/build

The Dockerfile {dockerfile} for {service} is outside the build context {context}.

What to do. Widen build.context, or move the Dockerfile inside it. A build cannot read a file the context does not carry.

Exit code 4
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/build

A fault names the target {target}, which this environment does not have: {detail}

What to do. Name a target the environment is running. ‘af status’ lists them, and ‘af chaos list’ lists the ones a fault may reach.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/chaos

The fault kind {kind} cannot be run as written: {detail}

What to do. Correct the fault in the manifest’s chaos block. The reference page lists each kind and the parameters it requires.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/chaos

The fault {fault} could not be injected into {target}: {detail}

What to do. Read what the container said. A fault that could not be injected has measured nothing, so the run reports that rather than a recovery.

Exit code 5
Retryable Yes. The engine retries automatically where it can.
More guides/chaos

The fault {fault} was applied to {target} and changed nothing: {detail}

What to do. A fault that changes nothing makes every recovery check that follows it meaningless, so it is refused rather than reported as survived. Fix the fault, or the environment it is aimed at.

Exit code 7
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/chaos

The fault {fault} is refused because its effect would reach past {target}: {detail}

What to do. A fault may only affect the environment that declared it. For disk_fill that means the data directory needs a filesystem of its own, which database.data_filesystem.size_bytes gives it: declare a size that holds the database with room left to fill, and the fill lands inside the environment instead of on the machine’s disk. Narrow the fault if the refusal was the cap rather than the layout.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/chaos

The database did not come back within {timeout} after the fault {fault}: {detail}

What to do. Read the database’s own log for how far recovery reached. A database that never came back has not passed a recovery check and has not failed one either.

Exit code 7
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/chaos

Faults are not available on the {provider} runtime.

What to do. Run the chaos suite against the local runtime, which is the one whose containers this engine can reach.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/chaos

Recovery after {fault} lost data the client was told was committed: {detail}

What to do. Open the finding for how many acknowledged commits are missing. This is a durability failure in the database or its configuration, not in the rehearsal.

Exit code 7
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/chaos

The chaos suite could not establish what it set out to check after {fault}: {detail}

What to do. An unverified recovery is not a passed one. Read what could not be measured and fix that before trusting the result.

Exit code 6
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/chaos

The control plane could not complete this request.

What to do. Retry once. If it fails again, quote the requestId the response carries: it is the only thing that ties the answer to a log line.

Exit code 5
Retryable Yes. The engine retries automatically where it can.
More self-hosting/control-plane

The control plane refused this request as a possible cross-site request.

What to do. Reload the page so the console fetches a fresh session token, then try again. If it happens again, quote the requestId the response carries: it is the only thing that ties the answer to a log line.

Exit code 4
Retryable No. Retrying the same operation unchanged will fail the same way.
More self-hosting/control-plane

No control plane token is configured.

What to do. Run ‘af login’ then ‘af token create ci’, and set AF_CONTROL_PLANE_TOKEN to what it prints. Everything except this command works without one.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More self-hosting/control-plane

The control plane has no environment called {env}.

What to do. Check the identifier with ‘af env list’, or confirm the engine that created it was sending events to this control plane.

Exit code 4
Retryable No. Retrying the same operation unchanged will fail the same way.
More self-hosting/control-plane

This machine is not signed in to {origin}.

What to do. Run ‘{command}’ to sign in from this terminal. Nothing else in the engine needs a sign in; only the commands that read or write your own account do.

Exit code 4
Retryable No. Retrying the same operation unchanged will fail the same way.
More self-hosting/control-plane

The sign in to {origin} on this machine expired.

What to do. Run ‘{command}’ to sign in again. The expired credential stays stored until a new sign in replaces it, so every command that needs one says this until you do.

Exit code 4
Retryable No. Retrying the same operation unchanged will fail the same way.
More self-hosting/control-plane

{origin} no longer accepts the sign in stored on this machine.

What to do. Run ‘{command}’ to sign in again. The token was revoked, or you were removed from the organization it belonged to; the control plane does not say which.

Exit code 4
Retryable No. Retrying the same operation unchanged will fail the same way.
More self-hosting/control-plane

The sign in to {origin} does not carry the scope this command needs: {detail}

What to do. Run ‘{command}’ and approve the scope in the browser. A sign in without it succeeds and then fails here again, which reads as the fix not working.

Exit code 4
Retryable No. Retrying the same operation unchanged will fail the same way.
More self-hosting/control-plane

The source database at {host} could not be reached.

What to do. Check that the host is reachable from this machine and that the connection string names the right port.

Exit code 5
Retryable Yes. The engine retries automatically where it can.
More providers/databases

The source database is Postgres {found}, and this provider supports {supported}.

What to do. Set database.version to one of {supported} if the source is one of those, or point database.provider at one that handles Postgres {found}. The docker provider builds a golden in the stock postgres image, so it handles every major that image is published for.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More providers/databases

The golden version {version} no longer exists.

