{"record":{"id":"5280b0fed5c7b060","repo":"hashicorp/terraform","slug":"failed-to-determine-request-credentials-s","errorCode":null,"errorMessage":"failed to determine request credentials: %s","messagePattern":"failed to determine request credentials: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/http_mirror_source.go","lineNumber":341,"sourceCode":"// produced the returned response, possibly after following some redirects.\nfunc (s *HTTPMirrorSource) get(ctx context.Context, relativePath string) (statusCode int, body io.ReadCloser, finalURL *url.URL, error error) {\n\tendpointPath, err := url.Parse(relativePath)\n\tif err != nil {\n\t\t// Should never happen because the caller should validate all of the\n\t\t// components it's including in the path.\n\t\treturn 0, nil, nil, err\n\t}\n\tendpointURL := s.baseURL.ResolveReference(endpointPath)\n\n\treq, err := retryablehttp.NewRequest(\"GET\", endpointURL.String(), nil)\n\tif err != nil {\n\t\treturn 0, nil, endpointURL, err\n\t}\n\treq = req.WithContext(ctx)\n\treq.Request.Header.Set(terraformVersionHeader, version.String())\n\tcreds, err := s.mirrorHostCredentials()\n\tif err != nil {\n\t\treturn 0, nil, endpointURL, fmt.Errorf(\"failed to determine request credentials: %s\", err)\n\t}\n\tif creds != nil {\n\t\t// Note that if the initial requests gets redirected elsewhere\n\t\t// then the credentials will still be included in the new request,\n\t\t// even if they are on a different hostname. This is intentional\n\t\t// and consistent with how we handle credentials for other\n\t\t// Terraform-native services, because the user model is to configure\n\t\t// credentials for the \"friendly hostname\" they configured, not for\n\t\t// whatever hostname ends up ultimately serving the request as an\n\t\t// implementation detail.\n\t\tcreds.PrepareRequest(req.Request)\n\t}\n\n\tresp, err := s.httpClient.Do(req)\n\tif err != nil {\n\t\treturn 0, nil, endpointURL, err\n\t}\n\tdefer func() {","sourceCodeStart":323,"sourceCodeEnd":359,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/http_mirror_source.go#L323-L359","documentation":"During request building, the mirror client calls `mirrorHostCredentials()` to attach host credentials. If that lookup itself errors (see 895: invalid base URL, or the credentials source fails for the host), the error is wrapped with this prefix.","triggerScenarios":"`s.mirrorHostCredentials()` returns an error inside the GET helper; wrapped at http_mirror_source.go:341.","commonSituations":"Same root causes as 895 (bad base URL) plus: the configured credentials source for the mirror hostname fails (bad token, unreachable `cli_credentials_host`); credentials helper plugin error.","solutions":["Fix the mirror base URL so `mirrorHost` succeeds.","Verify credentials configuration for the mirror hostname in the CLI config / credentials helper.","Run `terraform providers mirror` or a manual `curl` with the same creds to isolate auth vs URL issues.","Remove the credentials block temporarily to see if the URL itself is the problem."],"exampleFix":"// before: creds block references unknown host\ncredentials \"mirror.local\" { token = \"...\" } // but url is https://other.local/\n// after: align URL and creds\nprovider_installation {\n  network_mirror { url = \"https://mirror.local/\" }\n}\ncredentials \"mirror.local\" { token = \"...\" }","handlingStrategy":"validation","validationCode":"// Pre-flight: confirm creds resolve before the request loop\nif creds, err := s.mirrorHostCredentials(); err != nil {\n    return fmt.Errorf(\"mirror credentials unavailable: %w\", err)\n} else if creds == nil {\n    log.Printf(\"[INFO] no mirror credentials configured; proceeding anonymous\")\n}","typeGuard":null,"tryCatchPattern":"creds, err := s.mirrorHostCredentials()\nif err != nil {\n    // retry without creds as anonymous fallback\n    log.Printf(\"[WARN] mirror creds failed (%s); retrying anonymous\", err)\n    creds = nil\n}","preventionTips":["Validate credentials for the mirror hostname with `terraform login <host>` (where applicable).","Keep credentials helper plugin versions aligned.","Test credentials with a direct `curl -u` before wiring them into Terraform.","Log credential resolution failures distinctly from request failures."],"tags":["network","mirror","credentials","config"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}