{"record":{"id":"0919cc1972392b7a","repo":"hashicorp/terraform","slug":"invalid-url-v-must-be-v","errorCode":null,"errorMessage":"Invalid URL: %v must be: %v","messagePattern":"Invalid URL: (.+?) must be: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/cos/backend.go","lineNumber":309,"sourceCode":"\t\tu, err = url.Parse(fmt.Sprintf(\"https://%s.cos.%s.myqcloud.com\", b.bucket, b.region))\n\t}\n\tif err != nil {\n\t\treturn err\n\t}\n\n\tif v, ok := data.GetOk(\"domain\"); ok {\n\t\tb.domain = v.(string)\n\t\tlog.Printf(\"[DEBUG] Backend: set domain for TencentCloud API client. Domain: [%s]\", b.domain)\n\t}\n\t// set url as endpoint when provided\n\t// \"http://{Bucket}.cos-internal.{Region}.tencentcos.cn\"\n\tif v, ok := data.GetOk(\"endpoint\"); ok {\n\t\tendpoint := v.(string)\n\n\t\tre := regexp.MustCompile(`^(http(s)?)://cos-internal\\.([^.]+)\\.tencentcos\\.cn$`)\n\t\tmatches := re.FindStringSubmatch(endpoint)\n\t\tif len(matches) != 4 {\n\t\t\treturn fmt.Errorf(\"Invalid URL: %v must be: %v\", endpoint, \"http(s)://cos-internal.{Region}.tencentcos.cn\")\n\t\t}\n\n\t\tprotocol := matches[1]\n\t\tregion := matches[3]\n\n\t\t// URL after converting\n\t\tnewUrl := fmt.Sprintf(\"%s://%s.cos-internal.%s.tencentcos.cn\", protocol, b.bucket, region)\n\t\tu, err = url.Parse(newUrl)\n\t\tlog.Printf(\"[DEBUG] Backend: set COS URL as: [%s]\", newUrl)\n\t}\n\tif err != nil {\n\t\treturn err\n\t}\n\n\tvar getProviderConfig = func(key string) string {\n\t\tvar str string\n\t\tvalue, err := getConfigFromProfile(data, key)\n\t\tif err == nil && value != nil {","sourceCodeStart":291,"sourceCodeEnd":327,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/cos/backend.go#L291-L327","documentation":"When the optional COS backend 'endpoint' attribute is set, configure() validates it against the strict regex ^(http(s)?)://cos-internal\\.([^.]+)\\.tencentcos\\.cn$ (4 capture groups). Any non-matching endpoint is rejected. The endpoint is intended only for TencentCloud internal (VPC) access; public access is built from region+bucket.","triggerScenarios":"terraform init with endpoint set to a value that does not match http(s)://cos-internal.{Region}.tencentcos.cn.","commonSituations":"User supplies the public COS endpoint in endpoint (e.g. https://bucket.cos.ap-beijing.myqcloud.com); uses a custom CDN domain; forgets the cos-internal subdomain; uses http://cos.example.com.","solutions":["Use the internal form: http://cos-internal.ap-beijing.tencentcos.cn or https://cos-internal.ap-beijing.tencentcos.cn.","If you want the public endpoint, omit endpoint entirely and rely on region+bucket+accelerate."],"exampleFix":"// before\nterraform {\n  backend \"cos\" {\n    endpoint = \"https://bucket.cos.ap-beijing.myqcloud.com\"\n  }\n}\n\n// after\nterraform {\n  backend \"cos\" {\n    region   = \"ap-beijing\"\n    bucket   = \"bucket\"\n    # endpoint omitted; or for VPC-internal access:\n    # endpoint = \"https://cos-internal.ap-beijing.tencentcos.cn\"\n  }\n}","handlingStrategy":"validation","validationCode":"// Validate the COS endpoint matches the strict internal form.\nvar cosInternalRe = regexp.MustCompile(`^(http(s)?)://cos-internal\\.([^.]+)\\.tencentcos\\.cn$`)\n\nfunc validateCOSEndpoint(endpoint string) error {\n    if endpoint == \"\" {\n        return nil // endpoint is optional\n    }\n    if len(cosInternalRe.FindStringSubmatch(endpoint)) != 4 {\n        return fmt.Errorf(\"Invalid URL: %s must be: %s\", endpoint, \"http(s)://cos-internal.{Region}.tencentcos.cn\")\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Leave endpoint unset for public COS access; the backend builds the URL from region+bucket.","Use endpoint only for VPC-internal access, in the form http(s)://cos-internal.{Region}.tencentcos.cn.","Don't put a bucket name or custom domain in endpoint.","Lint backend blocks in CI against the regex."],"tags":["cos","tencent-cloud","config-validation","endpoint","backend"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}