What to do. Run ‘af golden list’ to see what exists, or ‘af golden refresh’ to make one. ‘af up’ chooses a version itself.

Exit code 5
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/goldens

The golden version {version} is still referenced by {count} environments and cannot be collected.

What to do. Run ‘af down’ on those environments first, or leave the version in place.

Exit code 6
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/goldens

The provider’s concurrent branch limit ({limit}) is reached.

What to do. Run ‘af down’ on unused environments or raise the limit in the provider settings.

Exit code 5
Retryable No. Retrying the same operation unchanged will fail the same way.
More providers/limits

The source database uses the extension {extension}, and the Postgres the golden is built in does not carry it.

What to do. Set database.image to an image whose Postgres carries {extension}, such as pgvector/pgvector:pg17 or postgis/postgis:17-3.5, and add {extension} to database.extensions so it is created before the copy runs. An extension loaded at server start rather than created in a database, such as timescaledb, citus or pg_cron, also goes in database.preload_libraries. The stock postgres image the docker provider builds from otherwise carries the contrib modules and nothing else, which is why this is the default answer rather than the only one; a hosted provider whose Postgres already has {extension} is the other.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/goldens

The database provider {provider} at {endpoint} rejected the configured credential.

What to do. Check the value of the variable named by database.api_key_env; the provider answered 401, so the credential reached it and was refused rather than being missing.

Exit code 4
Retryable No. Retrying the same operation unchanged will fail the same way.
More providers/databases

The Database Lab Engine at {endpoint} has no snapshot to build a golden from: {detail}

What to do. Wait for the engine’s own data retrieval to finish, then refresh again; its progress is at GET /instance/retrieval.

Exit code 5
Retryable Yes. The engine retries automatically where it can.
More providers/dblab

The subset could not be taken: {detail}

What to do. Run ‘af explain’ to see the effective subset block, and check that the seed table and its predicate name columns this database has.

Exit code 4
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/subsetting

No golden here was made for this project, and {count} were made for something else.

What to do. Run ‘af golden refresh’ to make one from the source this manifest names. A golden is chosen by the project it was made for, the database it was copied from, the masking rules, the subset and the Postgres version, so one belonging to another project on this machine is never branched here.

Exit code 5
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/goldens

The database seed command failed: {detail}

What to do. Run the command yourself against an empty database of the same version. It is: {command}

Exit code 5
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/goldens

No database branch exists for {env}.

What to do. Run ‘af up’ to create one. This is not a missing golden: nothing has been branched for this environment yet.

Exit code 5
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/goldens

The published golden {version} in {store} was made for a different project.

What to do. Name a version this project published with ‘af golden pull ’, or run ‘af golden refresh’ on a machine that can reach the source. A store is shared, so the newest object in it is not necessarily yours.

Exit code 5
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/goldens

database.source_url_env names {variable}, and no configured source has a value for it.

What to do. Put the read only connection string of the database to copy in one of the searched sources: export {variable} in this shell, add it to .env, or run ‘af secret set {variable}’. To build a golden with no production behind it, remove database.source_url_env and set database.seed instead.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/goldens

The role in the connection string cannot read all of the source database: {detail}

What to do. Grant what is listed, in every schema and not only public: ‘GRANT USAGE ON SCHEMA TO ’, ‘GRANT SELECT ON ALL TABLES IN SCHEMA TO ’, and the same for ALL SEQUENCES. Anything listed as row level security needs ‘ALTER ROLE BYPASSRLS’ instead, which no grant provides.

Exit code 4
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/goldens

Row level security stops pg_dump from reading the source as this role: {detail}

What to do. Copy as a role that is exempt, with ‘ALTER ROLE BYPASSRLS’, or as the owner of the tables where row level security is not forced. Postgres refuses rather than filtering because a dump taken under a policy carries only the rows that role can see, and nothing in it would say so.

Exit code 4
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/goldens

{program} stopped while copying the source database: {detail}

What to do. Run {program} yourself against the same connection string to see the whole transcript, or run this command again with -v. The copy only ever reads the source, so nothing in it was changed.

Exit code 5
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/goldens

Personas cannot be provisioned because {provider} creates users only through its own API, and no sandbox tenant is configured.

What to do. Point auth.url or auth.domain at a sandbox, development or staging tenant and set auth.sandbox: true, so that personas are never created in production.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/personas

{provider} rejected the admin token used to create personas.

What to do. Check that the variable named by auth.token_env holds a key for the sandbox tenant with permission to create users.

Exit code 4
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/personas

No table that looks like a users table was found, so there is nowhere to create the personas that sign in.

What to do. Name the table with auth.table if it is there under a name this did not recognise, use auth.adapter: seed to have the personas seeded instead, or give a persona ‘login: none’ if it never signs in, in which case no account is needed.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/personas

The source database answered and refused the connection: {detail}

What to do. Check the value of the variable named by database.source_url_env. The host and port are right, because a server replied, so it is the user, the password or the database name that is not.

