{"record":{"id":"3fc5ca0bdd180651","repo":"hashicorp/terraform","slug":"error-connecting-to-proxy-s","errorCode":null,"errorMessage":"Error connecting to proxy: %s","messagePattern":"Error connecting to proxy: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/communicator/ssh/communicator.go","lineNumber":846,"sourceCode":"\taddr string,\n\tp *proxyInfo) func() (net.Conn, error) {\n\treturn func() (net.Conn, error) {\n\t\tlog.Printf(\"[DEBUG] Connecting to bastion: %s\", bAddr)\n\t\tvar bastion *ssh.Client\n\t\tvar err error\n\n\t\t// Wrap connection to bastion server if proxy server is configured\n\t\tif p != nil {\n\t\t\tvar pConn net.Conn\n\t\t\tvar bConn ssh.Conn\n\t\t\tvar bChans <-chan ssh.NewChannel\n\t\t\tvar bReq <-chan *ssh.Request\n\n\t\t\tRegisterDialerType()\n\t\t\tpConn, err = newHttpProxyConn(p, bAddr)\n\n\t\t\tif err != nil {\n\t\t\t\treturn nil, fmt.Errorf(\"Error connecting to proxy: %s\", err)\n\t\t\t}\n\n\t\t\tbConn, bChans, bReq, err = ssh.NewClientConn(pConn, bAddr, bConf)\n\n\t\t\tif err != nil {\n\t\t\t\treturn nil, fmt.Errorf(\"Error creating new client connection via proxy: %s\", err)\n\t\t\t}\n\n\t\t\tbastion = ssh.NewClient(bConn, bChans, bReq)\n\t\t} else {\n\t\t\tbastion, err = ssh.Dial(bProto, bAddr, bConf)\n\t\t}\n\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"Error connecting to bastion: %s\", err)\n\t\t}\n\n\t\tlog.Printf(\"[DEBUG] Connecting via bastion (%s) to host: %s\", bAddr, addr)","sourceCodeStart":828,"sourceCodeEnd":864,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/communicator/ssh/communicator.go#L828-L864","documentation":"Returned when newHttpProxyConn fails while establishing the bastion hop through an HTTP CONNECT proxy. The proxy connection to the bastion address (bAddr) could not be opened: proxy unreachable, refused, auth failed, or the CONNECT tunne failed with a non-200 (the latter is wrapped from http_proxy.go).","triggerScenarios":"connection.bastion_host is set together with a proxy_url; the proxy at proxy_url is down, refuses CONNECT to the bastion:port, requires auth that was not supplied, or returns a non-200 status. Also fires if the proxy URL is malformed.","commonSituations":"Corporate proxy requiring credentials not set in proxy_url; typo in proxy_url; proxy allowing only whitelisted destinations that exclude the bastion; proxy behind a flaky link.","solutions":["Verify proxy_url is reachable and accepts CONNECT to the bastion host:port (test with curl -x).","Provide proxy credentials in the URL if required: proxy_url = \"http://user:pass@proxy:3128\".","Confirm the bastion address and port in bastion_host/bastion_port are correct.","If the proxy returns a status code, see the wrapped 'Connection Error: StatusCode' message (797) for the code."],"exampleFix":"// before\nconnection {\n  host          = \"10.0.0.5\"\n  bastion_host  = \"bastion.example.com\"\n  proxy_url     = \"http://proxy.corp:3128\"\n}\n\n// after\nconnection {\n  host          = \"10.0.0.5\"\n  bastion_host  = \"bastion.example.com\"\n  proxy_url     = \"http://user:pass@proxy.corp:3128\"\n}","handlingStrategy":"validation","validationCode":"# Before apply, verify the proxy accepts CONNECT to the bastion:\n#   curl -v -x http://<proxy> --proxytunnel https://<bastion_host>:<bastion_port>\n# Provide creds in the URL if required by the proxy.","typeGuard":null,"tryCatchPattern":"// In Go, classify proxy-connect failure distinctly from SSH failures:\nif strings.Contains(err.Error(), \"Error connecting to proxy\") {\n    return fmt.Errorf(\"HTTP proxy refused CONNECT to bastion; check proxy_url/creds: %w\", err)\n}","preventionTips":["Test the proxy CONNECT path manually before apply.","Embed credentials in proxy_url when the proxy requires auth.","Whitelist bastion_host:bastion_port on the proxy."],"tags":["terraform","ssh","proxy","http-proxy","bastion","connection","provisioner"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}