{"record":{"id":"0afa54a4dc98eb55","repo":"hashicorp/terraform","slug":"the-host-q-block-has-an-invalid-hostname-s","errorCode":null,"errorMessage":"The host %q block has an invalid hostname: %s","messagePattern":"The host %q block has an invalid hostname: (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/command/cliconfig/cliconfig.go","lineNumber":298,"sourceCode":"// method. A non-nil diagnostics is not necessarily an error, since it may\n// contain just warnings.\nfunc (c *Config) Validate() tfdiags.Diagnostics {\n\tvar diags tfdiags.Diagnostics\n\n\tif c == nil {\n\t\treturn diags\n\t}\n\n\t// FIXME: Right now our config parsing doesn't retain enough information\n\t// to give proper source references to any errors. We should improve\n\t// on this when we change the CLI config parser to use HCL2.\n\n\t// Check that all \"host\" blocks have valid hostnames.\n\tfor givenHost := range c.Hosts {\n\t\t_, err := svchost.ForComparison(givenHost)\n\t\tif err != nil {\n\t\t\tdiags = diags.Append(\n\t\t\t\tfmt.Errorf(\"The host %q block has an invalid hostname: %s\", givenHost, err),\n\t\t\t)\n\t\t}\n\t}\n\n\t// Check that all \"credentials\" blocks have valid hostnames.\n\tfor givenHost := range c.Credentials {\n\t\t_, err := svchost.ForComparison(givenHost)\n\t\tif err != nil {\n\t\t\tdiags = diags.Append(\n\t\t\t\tfmt.Errorf(\"The credentials %q block has an invalid hostname: %s\", givenHost, err),\n\t\t\t)\n\t\t}\n\t}\n\n\t// Should have zero or one \"credentials_helper\" blocks\n\tif len(c.CredentialsHelpers) > 1 {\n\t\tdiags = diags.Append(\n\t\t\tfmt.Errorf(\"No more than one credentials_helper block may be specified\"),","sourceCodeStart":280,"sourceCodeEnd":316,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/command/cliconfig/cliconfig.go#L280-L316","documentation":"Thrown during CLI config validation when a host block contains a hostname that fails svchost.ForComparison normalization. Hostnames must be valid, normalizable DNS names for Terraform to use them for service discovery and credential matching. The error includes the offending hostname and the underlying validation error.","triggerScenarios":"For each key in c.Hosts, svchost.ForComparison(givenHost) returns an error. This happens when the hostname contains invalid characters (underscores, spaces), has an invalid format (trailing dots, empty labels), or is empty.","commonSituations":"Typo in hostname (e.g., app.terraform..io with double dots); using underscores which DNS forbids; hostname from a variable that resolved incorrectly; copy-paste with trailing whitespace or invisible characters.","solutions":["Correct the hostname to be a valid DNS name (letters, digits, hyphens, and dots only)","Remove underscores, trailing dots, spaces, or special characters","Verify the hostname resolves: nslookup <hostname> or dig <hostname>","Check for invisible/whitespace characters in the config file"],"exampleFix":"// before\nhost \"app_terraform_io\" {\n  services = {}\n}\n\n// after\nhost \"app.terraform.io\" {\n  services = {}\n}","handlingStrategy":"validation","validationCode":"// Validate hostname before using in a host block\nfunc validateHostname(h string) error {\n    _, err := svchost.ForComparison(h)\n    return err\n}\n\n// Simple DNS-safe check without the svchost dependency\nfunc isValidHostname(h string) bool {\n    if h == \"\" || len(h) > 253 {\n        return false\n    }\n    matched, _ := regexp.MatchString(`^[a-zA-Z0-9]([a-zA-Z0-9.-]*[a-zA-Z0-9])?$`, h)\n    return matched && !strings.Contains(h, \"_\")\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Use only valid DNS hostnames (alphanumeric, hyphens, dots) in host blocks","Avoid underscores and special characters in hostnames","Verify hostnames resolve via DNS before adding to config","Trim whitespace from hostnames before writing to config files"],"tags":["cli-config","hostname","validation","dns","host-block"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}