Exit code 4
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/goldens

The value of the variable named by database.source_url_env is not a connection string: {detail}

What to do. Give it the URL form, ‘postgres://user:password@host:5432/dbname’, with any character outside A to Z, 0 to 9 and ‘-._~’ in the password percent encoded.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/goldens

Personas cannot be provisioned in {provider} because the admin token it was given is empty.

What to do. Set the variable auth.token_env names to the tenant’s admin token. A hosted persona’s password is derived from that token, so an empty one is refused rather than used as a key.

Exit code 4
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/personas

Migrations failed on the branch: {detail}

What to do. The rehearsal names the statement that failed and times the ones before it. Fix the migration and push again: a migration that fails on a branch with production’s shape is one that would have failed in production.

Exit code 5
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/insights

The migration finding {rule} fails this project’s policy: {detail}

What to do. The report above names the table and the statement. Fix the migration, or lower the rule to ‘warn’ in the manifest’s policy block.

Exit code 8
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/verdicts

The previous release does not survive this migration: {detail}

What to do. A rolling deploy runs both releases at once, so make the change backward compatible: add the new column and write to both, migrate the readers, and drop the old one in a later deploy.

Exit code 8
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/insights

The migrations were not rehearsed, so this run says nothing about them: {detail}

What to do. The report above names what was missing. Fix that, or pass –no-rehearsal to say the run is deliberately without it: a check that could not run must not exit like one that passed.

Exit code 7
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/insights

The Postgres server named by {variable}, at {host}, could not be reached: {detail}

What to do. The pgurl provider keeps goldens and branches on a server you name, which is not your source database. Check that {variable} holds a connection string for a server this machine can reach.

Exit code 5
Retryable Yes. The engine retries automatically where it can.
More providers/pgurl

The role {role} on {host} may not create databases.

What to do. The pgurl provider makes one database per golden and one per environment, so the role named by {variable} needs CREATEDB. Run: ALTER ROLE {role} CREATEDB, as a role that may grant it. A managed Postgres that gives you no such role cannot hold the goldens: keep it as database.source_url_env, which needs read access only, and point {variable} at a Postgres you administer.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More providers/pgurl

The database {database} on {host} was not created by Antifailure and will not be dropped or written to.

What to do. Rename or remove that database yourself if it is disposable, or point the provider at a server that does not already hold one by that name. Nothing here is deleted on the strength of its name.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More providers/pgurl

The role {role} on {host} may not create databases, and {vendor} does not let you grant it.

What to do. On {vendor} the fix AF-DB-035 gives is not available: {reason}. Keep {vendor} as database.source_url_env, which needs read access only, and point {variable} at a Postgres you administer, which is where the goldens and the branches are made. The verdict was read from {citation}.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More providers/managed-postgres

The image {image} declares {volume} as a volume, and the golden’s data directory {datadir} is inside it.

What to do. A golden is the container’s filesystem committed, and anything written under a declared volume is written to an anonymous volume instead, so this image would publish a golden holding no rows and report success. Use an image that does not declare a volume over that path, or rebuild yours without it.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More providers/databases

The image {image} runs Postgres {found} and database.version declares {declared}.

What to do. Set database.version to {found}, or name an image built on {declared}. The two are checked rather than trusted because every branch of this golden would run a Postgres your application does not, and nothing later in the run would notice.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More providers/databases

The extension {extension} named by database.extensions could not be created in the image {image}.

What to do. Name an image that carries {extension} and set database.image to it, or drop {extension} from database.extensions. An extension is files on the server’s disk before it is anything in a database, so no amount of SQL adds one the image does not have: pgvector/pgvector, postgis/postgis and timescale/timescaledb are the published images for the common ones.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More providers/databases

Nothing reached the golden: the verification read 0 tables, and {origin} declares where its contents come from.

What to do. Check what {origin} names: a seed command that exits 0 without writing, or a source database that turns out to be empty, both produce this. Then refresh again. The golden is not published and nothing can branch it, which is the point: a golden that holds nothing and reports itself verified is worse than one that fails, because the word verified is what the next environment relies on. To build a golden with no data behind it deliberately, declare neither database.source_url_env nor database.seed; a project that declares neither gets the schema its migrations build and no rows, and that is supported.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/goldens

database.data_filesystem.size_bytes asks for {declared} bytes and the Docker daemon reports {memory} bytes of memory.

What to do. Lower database.data_filesystem.size_bytes to under half of that, or give the daemon more memory. The filesystem that key asks for is held in memory, which is what stops a disk_fill fault reaching the machine’s disk; one larger than the machine would move the same problem from the disk to the memory, and a daemon killed for memory takes every other environment on it too.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/chaos

The data directory does not fit in the filesystem database.data_filesystem.size_bytes asks for: {used} bytes of data into {declared} bytes.

