{"record":{"id":"2c9fcf4f37495d95","repo":"hashicorp/terraform","slug":"connection-type-s-not-supported","errorCode":null,"errorMessage":"connection type '%s' not supported","messagePattern":"connection type '(.+?)' not supported","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/communicator/communicator.go","lineNumber":70,"sourceCode":"func New(v cty.Value) (Communicator, error) {\n\tv, err := shared.ConnectionBlockSupersetSchema.CoerceValue(v)\n\tif err != nil {\n\t\treturn nil, err\n\t}\n\n\ttypeVal := v.GetAttr(\"type\")\n\tconnType := \"\"\n\tif !typeVal.IsNull() {\n\t\tconnType = typeVal.AsString()\n\t}\n\n\tswitch connType {\n\tcase \"ssh\", \"\": // The default connection type is ssh, so if connType is empty use ssh\n\t\treturn ssh.New(v)\n\tcase \"winrm\":\n\t\treturn winrm.New(v)\n\tdefault:\n\t\treturn nil, fmt.Errorf(\"connection type '%s' not supported\", connType)\n\t}\n}\n\n// maxBackoffDelay is the maximum delay between retry attempts\nvar maxBackoffDelay = 20 * time.Second\nvar initialBackoffDelay = time.Second\n\n// in practice we want to abort the retry asap, but for tests we need to\n// synchronize the return.\nvar retryTestWg *sync.WaitGroup\n\n// Fatal is an interface that error values can return to halt Retry\ntype Fatal interface {\n\tFatalError() error\n}\n\n// Retry retries the function f until it returns a nil error, a Fatal error, or\n// the context expires.","sourceCodeStart":52,"sourceCodeEnd":88,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/communicator/communicator.go#L52-L88","documentation":"Returned by the connection-type factory when the connection block's type attribute is set to a value other than 'ssh' or 'winrm' (the only two supported communicators). An empty/omitted type defaults to ssh, so this only fires for an explicitly unrecognized, non-empty type string.","triggerScenarios":"A provisioner connection { type = \"...\" } block with a typo or unsupported value such as 'telnet', 'rdp', 'bash', or 'winrmm'. Any non-empty value that is not exactly 'ssh' or 'winrm' hits the default branch.","commonSituations":"Copy-paste from documentation of a different tool; typo like 'winrmm' or 'ssh2'; attempting to use a connection type that the local Terraform build does not support (older builds predate winrm).","solutions":["Set connection.type to either \"ssh\" or \"winrm\" (or omit it to get the ssh default).","For Windows targets use type = \"winrm\"; for Linux/Unix targets use type = \"ssh\" or omit.","Remove any leading/trailing whitespace in the type string."],"exampleFix":"// before\nconnection {\n  type     = \"winrmm\"\n  host     = aws_instance.web.public_ip\n}\n\n// after\nconnection {\n  type     = \"winrm\"\n  host     = aws_instance.web.public_ip\n}","handlingStrategy":"validation","validationCode":"# Validate before apply with a quick grep / policy check on connection.type:\n# only 'ssh', 'winrm', or unset are allowed.\ngrep -RnE 'type\\s*=\\s*\"(?!ssh|winrm)' *.tf && echo 'unsupported connection type' || echo ok","typeGuard":"# HCL: there is no native enum, but a sentinel check via locals:\nlocals {\n  allowed_conn_types = toset([\"ssh\", \"winrm\"])\n  # use only in modules that validate inputs; connection.type itself can't\n  # be guard-checked inline without a custom validation block in a variable.\n}","tryCatchPattern":null,"preventionTips":["Standardize connection.type from a module variable with a validation block restricting it to ssh/winrm.","Document that omitting type defaults to ssh.","Add a pre-apply policy (Sentinel/OPA) rejecting unknown connection types."],"tags":["terraform","connection","provisioner","ssh","winrm","validation"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}