{"record":{"id":"2da9a6a259afa88b","repo":"influxdata/influxdb","slug":"failed-to-build-an-http-client","errorCode":null,"errorMessage":"failed to build an http client: {}","messagePattern":"failed to build an http client: (.+?)","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"influxdb3_client/src/lib.rs","lineNumber":72,"sourceCode":"    Text(#[source] reqwest::Error),\n\n    #[error(\"server responded with error [{code}]: {message}\")]\n    ApiError {\n        code: StatusCode,\n        message: String,\n        /// Machine-readable error code from JSON error responses, if present.\n        error_code: Option<String>,\n    },\n\n    #[error(\"failed to send {method} {url} request: {}\", reqwest_description(.source))]\n    RequestSend {\n        method: Method,\n        url: String,\n        #[source]\n        source: reqwest::Error,\n    },\n\n    #[error(\"failed to build an http client: {}\", reqwest_description(.0))]\n    Builder(#[source] reqwest::Error),\n\n    #[error(\"io error: {0}\")]\n    IO(#[from] std::io::Error),\n}\n\n/// Try to parse a JSON error response body with `error_code` and `message` fields.\n/// Returns `(message, error_code)`. If JSON parsing fails, treats the body as plain text.\npub(crate) fn parse_error_body(body: &str) -> (String, Option<String>) {\n    #[derive(serde::Deserialize)]\n    struct JsonError {\n        #[serde(default)]\n        error_code: Option<String>,\n        #[serde(default)]\n        message: Option<String>,\n    }\n    if let Ok(parsed) = serde_json::from_str::<JsonError>(body) {\n        let message = parsed.message.unwrap_or_else(|| body.to_string());","sourceCodeStart":54,"sourceCodeEnd":90,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_client/src/lib.rs#L54-L90","documentation":"Error::Builder, raised during Client construction when reqwest's ClientBuilder fails to produce an HTTP client. The reqwest::Error is attached as #[source] and described via reqwest_description. This happens once, before any request is made, and always indicates a problem with the client configuration, not the server.","triggerScenarios":"Building the Client with invalid TLS configuration: unreadable/invalid CA certificate passed to add_root_certificate, invalid TLS version constraints, conflicting or invalid builder options (e.g. bad timeout values), or failure initializing the TLS backend.","commonSituations":"Pointing the client at a CA bundle path that doesn't exist or contains invalid PEM; enabling mutual TLS with a malformed client cert/key; platform TLS backend initialization failures (missing OpenSSL, restricted FIPS environments).","solutions":["Unwrap the source chain to see which builder option reqwest rejected","Validate the CA certificate file exists and contains valid PEM before passing it to add_root_certificate","Simplify the builder config (remove custom certs/TLS options) to isolate the failing option","Ensure the TLS backend dependency is properly installed (openssl/pkg-config on the build host)","Rebuild the client with a plain reqwest::Client::new() to confirm the base builder works in the environment"],"exampleFix":"// before\nlet ca = Certificate::from_pem(std::fs::read(\"ca.pem\")?); // invalid/missing PEM\nlet client = Client::new(url, token, Some(ca), ...)?; // Builder error\n// after\nlet pem = std::fs::read(\"ca.pem\")?;\nlet ca = Certificate::from_pem(&pem)?; // validate early\nlet client = Client::new(url, token, Some(ca), ...)?;","handlingStrategy":"validation","validationCode":"// validate cert material before building the client\nfn validate_pem(path: &std::path::Path) -> Result<(), String> {\n    let data = std::fs::read(path).map_err(|e| e.to_string())?;\n    if !data.starts_with(b\"-----BEGIN \") { return Err(\"not a PEM file\".into()); }\n    reqwest::Certificate::from_pem(&data).map(|_| ()).map_err(|e| e.to_string())\n}","typeGuard":"fn is_builder_error(e: &influxdb3_client::Error) -> bool {\n    matches!(e, influxdb3_client::Error::Builder(_))\n}","tryCatchPattern":"let client = match Client::new(url, token, ca, ...) {\n    Err(e @ influxdb3_client::Error::Builder(src)) => {\n        eprintln!(\"client config invalid: {src:#}\");\n        return Err(e); // fail fast at startup, never retry\n    }\n    other => other?,\n};","preventionTips":["Build the client once at startup so config errors surface immediately, not mid-request","Validate CA cert/key files exist and parse as PEM before passing them in","Keep TLS builder options minimal and tested on the target platform","Verify the TLS backend builds in your deployment image (openssl present, etc.)"],"tags":["http","tls","configuration","influxdb3","client"],"backgroundTag":"invalid-config-value","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}