What to do. Raise database.data_filesystem.size_bytes above the size of the data directory, with room left over for the fault to fill. The copy is refused rather than truncated, because half a data directory is a database that starts and is missing rows.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/chaos

The build {image} could not open the data directory of golden {version}, and the server said: {said}

What to do. Read this as a finding about the two builds rather than as an environment that failed to start: one build wrote that data directory and the other would not open it. READ THE SERVER’S OWN WORDS ABOVE FIRST, because they name the cause and this list does not. A catalog version, a block size, a WAL format or a page layout one build does not accept all produce this, and so does a build that cannot take ownership of the directory, which says so as a permission or access error rather than as a format one. For a format disagreement, compare the two builds’ pg_controldata output, or build the golden on the build you are comparing against by setting database.image to it. For an access error, the build has to be one whose entrypoint can chown the data directory, which the published images do as root before dropping privileges. Nothing was measured, and nothing can be until both builds read the same rows.

Exit code 7
Retryable No. Retrying the same operation unchanged will fail the same way.
More providers/databases

The environment {env} is already running a database branch on {running} and this run asked for {asked}.

What to do. Tear the environment down with ‘af down’ and run the comparison again, or drop the image flag to measure the build it is already on. The branch is not replaced automatically: it is copy on write, so anything written since it was branched would be destroyed to answer a question about measurement, and it is not adopted either, because a run that asked for one build and measured another would report a difference and name the wrong reason for it.

Exit code 7
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/load

No application could be detected in {path}.

What to do. Declare your services by hand in antifailure.yaml; the manifest reference lists the minimum fields.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/detection

Detection could not decide {question}, and there is no default to fall back on.

What to do. Answer it with –answer {id}=, or run ‘af init’ from a terminal so it can ask.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/detection

Detection produced a draft that is not a valid manifest, so nothing was written and {path} does not exist: {detail}

What to do. The detail names the field that was refused and why. Correct that value in the file detection read it from, then run af init again. If nothing in the repository is wrong, this is a defect in Antifailure and worth reporting with the detail above.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/detection

–answer {id}=… does not name anything in this repository.

What to do. Use one of: {known}

Exit code 2
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/detection

The changed files between {base} and {head} could not be read: {detail}

What to do. Fetch the base branch before running ‘af change’. A checkout cloned one commit deep shares no history with it, which is what ‘fetch-depth: 0’ fixes in a GitHub Actions job.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/change-analysis

The diff at {path} could not be read: {detail}

What to do. Produce it with ‘git diff –unified=0 base…head’; this reads git’s own unified format and nothing else.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/change-analysis

The security check {rule} proved a vulnerability against the sanitized twin: {detail}

What to do. Open the finding for the location it was proved at and its fix, then re-run the rehearsal. The offending value is never shown; it lives in the copy of production.

Exit code 7
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/security

The security check {rule} refused this change on policy grounds: {detail}

What to do. Open the finding for what to change. If the change is intended, set its key in the manifest’s policy block. The offending value is never shown.

Exit code 6
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/security

The license covers {seats} seats and they are all in use.

What to do. Remove an inactive member, or ask for more seats at https://antifailure.dev/contact. No existing member was removed.

Exit code 6
Retryable No. Retrying the same operation unchanged will fail the same way.
More enterprise/licensing

Organization policy {policy} refuses this environment: {detail}

What to do. Ask an organization administrator to review {policy}, or bring the repository into compliance.

Exit code 6
Retryable No. Retrying the same operation unchanged will fail the same way.
More enterprise/policy

This manifest declares {count} placement targets and {feature} is not licensed here.

What to do. Reduce runtime.targets to one, or install a license carrying {feature}. Nothing was created, and every setting in the manifest is preserved.

Exit code 4
Retryable No. Retrying the same operation unchanged will fail the same way.
More enterprise/runtimes

The provider {provider} needs the {feature} feature: {reason}

What to do. Install a licence that includes {feature}, or use a provider built into the engine. Nothing was created, and removing what already exists is never refused for this reason.

Exit code 6
Retryable No. Retrying the same operation unchanged will fail the same way.
More enterprise/licensing

This build cannot honor one of its own extension registrations: {detail}

What to do. Fix the registration in the binary that made it. Nothing was created.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More contributing/provider-authoring

The registered {socket} {name} returned nothing and reported no error.

What to do. Fix the registration to return either something usable or an error saying why it could not. Nothing was created.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More contributing/provider-authoring

The environment does not reproduce {dimension}, which the manifest requires: {detail}

What to do. Fix what the inventory names, or remove {dimension} from fidelity.require.

Exit code 6
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/inventory

{dimension} is required and could not be measured, so it is neither met nor broken: {detail}

What to do. Run ‘af fidelity’ to see what could not be measured, and fix that before trusting the requirement.

Exit code 1
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/inventory

Nothing ran, because of the fork policy on the base branch. {detail}

What to do. Add the antifailure:allow label to the pull request, or change github.fork_policy on the base branch.

