{"record":{"id":"2279bcc6a9c26d0a","repo":"hashicorp/terraform","slug":"connection-error-statuscode-d","errorCode":null,"errorMessage":"Connection Error: StatusCode: %d","messagePattern":"Connection Error: StatusCode: (.+?)","errorType":"http","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/communicator/ssh/http_proxy.go","lineNumber":111,"sourceCode":"\t// Writes the request in the form expected by an HTTP proxy.\n\terr = req.Write(c)\n\tif err != nil {\n\t\tc.Close()\n\t\treturn nil, err\n\t}\n\n\tres, err := http.ReadResponse(bufio.NewReader(c), req)\n\n\tif err != nil {\n\t\tc.Close()\n\t\treturn nil, err\n\t}\n\n\tres.Body.Close()\n\n\tif res.StatusCode != http.StatusOK {\n\t\tc.Close()\n\t\treturn nil, fmt.Errorf(\"Connection Error: StatusCode: %d\", res.StatusCode)\n\t}\n\n\treturn c, nil\n}\n\n// NewHttpProxyDialer generate Http Proxy Dialer\nfunc newHttpProxyDialer(u *url.URL, forward proxy.Dialer) (proxy.Dialer, error) {\n\tvar proxyUserName, proxyPassword string\n\tif u.User != nil {\n\t\tproxyUserName = u.User.Username()\n\t\tproxyPassword, _ = u.User.Password()\n\t}\n\n\tpd := &proxyDialer{\n\t\tproxy:   *newProxyInfo(u.Host, u.Scheme, proxyUserName, proxyPassword),\n\t\tforward: forward,\n\t}\n","sourceCodeStart":93,"sourceCodeEnd":129,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/communicator/ssh/http_proxy.go#L93-L129","documentation":"Returned by the HTTP-proxy CONNECT helper when the proxy responded with a status code other than 200 OK. The proxy connection is closed and the numeric status is returned. This is the proxy's response to the CONNECT request, surfaced before any SSH traffic — i.e. the proxy refused to tunnel to the requested host:port.","triggerScenarios":"Proxy returns 407 (auth required / bad creds), 403 (forbidden / policy), 502/503 (proxy can't reach upstream), or 405 (CONNECT not allowed on this endpoint). Triggered only when proxy_url is set and the proxy is reachable.","commonSituations":"407 Proxy Authentication Required with missing/wrong proxy_url credentials; 403 because the destination is not on the proxy's allowlist; 502 when the proxy cannot resolve/reach the bastion; corporate Zabbix/Squid policies blocking CONNECT to non-standard ports.","solutions":["Map the status code: 407 -> add proxy credentials; 403 -> allowlist the destination; 502/503 -> fix proxy-to-bastion reachability.","Provide credentials in proxy_url: \"http://user:pass@proxy:3128\".","Ask the proxy admin to allow CONNECT to bastion_host:bastion_port.","Verify the bastion host/port are resolvable and reachable from the proxy itself."],"exampleFix":"// before\nconnection {\n  host         = \"10.0.0.5\"\n  bastion_host = \"bastion.example.com\"\n  proxy_url    = \"http://proxy.corp:3128\"   // returns 407\n}\n\n// after\nconnection {\n  host         = \"10.0.0.5\"\n  bastion_host = \"bastion.example.com\"\n  proxy_url    = \"http://svc:secret@proxy.corp:3128\"\n}","handlingStrategy":"try-catch","validationCode":"# Decode the status code from the message and act:\n#   407 -> proxy auth; 403 -> policy/allowlist; 502/503 -> upstream reachability.\n# Test CONNECT manually:\n#   curl -v -x http://<proxy> --proxytunnel https://<bastion>:<port>","typeGuard":null,"tryCatchPattern":"// In Go, parse the status code from the message to drive behavior:\nif strings.Contains(err.Error(), \"Connection Error: StatusCode:\") {\n    code := parseStatusCode(err.Error()) // extract the %d\n    switch code {\n    case 407: return fmt.Errorf(\"proxy auth required; add creds to proxy_url: %w\", err)\n    case 403: return fmt.Errorf(\"proxy denied CONNECT; allowlist destination: %w\", err)\n    default:  return fmt.Errorf(\"proxy CONNECT failed with %d: %w\", code, err)\n    }\n}","preventionTips":["Embed proxy credentials in proxy_url when the proxy requires auth.","Ask proxy admins to allowlist CONNECT to bastion_host:bastion_port.","Confirm the proxy can resolve and reach the bastion upstream."],"tags":["terraform","ssh","http-proxy","proxy","connect","authentication","provisioner"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}