{"record":{"id":"446c4b1fa683a487","repo":"hashicorp/terraform","slug":"resp-status","errorCode":null,"errorMessage":"${resp.Status}","messagePattern":"\\$\\{resp\\.Status\\}","errorType":"http","errorClass":"ErrQueryFailed","httpStatus":null,"severity":"error","filePath":"internal/pluginshared/client.go","lineNumber":196,"sourceCode":"\t\t\tinner: err,\n\t\t}\n\t}\n\tdefer resp.Body.Close()\n\n\tswitch resp.StatusCode {\n\tcase http.StatusOK:\n\t\tmanifest, err := decodeManifest(resp.Body)\n\t\tif err != nil {\n\t\t\treturn nil, err\n\t\t}\n\t\treturn manifest, nil\n\tcase http.StatusNotModified:\n\t\treturn nil, nil\n\tcase http.StatusNotFound:\n\t\treturn nil, ErrPluginNotSupported\n\tdefault:\n\t\treturn nil, ErrQueryFailed{\n\t\t\tinner: errors.New(resp.Status),\n\t\t}\n\t}\n}\n\n// DownloadFile gets the URL at the specified path or URL and writes the\n// contents to the specified Writer.\nfunc (b BasePluginClient) DownloadFile(pathOrURL string, writer io.Writer) error {\n\turl, err := b.resolveManifestURL(pathOrURL)\n\tif err != nil {\n\t\treturn err\n\t}\n\treq, err := retryablehttp.NewRequestWithContext(b.ctx, \"GET\", url.String(), nil)\n\tif err != nil {\n\t\treturn fmt.Errorf(\"invalid URL %q was provided by the %s manifest: %w\", url, b.pluginName, err)\n\t}\n\tresp, err := b.httpClient.Do(req)\n\tif err != nil {\n\t\tif errors.Is(err, context.Canceled) {","sourceCodeStart":178,"sourceCodeEnd":214,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/pluginshared/client.go#L178-L214","documentation":"Thrown by the plugin manifest HTTP client (BasePluginClient, pluginshared package) when the manifest query returned an HTTP status that is neither 200, 304, nor 404. The default branch wraps resp.Status (the HTTP status line, e.g. '429 Too Many Requests') in an ErrQueryFailed. This client is used to resolve the plugin release manifest (versions, build artifacts) from a releases server.","triggerScenarios":"The releases/manifest endpoint returned 5xx (server error), 429 (rate limit), 403 (forbidden/CI network policy), or another unexpected code during `terraform init` plugin discovery.","commonSituations":"Rate-limiting from releases.hashicorp.com in CI. Corporate proxy/firewall returning 403/502. Transient 5xx on the releases server. A misconfigured plugin installation mirror URL returning an error page.","solutions":["Retry `terraform init` — 429/5xx are usually transient; the client already uses retryablehttp for some requests.","Set CLI args / network config to route through an allowed mirror (TF_PLUGIN_CACHE_DIR, plugin_installation filesystem mirror).","Check for a proxy or firewall blocking the releases host; allowlist it.","Pin provider versions with `terraform providers lock` to avoid live manifest queries."],"exampleFix":"# before\n$ terraform init   # -> ErrQueryFailed: 429 Too Many Requests\n\n# after\n# wait and retry, or pre-lock providers offline\n$ terraform providers lock && terraform init","handlingStrategy":"retry","validationCode":"# shell: pre-check manifest endpoint reachability\n$ curl -sS -o /dev/null -w '%{http_code}\\n' https://releases.hashicorp.com/index.json","typeGuard":null,"tryCatchPattern":"# bash: retry init on transient manifest failures; fall back to locked providers\nfor i in 1 2 3; do\n  terraform init && break\n  sleep 5\ndone\n# fallback: use pre-locked providers offline\nterraform init -plugin-dir=.terraform/plugins","preventionTips":["Run `terraform providers lock` to vendor provider checksums and reduce live manifest queries.","Configure a filesystem mirror for air-gapped/restricted networks.","Allowlist the releases host through proxies/firewalls.","Throttle parallel CI jobs hitting the releases endpoint to avoid 429s."],"tags":["terraform","plugin-distribution","http","network","manifest"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}