Exit code 6
Retryable No. Retrying the same operation unchanged will fail the same way.
More getting-started/pull-requests

The github block could not be added to {path}, so the manifest was left as it was: {detail}

What to do. Add ‘github: {mode: actions, comment: true, fork_policy: label}’ to the manifest by hand, then run ‘af explain’ to check it.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More getting-started/pull-requests

The provider rate limited this operation and asked to wait {retry_after}.

What to do. The engine retries automatically. If this persists, lower the concurrency in the manifest.

Exit code 5
Retryable Yes. The engine retries automatically where it can.
More providers/limits

Load could not be generated: {detail}

What to do. Bring the environment up with ‘af up’, and check the load section of the manifest.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/load

Load exceeded {count} thresholds the manifest sets.

What to do. The breaches are listed above, worst first. Raise the threshold or fix the regression.

Exit code 8
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/load

There is no load source called {source}.

What to do. Use otel for an OpenTelemetry trace export, access_log for a combined format log, or none. Both file sources read source_config.path.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/load

The scenario at {path} could not be read: {detail}

What to do. Fix the document, then run ‘af doctor’ to revalidate the manifest.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/load

{count} scenario assertions did not hold.

What to do. Each one is listed above with what it measured. Fix the regression, or change what the scenario asks for.

Exit code 8
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/load

The scenario {scenario} proved nothing: {detail}

What to do. A scenario is blocked when a route it sends is not named in load.safe_routes, and unverified when an assertion names a step that nothing sent. Both are fixed in the manifest or in the scenario document.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/load

The p95_increase threshold proved nothing: {detail}

What to do. The threshold divides a measured p95 by production’s own p95 for that route, and only a trace export carries one. Read the traffic with source: otel, or judge the run on error_rate alone.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/load

The SQL workload could not be run: {detail}

What to do. Bring the environment up with ‘af up’, then check the load.sql section of the manifest and the workload document it names.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/sql-workloads

The SQL workload’s clients could not all connect: {detail}

What to do. Lower load.sql.clients, or raise max_connections on the database. A run at a concurrency nobody chose measures nothing, so this refuses rather than running with fewer.

Exit code 5
Retryable Yes. The engine retries automatically where it can.
More concepts/sql-workloads

The statement statistics could not be read: {detail}

What to do. A derived mix needs pg_stat_statements. Start the database with -c shared_preload_libraries=pg_stat_statements, or declare the workload with load.sql.source set to declared.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/sql-workloads

No statement could be taken from the statistics: {detail}

What to do. Send traffic at the environment first so the branch records what it ran, allow writes with load.sql.writes, or declare the workload instead.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/sql-workloads

The SQL workload proved nothing: {detail}

What to do. A run that committed no transaction has measured neither throughput nor latency. The errors above say why each attempt failed.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/sql-workloads

{count} SQL workload thresholds were breached.

What to do. Each one is listed above with what it measured. Fix the regression, or change what the manifest asks for.

Exit code 8
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/sql-workloads

The base branch comparison exceeded thresholds the manifest sets: {detail}

What to do. Read the per route table in the report: it names the base branch p95 and this build’s beside each other. Raise the limit under load.comparison.thresholds if the change is deliberate, and remember a difference between two sequential runs on one host is not a controlled experiment.

Exit code 8
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/load

The base branch comparison judged nothing: {detail}

What to do. Every declared threshold went unmeasured, which is not a clean comparison. Check that both sides sent the same routes: a route served on one side only has no counterpart to be compared against, and a run that sent nothing has none at all.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/load

No antifailure.yaml was found in {path} or any parent directory.

What to do. Run ‘af init’ in the repository root to create one.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More reference/manifest

The manifest at {path} is not valid: {detail}

What to do. Fix the reported line, then run ‘af doctor’ to revalidate.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More reference/manifest

The manifest at {path} declares schema version {found}, which this build does not understand.

What to do. Check the build you are running with ‘af version’ and install the release that supports version {found}.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More reference/manifest

The manifest at {path} is larger than the {limit} limit.

What to do. Split the configuration or remove generated content; a manifest describes services, it does not contain them.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More reference/manifest

A manifest already exists at {path}, and af init does not merge into one.

What to do. Edit the file to change it, or run ‘af init –force’ to replace it with a fresh detection. –force discards every edit in the file, so read it first.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More reference/manifest

The golden {version} has no valid verification attestation and cannot be branched.

What to do. Run ‘af golden verify {version}’; a golden is branchable only once verification has passed.

Exit code 7
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/verification

Verification found data matching {detector} in {table}.{column}.

What to do. Add a masking rule for {table}.{column} and refresh the golden. The value itself is never printed.

Exit code 7
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/verification

Masking could not run: {detail}

What to do. The detail names what stopped it, column by column wherever masking had a schema to read, and each of those problems carries its own remedy: give the column a rule that preserves it, or change the table so masking can address a row in it. ‘af mask plan’ prints the same decisions for every column at once, and it reads the schema of a branch, so it has one to read only once ‘af up’ has made it.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/masking

Verification could not read {table}.{column}, so the golden was not verified: {detail}

What to do. Grant the scanner read access to {table}.{column} and refresh the golden. A column the scan could not read is not a column that passed.

