{"record":{"id":"46d5bb824458902d","repo":"hashicorp/terraform","slug":"error-creating-new-client-connection-via-proxy-s","errorCode":null,"errorMessage":"Error creating new client connection via proxy: %s","messagePattern":"Error creating new client connection via proxy: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/communicator/ssh/communicator.go","lineNumber":852,"sourceCode":"\n\t\t// Wrap connection to bastion server if proxy server is configured\n\t\tif p != nil {\n\t\t\tvar pConn net.Conn\n\t\t\tvar bConn ssh.Conn\n\t\t\tvar bChans <-chan ssh.NewChannel\n\t\t\tvar bReq <-chan *ssh.Request\n\n\t\t\tRegisterDialerType()\n\t\t\tpConn, err = newHttpProxyConn(p, bAddr)\n\n\t\t\tif err != nil {\n\t\t\t\treturn nil, fmt.Errorf(\"Error connecting to proxy: %s\", err)\n\t\t\t}\n\n\t\t\tbConn, bChans, bReq, err = ssh.NewClientConn(pConn, bAddr, bConf)\n\n\t\t\tif err != nil {\n\t\t\t\treturn nil, fmt.Errorf(\"Error creating new client connection via proxy: %s\", err)\n\t\t\t}\n\n\t\t\tbastion = ssh.NewClient(bConn, bChans, bReq)\n\t\t} else {\n\t\t\tbastion, err = ssh.Dial(bProto, bAddr, bConf)\n\t\t}\n\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"Error connecting to bastion: %s\", err)\n\t\t}\n\n\t\tlog.Printf(\"[DEBUG] Connecting via bastion (%s) to host: %s\", bAddr, addr)\n\t\tconn, err := bastion.Dial(proto, addr)\n\t\tif err != nil {\n\t\t\tbastion.Close()\n\t\t\treturn nil, err\n\t\t}\n","sourceCodeStart":834,"sourceCodeEnd":870,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/communicator/ssh/communicator.go#L834-L870","documentation":"Returned when ssh.NewClientConn fails over the already-established HTTP proxy tunnel to the bastion. The proxy CONNECT succeeded (otherwise 793 would fire) but the SSH handshake to the bastion itself failed. Identical class of failure as the direct SSH auth error (784) but scoped to the bastion leg.","triggerScenarios":"Wrong bastion user/key/password, host key verification failure, algorithm/KEX mismatch with the bastion sshd, or the bastion's sshd not yet ready. The proxy tunnel is up but the SSH protocol exchange to the bastion errors.","commonSituations":"bastion_user/bastion_private_key pointing at the wrong identity; bastion_user default not valid for that bastion; hardened bastion sshd disabling the negotiated ciphers; freshly-booted bastion not yet serving SSH.","solutions":["Test the bastion directly through the proxy: ssh -o ProxyCommand='...' <bastion_user>@<bastion_host>.","Confirm bastion_user and bastion_private_key/bastion_password are correct for the bastion (separate from the target host creds).","Allow more time via connection.timeout for a bastion that boots slowly.","Check the wrapped %s for the precise SSH handshake failure."],"exampleFix":"// before\nconnection {\n  host               = \"10.0.0.5\"\n  user               = \"appuser\"\n  bastion_host       = \"bastion.example.com\"\n  bastion_user       = \"appuser\"   // wrong for bastion\n  bastion_private_key = file(\"~/.ssh/app-key\")\n}\n\n// after\nconnection {\n  host               = \"10.0.0.5\"\n  user               = \"appuser\"\n  bastion_host       = \"bastion.example.com\"\n  bastion_user       = \"devops\"\n  bastion_private_key = file(\"~/.ssh/bastion-key\")\n}","handlingStrategy":"validation","validationCode":"# Test SSH to the bastion through the proxy before apply:\n#   ssh -o ProxyCommand='nc -X connect -x proxy:3128 %h %p' <bastion_user>@<bastion_host>\n# Confirm bastion_user/bastion_private_key are correct for the bastion.","typeGuard":null,"tryCatchPattern":"// In Go, separate bastion-handshake failure from target-handshake failure:\nif strings.Contains(err.Error(), \"client connection via proxy\") {\n    return fmt.Errorf(\"bastion SSH handshake via proxy failed; check bastion creds: %w\", err)\n}","preventionTips":["Use bastion-specific credentials distinct from target host creds.","Smoke-test the bastion SSH path through the proxy.","Allow startup time for freshly-booted bastions via connection.timeout."],"tags":["terraform","ssh","proxy","bastion","handshake","authentication","provisioner"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}