{"record":{"id":"79fa4edce71ec0d3","repo":"hashicorp/terraform","slug":"failed-to-make-s-http-request-s","errorCode":null,"errorMessage":"Failed to make %s HTTP request: %s","messagePattern":"Failed to make (.+?) HTTP request: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/http/client.go","lineNumber":53,"sourceCode":"\tClient   *retryablehttp.Client\n\tUsername string\n\tPassword string\n\n\tlockID       string\n\tjsonLockInfo []byte\n}\n\nfunc (c *httpClient) httpRequest(method string, url *url.URL, data *[]byte, what string) (*http.Response, error) {\n\t// If we have data we need a reader\n\tvar reader io.Reader = nil\n\tif data != nil {\n\t\treader = bytes.NewReader(*data)\n\t}\n\n\t// Create the request\n\treq, err := retryablehttp.NewRequest(method, url.String(), reader)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"Failed to make %s HTTP request: %s\", what, err)\n\t}\n\t// Set up basic auth\n\tif c.Username != \"\" {\n\t\treq.SetBasicAuth(c.Username, c.Password)\n\t}\n\n\t// Work with data/body\n\tif data != nil {\n\t\treq.Header.Set(\"Content-Type\", \"application/json\")\n\t\treq.ContentLength = int64(len(*data))\n\n\t\t// Generate the MD5\n\t\thash := md5.Sum(*data)\n\t\tb64 := base64.StdEncoding.EncodeToString(hash[:])\n\t\treq.Header.Set(\"Content-MD5\", b64)\n\t}\n\n\t// Make the request","sourceCodeStart":35,"sourceCodeEnd":71,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/http/client.go#L35-L71","documentation":"retryablehttp.NewRequest(method, url, body) returned an error before any network call. This is a request-construction failure, almost always an invalid HTTP method (containing spaces or control characters) or, less often, an invalid URL string with control characters. The '%s' is filled by the 'what' argument: 'lock', 'unlock', 'get state', 'upload state', or 'delete state'.","triggerScenarios":"User set lock_method/unlock_method/update_method to a string containing whitespace or control characters (e.g. 'LOCK\\n', 'P OST'); a URL string contains control characters that slipped past url.Parse at config time (very rare).","commonSituations":"Env var (TF_HTTP_LOCK_METHOD etc.) carries a trailing newline from a secret store or echo; method mistyped with a space; method set via a variable that picked up whitespace.","solutions":["Set update_method/lock_method/unlock_method to a valid HTTP verb with no whitespace (POST, PUT, LOCK, UNLOCK, DELETE, GET).","Trim trailing newlines/whitespace from the TF_HTTP_*_METHOD env vars: export TF_HTTP_LOCK_METHOD=$(printf '%s' \"$TF_HTTP_LOCK_METHOD\").","Re-run terraform init after correcting the method value."],"exampleFix":"// before (env has trailing newline)\n//   TF_HTTP_LOCK_METHOD='LOCK\\n'\n// after\nexport TF_HTTP_LOCK_METHOD=LOCK","handlingStrategy":"validation","validationCode":"# Pre-flight: HTTP methods must be a bare token with no whitespace/control chars\nfor v in TF_HTTP_UPDATE_METHOD TF_HTTP_LOCK_METHOD TF_HTTP_UNLOCK_METHOD; do\n  val=$(eval echo \"\\$$v\")\n  if [ -n \"$val\" ] && printf '%s' \"$val\" | grep -Pq '[\\x00-\\x20]|[^[:print:]]'; then\n    echo \"ERROR: $v contains whitespace/control chars: '$val'\"; exit 1\n  fi\ndone","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Set *_method values to a single uppercase HTTP verb with no surrounding whitespace.","When sourcing methods from env/secret stores, trim trailing newlines.","Prefer the documented defaults (POST / LOCK / UNLOCK) unless the server requires otherwise."],"tags":["http","request","http-backend","method","config"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}