Exit code 7
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/verification

There is already a masking file at {path}, and ‘af mask init’ would overwrite the rules in it.

What to do. Edit the file, or pass –force to replace it with rules written from the schema.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/masking

Verification could not read {table}.{column} ({type}), no masking rule covers it, and its name says it holds a secret.

What to do. Give {table}.{column} a rule in masking.yaml, nullify or hash_hex, and refresh the golden. A column the scan cannot read is masked by the rules or by nothing.

Exit code 7
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/verification

The same identifier does not mask to the same value in every store: {detail}

What to do. Give the two columns one rule, or one link, so both sides derive their subkey from the same identity. Until they do, a join across the two stores returns the wrong person and every report built on it is plausible.

Exit code 7
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/masking

The cross store check did not compare every store it was given: {detail}

What to do. Give each datastore a source_url_env naming the variable that holds its connection string, export those variables, and make every store reachable from here. A store that was not compared is not a store that agreed.

Exit code 1
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/masking

Masking was interrupted before it finished: {detail}

What to do. Run it again against a fresh copy: ‘af golden refresh’ starts again from the source, and a branch that was partly masked has to be recreated with ‘af down’ and then ‘af up’ first, because masking a value that is already masked changes it.

Exit code 9
Retryable Yes. The engine retries automatically where it can.
More concepts/masking

The request to {host} was blocked by rule {rule}.

What to do. Add an egress rule for {host} with the mode you intend, or leave it blocked.

Exit code 6
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/egress

{request} is not a request that can be explained: {detail}

What to do. Pass a method and a URL, as in ‘af net explain GET https://api.stripe.com/v1/charges’.

Exit code 2
Retryable No. Retrying the same operation unchanged will fail the same way.
More reference/cli#af-net-explain

No mock matched {method} {path} on {host}.

What to do. A fixture skeleton was written to {suggestion}. Fill it in and run again.

Exit code 6
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/mocking

No message matching {match} arrived within {timeout}.

What to do. Check ‘af net log’ to see whether the request was refused, and ‘af inbox list’ for what did arrive.

Exit code 8
Retryable Yes. The engine retries automatically where it can.
More guides/inbox

The webhook could not be delivered to {service}: {detail}

What to do. Run ‘af status’ to check the service is up, and check the path against the manifest’s webhook_path.

Exit code 1
Retryable Yes. The engine retries automatically where it can.
More guides/webhooks

The environment tried to reach {hosts}, which nothing in the manifest mentions.

What to do. Add an egress rule for it with the mode you intend, or set policy.egress_surprise to ‘warn’ to let the attempt through the check.

Exit code 6
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/verdicts

The manifest declares no oracle block, so there is nothing to compare.

What to do. Add an oracle block with at least one probe; the manifest reference has the shape.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/oracle

The oracle is on and declares no requests to send.

What to do. Add at least one entry under oracle.probes. Both versions have to receive the same requests in the same order, so the plan is written down rather than discovered.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/oracle

The baseline revision could not be resolved: {detail}

What to do. Set the base_ref of whichever block asked for the comparison, oracle.base_ref or load.comparison.base_ref, to a branch, tag, or commit this checkout can see, and fetch it if it is a remote ref. The flag that overrides either is –baseline.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/oracle

The baseline and the candidate are both {commit}, so there is nothing to compare.

What to do. Commit the change, or point oracle.base_ref at the revision you meant to compare against.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/oracle

The baseline revision {commit} could not be checked out: {detail}

What to do. Check that the commit is present in this clone; a shallow clone often is not deep enough to reach it.

Exit code 5
Retryable Yes. The engine retries automatically where it can.
More concepts/oracle

There is no web service to send requests to in the {side} environment.

What to do. Declare a service of kind web in the manifest; the oracle compares HTTP responses and needs somewhere to send them.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/oracle

The baseline environment did not come up: {detail}

What to do. Bring the baseline revision up on its own with ‘af up’ from a checkout of it to see the build or migration failure in full.

Exit code 5
Retryable Yes. The engine retries automatically where it can.
More concepts/oracle

The {side} branch could not be read for comparison: {detail}

What to do. Check the branch is reachable, or turn the contents comparison off with oracle.database.enabled: false to compare responses alone.

Exit code 5
Retryable Yes. The engine retries automatically where it can.
More concepts/oracle

The golden version {version} the comparison pinned is no longer present or no longer verified.

What to do. Run the comparison again; both sides branch one golden and the one the candidate used has gone.

Exit code 5
Retryable Yes. The engine retries automatically where it can.
More concepts/oracle

The candidate behaves differently from the baseline: {detail}

What to do. Read the differences above. Each one is either the change you meant to make or a regression; raise oracle.fail_on if this class of difference is expected.

