{
  "meta": {
    "version": "v1",
    "pricing": {
      "public": {
        "label": "Public",
        "description": "Read-only API access for lightweight status checks and public integrations."
      },
      "premium": {
        "label": "Premium",
        "description": "API keys with higher hourly quotas, plus Slack, Discord, webhook, and email outage alerts across your vendor stack."
      }
    },
    "generatedAt": "2026-07-24T11:08:02.105Z"
  },
  "data": {
    "id": "incident_statuspage_harness_5dmkszpp3xq6",
    "slug": "harness-iacm-infrastructure-pipelines-using-terraform-are-currently-2026-04-19-szpp3xq6",
    "title": "IACM infrastructure pipelines using terraform are currently experiencing an outage",
    "summary": "IACM infrastructure pipelines using terraform are currently experiencing an outage",
    "status": "resolved",
    "severity": "major",
    "startedAt": "2026-04-19T14:09:18.55+00:00",
    "updatedAt": "2026-04-30T19:06:44.827+00:00",
    "resolvedAt": "2026-04-19T15:24:54.393+00:00",
    "provider": {
      "slug": "harness",
      "name": "Harness"
    },
    "affectedServices": [],
    "links": {
      "html": "/incidents/harness-iacm-infrastructure-pipelines-using-terraform-are-currently-2026-04-19-szpp3xq6",
      "api": "/api/v1/incidents/harness-iacm-infrastructure-pipelines-using-terraform-are-currently-2026-04-19-szpp3xq6",
      "providerHtml": "/providers/harness"
    },
    "impactSummary": "Harness reported a major event for the affected tracked services.",
    "source": {
      "id": "source_harness_status",
      "kind": "official_api",
      "name": "Harness Status",
      "checkedAt": "2026-07-24T11:00:50.68+00:00",
      "officialUrl": "https://status.harness.io",
      "statusPageUrl": "https://status.harness.io"
    },
    "updates": [
      {
        "id": "update_statuspage_harness_5dmkszpp3xq6_7p33g2k3f406",
        "status": "investigating",
        "body": "We are currently investigating this issue.",
        "createdAt": "2026-04-19T14:09:18.737+00:00"
      },
      {
        "id": "update_statuspage_harness_5dmkszpp3xq6_b4pqnk7xvwfx",
        "status": "identified",
        "body": "The issue has been identified and a fix is being implemented.",
        "createdAt": "2026-04-19T14:20:07.46+00:00"
      },
      {
        "id": "update_statuspage_harness_5dmkszpp3xq6_q9gbzy1fvjpl",
        "status": "monitoring",
        "body": "A fix has been implemented and we are monitoring the results.",
        "createdAt": "2026-04-19T15:17:21.899+00:00"
      },
      {
        "id": "update_statuspage_harness_5dmkszpp3xq6_qld34cd5j6zn",
        "status": "resolved",
        "body": "This incident has been resolved.\n\nCustomers using a pinned version older than plugins/harness_terraform:0.214.0 should update to the latest version by following the                                                                      \nhttps://developer.harness.io/docs/continuous-integration/use-ci/set-up-build-infrastructure/harness-ci/#specify-the-harness-ci-images-used-in-your-pipelines. \n\nIf you are not pinning a specific version, no action is required — your pipelines are already using the updated image.",
        "createdAt": "2026-04-19T15:24:54.393+00:00"
      },
      {
        "id": "update_statuspage_harness_5dmkszpp3xq6_vnyp7dpn5fmp",
        "status": "resolved",
        "body": "## **Summary**\n\nOn April 19, 2026, Terraform-based IaCM pipelines failed across production environments due to an issue with Terraform binary verification during runtime.\n\nThe issue was caused by an expired OpenPGP signing key in a third-party library used to validate Terraform downloads. This resulted in failures when pipelines attempted to install Terraform dynamically.\n\n## **Impact**\n\n* Terraform-based IaCM pipelines failed during execution\n* Failures occurred at runtime when attempting to download/verify Terraform binaries\n*  **Customers Unaffected:** \n\n    * OpenTofu-based pipelines\n    * Pipelines using pre-installed or cached Terraform binaries\n    \n\nCustomers pinning plugin versions older than the fixed release continued to experience failures until upgraded.\n\n## **Root Cause**\n\nThe IaCM Terraform plugin relies on a third-party library \\(HashiCorp’s `hc-install`\\) to download and verify Terraform binaries.\n\n* The library contained a **hardcoded OpenPGP signing key**\n* This key **expired**, causing verification failures during Terraform installation\n* HashiCorp had not yet released an updated version with a renewed key\n\n## **Remediation**\n\n### **Immediate Mitigation**\n\n* Released **IaCM Terraform plugin v0.214.0**\n* Modified behavior to:\n\n    * **Bypass the expired signature verification step**\n    * Continue secure downloads over HTTPS\n    \n\n### **Resolution**\n\n* Rolled out the fix across **prod0–prod4**\n* Pipeline execution functionality was restored\n\n## **Customer Actions Required**\n\n* Customers using pinned plugin versions **older than v0.214.0** must:\n\n    * **Upgrade to v0.214.0 or later**\n    \n* No action required for customers using default/latest plugin versions\n\n## **Prevention & Next Steps**\n\nWe are implementing the following improvements:\n\n* **Dependency Monitoring**\n\n    * Proactive monitoring for third-party certificate/key expirations\n    \n* **Upstream Coordination**\n\n    * Track HashiCorp release for updated signing key\n    * Re-enable signature verification once available\n    \n* **Customer Communication**\n\n    * Notify customers using older pinned versions\n    \n* **Operational Improvements**\n\n    * Enhance validation of external dependencies in runtime workflows",
        "createdAt": "2026-04-30T19:04:06.711+00:00"
      }
    ],
    "access": {
      "plan": "public",
      "keyed": false
    }
  }
}