{"record":{"id":"308f8d951b893317","repo":"hashicorp/terraform","slug":"failed-to-read-remote-state-s","errorCode":null,"errorMessage":"Failed to read remote state: %s","messagePattern":"Failed to read remote state: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/http/client.go","lineNumber":174,"sourceCode":"\t\t// Handled after\n\tcase http.StatusNoContent:\n\t\treturn nil, diags\n\tcase http.StatusNotFound:\n\t\treturn nil, diags\n\tcase http.StatusUnauthorized:\n\t\treturn nil, diags.Append(fmt.Errorf(\"HTTP remote state endpoint requires auth\"))\n\tcase http.StatusForbidden:\n\t\treturn nil, diags.Append(fmt.Errorf(\"HTTP remote state endpoint invalid auth\"))\n\tcase http.StatusInternalServerError:\n\t\treturn nil, diags.Append(fmt.Errorf(\"HTTP remote state internal server error\"))\n\tdefault:\n\t\treturn nil, diags.Append(fmt.Errorf(\"Unexpected HTTP response code %d\", resp.StatusCode))\n\t}\n\n\t// Read in the body\n\tbuf := bytes.NewBuffer(nil)\n\tif _, err := io.Copy(buf, resp.Body); err != nil {\n\t\treturn nil, diags.Append(fmt.Errorf(\"Failed to read remote state: %s\", err))\n\t}\n\n\t// Create the payload\n\tpayload := &remote.Payload{\n\t\tData: buf.Bytes(),\n\t}\n\n\t// If there was no data, then return nil\n\tif len(payload.Data) == 0 {\n\t\treturn nil, diags\n\t}\n\n\t// Check for the MD5\n\tif raw := resp.Header.Get(\"Content-MD5\"); raw != \"\" {\n\t\tmd5, err := base64.StdEncoding.DecodeString(raw)\n\t\tif err != nil {\n\t\t\treturn nil, diags.Append(fmt.Errorf(\n\t\t\t\t\"Failed to decode Content-MD5 '%s': %s\", raw, err))","sourceCodeStart":156,"sourceCodeEnd":192,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/http/client.go#L156-L192","documentation":"Thrown when io.Copy from resp.Body into a buffer fails while reading the state payload (client.go:171-175). The %s is the underlying I/O error. This occurs after a successful status code (200 OK) but during body streaming, so the connection broke mid-transfer.","triggerScenarios":"The TCP connection is reset or dropped while the response body is being read; a proxy closes the connection after a timeout; the server streams slowly and an intermediary cuts it off; TLS handshake succeeds but the socket dies during transfer.","commonSituations":"Flaky network or VPN dropping long-lived connections; a reverse proxy with an aggressive read timeout; large state files exceeding a proxy body-size/time limit mid-stream; cloud network blips.","solutions":["Retry the Terraform command — transient I/O failures often clear on the next attempt.","If recurring, check for proxy/intermediary read timeouts that are shorter than large-state transfer time.","Reduce state size (split resources into workspaces) if transfers consistently time out.","Verify network stability to the state endpoint (latency, packet loss)."],"exampleFix":null,"handlingStrategy":"retry","validationCode":null,"typeGuard":null,"tryCatchPattern":"// Retry body-read failures with backoff; they are typically transient:\n// var payload *remote.Payload\n// for attempt := 0; attempt < maxAttempts; attempt++ {\n//   var diags tfdiags.Diagnostics\n//   payload, diags = httpClient.Get()\n//   if !diagsHas(diags, \"Failed to read remote state\") { break }\n//   time.Sleep(backoff(attempt))\n// }","preventionTips":["Ensure proxies/load balancers have read timeouts larger than large-state transfer time.","Stabilize the network path between Terraform and the state server.","Keep state reasonably sized (split workspaces) to shorten transfers."],"tags":["http-backend","io-error","network","remote-state"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}