Exit code 8
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/oracle

Your replay evidence could not be prepared: {detail}

What to do. Inspect the incident, supply the named prerequisite, and retry. No replay verdict was reached.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/agent-replay

Your replay is inconclusive: {detail}

What to do. Inspect the replay report and recover any pending environments before retrying.

Exit code 7
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/agent-replay

Your candidate did not satisfy the saved outcome assertion.

What to do. Inspect the candidate outcome, fix the agent, and run the same scenario again.

Exit code 8
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/agent-replay

The command ‘{command}’ is not available in this version.

What to do. Run ‘af –help’ for the commands this binary carries and ‘af version’ for which build it is. ‘af update’ replaces it in place with the newest release, which may carry more.

Exit code 2
Retryable No. Retrying the same operation unchanged will fail the same way.
More reference/cli

The Docker daemon at {endpoint} could not be reached.

What to do. Start Docker and run ‘af doctor’ to confirm; on macOS that is Docker Desktop.

Exit code 5
Retryable Yes. The engine retries automatically where it can.
More guides/local-runtime

Another Antifailure process holds the lock for this branch (process {pid}, since {since}).

What to do. Wait for it to finish, or stop it and run ‘af down’ to clean up.

Exit code 1
Retryable Yes. The engine retries automatically where it can.
More concepts/journal

Service {service} did not become ready within {timeout}.

What to do. The last log lines are above. Check the health path {health} and the port the service binds.

Exit code 1
Retryable Yes. The engine retries automatically where it can.
More guides/local-runtime

Service {service} exited with code {code} during startup.

What to do. The last log lines are above. Run ‘af logs {service}’ for the full output.

Exit code 1
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/local-runtime

No free port was found in the range {range} to publish the environment on.

What to do. Free a port in that range, or set AF_PORT_RANGE_START to the first port of a range that is clear.

Exit code 1
Retryable Yes. The engine retries automatically where it can.
More guides/local-runtime

Writing to {path} failed because the disk is full; {needed} is required.

What to do. Free space on the volume holding {path}, then run the command again.

Exit code 1
Retryable Yes. The engine retries automatically where it can.
More guides/local-runtime

Docker has no room left for the environment: {detail}

What to do. Run ‘docker system prune’ or raise the disk limit in Docker’s settings.

Exit code 5
Retryable Yes. The engine retries automatically where it can.
More guides/local-runtime

The environment could not be torn down completely; {count} resources are still recorded.

What to do. Run ‘af down’ again once the provider is reachable; the journal remembers what is left.

Exit code 10
Retryable Yes. The engine retries automatically where it can.
More concepts/journal

The environment could not be placed: {detail}

What to do. Run ‘af doctor’ to check the runtime, then ‘af down’ to clear anything left behind.

Exit code 1
Retryable Yes. The engine retries automatically where it can.
More guides/local-runtime

The services depend on each other in a cycle: {cycle}

What to do. Remove one of the depends_on entries; a cycle has no order that can start.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More reference/manifest

Service {service} depends on {missing}, which the manifest does not declare.

What to do. Add a service called {missing}, or correct the depends_on entry.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More reference/manifest

This cluster is not containing the environment: {detail}

What to do. Use a cluster whose CNI enforces NetworkPolicy rather than only accepting it, then run ‘af up’ again.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/kubernetes-runtime

This runtime cannot do that: {detail}

What to do. Use the runtime that supports it, or run the command against an environment placed by one that does.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/kubernetes-runtime

{kind} {name} was not created by this runtime, so it was not removed.

What to do. Remove it yourself if you meant to, or use an environment id this runtime placed. ‘af env list’ shows the ones it owns.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/kubernetes-runtime

AF_PORT_RANGE_START is set to {value}, which is not a port number.

What to do. Set it to the first port of a free range, between {limit}, or unset it to use the default.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/local-runtime

This runtime cannot place the sizes the manifest asks for: {detail}

What to do. Lower resources.cpu or resources.memory on the services named, run fewer environments on this machine, or place it somewhere with room.

Exit code 1
Retryable Yes. The engine retries automatically where it can.
More reference/manifest

The egress sidecar image could not be obtained: {detail}

What to do. A release publishes this image, so an official build fetches it in seconds. Set AF_PROXY_IMAGE_TIMEOUT higher if this machine is slow, or name an image you host in AF_PROXY_IMAGE so nothing is compiled here.

Exit code 1
Retryable Yes. The engine retries automatically where it can.
More guides/local-runtime

The {emulator} emulator started but never accepted a connection at {address} within {timeout}, so the environment was torn down: {detail}

What to do. Nothing is listening inside that container yet. Run the image by hand and watch how long it takes to bind {address}, then raise AF_EMULATOR_READY_TIMEOUT if it needs longer than the default. A container that exits instead of binding is a wrong command or a missing companion.

Exit code 1
Retryable Yes. The engine retries automatically where it can.
More guides/local-runtime

The manifest declares no service called {service}, so there is no output by that name to show. The services it declares are {declared}.

What to do. Name one of those, or run ‘af logs’ with no name to read every service.

Exit code 2
Retryable No. Retrying the same operation unchanged will fail the same way.
More reference/manifest

{service} is {what}, not a service, so it writes no output that ‘af logs’ can show.

What to do. What the services saw of it, a refused connection or a failed migration, is in their own output. Run ‘af logs’ with no name to read every service: {declared}.

Exit code 2
Retryable No. Retrying the same operation unchanged will fail the same way.
More reference/manifest

The environment’s network could not be created, because Docker has no address range left to give it: {detail}

What to do. Run ‘af env prune –orphaned’ to list the Antifailure environments nothing is attached to, and ‘af env prune –orphaned –yes’ to remove exactly those. ‘af doctor’ counts them too. Networks another tool made are never touched: if the daemon is full of those, ‘docker network ls’ names them, and widening default-address-pools in Docker’s daemon settings makes room for more.

Exit code 1
Retryable Yes. The engine retries automatically where it can.
More guides/local-runtime

No runtime satisfies the placement requirement {requirement}.

What to do. Declare a target under runtime.targets carrying that tag, or relax runtime.requires. Nothing was created.

Exit code 5
Retryable No. Retrying the same operation unchanged will fail the same way.
More enterprise/runtimes

No placement target could take this environment: {detail}

What to do. The detail says which targets were tried and why each was refused. Fix the one you expect to work, or add a target that can take it. Nothing was created.

Exit code 5
Retryable Yes. The engine retries automatically where it can.
More enterprise/runtimes

The variables {names} are declared in the manifest but were not found in any configured source.

What to do. Add them to one of the searched sources: {sources}.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/secrets

The credential for {source} was rejected after one refresh: {detail}

What to do. Rotate the credential and store the new value where {source} reads it. A rejection that survives a refresh is a credential that was revoked or was never right, so retrying will not help.

Exit code 4
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/secrets

The value supplied for {name} carries a live credential prefix, and {name} is configured for sandbox use.

What to do. Point {name} at a sandbox credential; the environment must never hold a live key.

Exit code 6
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/secrets

The encrypted local store has no passphrase: no system keyring answered and AF_SECRET_PASSPHRASE is not set.

What to do. Set AF_SECRET_PASSPHRASE, or store the passphrase in the system keyring on a platform that has one. There is deliberately no default: a store encrypted with a passphrase everybody knows only looks encrypted.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/secrets

The variable {name} could not be looked up: {detail}

What to do. Fix the source named in the message, or export {name} in this shell, which is the first source the chain reads and beats the one that failed.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/secrets

The credential stored in {location} is not in this tool’s format: {detail}

What to do. Sign in again with ‘af login’, which replaces it. Nothing but ‘af login’ writes there, so if another tool or a hand edit did, move that aside first.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/signing-in

The sandbox credential {name} is declared by {services} with a scope or from more than one place, so it would need more than one value, and the egress proxy holds one value per credential for the whole environment.

What to do. Give every service that declares {name} the same source and no scope. The proxy substitutes the credential into every request to that provider whichever service sent it, so a value that belongs to one service cannot be kept to that service.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More guides/secrets

The environment certificate could not be created: {detail}

What to do. Run ‘af doctor’ to check the runtime, then bring the environment up again.

Exit code 1
Retryable Yes. The engine retries automatically where it can.
More concepts/egress

There is no workload kind called {kind}.

What to do. Use one of {known}, spelled the way the control plane spells it.

Exit code 2
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/workloads

The {kind} kind cannot set {knobs}.

What to do. Remove it from the workload version. The command that kind runs has no flag for it, so honouring it would be a promise the run cannot keep.

Exit code 2
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/workloads

The {knob} value {value} is not what this workload’s command takes: {detail}

What to do. Correct the value in the workload version, then run it again.

Exit code 2
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/workloads

The {kind} kind must name what it runs: {detail}

What to do. List the scenarios or goals the workload selects, by the names the manifest declares.

Exit code 2
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/workloads

The exploration {exploration} cannot be promoted: {detail}

What to do. Promote an exploration that reached its goal. One that was blocked has no journey to compile.

Exit code 3
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/workloads

These two workload results cannot be compared: {detail}

What to do. Compare two runs of the same workload kind. A mix and a browser workflow measure different things and a difference between them would be arithmetic on unlike numbers.

Exit code 2
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/workloads

The workload found a failure: {detail}

What to do. The result document above names what failed. Reproduce it with the command it carries.

Exit code 8
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/workloads

The workload proved nothing: {detail}

What to do. A run that measured nothing is not a run that found nothing. The result says which routes were refused or which selection matched no declared name.

Exit code 7
Retryable No. Retrying the same operation unchanged will fail the same way.
More concepts/workloads

The workload did not finish: {detail}

What to do. The environment was torn down where the run asked for it. Run it again, or raise the deadline.

Exit code 9
Retryable Yes. The engine retries automatically where it can.
More concepts/workloads