{"record":{"id":"a573a38af43e026f","repo":"hashicorp/terraform","slug":"failed-to-write-temp-known-hosts-file-s","errorCode":null,"errorMessage":"failed to write temp known_hosts file: %s","messagePattern":"failed to write temp known_hosts file: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/communicator/ssh/provisioner.go","lineNumber":348,"sourceCode":"\thkCallback := ssh.InsecureIgnoreHostKey()\n\n\tif opts.hostKey != \"\" {\n\t\t// The knownhosts package only takes paths to files, but terraform\n\t\t// generally wants to handle config data in-memory. Rather than making\n\t\t// the known_hosts file an exception, write out the data to a temporary\n\t\t// file to create the HostKeyCallback.\n\t\ttf, err := ioutil.TempFile(\"\", \"tf-known_hosts\")\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"failed to create temp known_hosts file: %s\", err)\n\t\t}\n\t\tdefer tf.Close()\n\t\tdefer os.RemoveAll(tf.Name())\n\n\t\t// we mark this as a CA as well, but the host key fallback will still\n\t\t// use it as a direct match if the remote host doesn't return a\n\t\t// certificate.\n\t\tif _, err := tf.WriteString(fmt.Sprintf(\"@cert-authority %s %s\\n\", opts.host, opts.hostKey)); err != nil {\n\t\t\treturn nil, fmt.Errorf(\"failed to write temp known_hosts file: %s\", err)\n\t\t}\n\t\ttf.Sync()\n\n\t\thkCallback, err = knownhosts.New(tf.Name())\n\t\tif err != nil {\n\t\t\treturn nil, err\n\t\t}\n\t}\n\n\tconf := &ssh.ClientConfig{\n\t\tHostKeyCallback: hkCallback,\n\t\tUser:            opts.user,\n\t}\n\n\tif opts.privateKey != \"\" {\n\t\tif opts.certificate != \"\" {\n\t\t\tlog.Println(\"using client certificate for authentication\")\n","sourceCodeStart":330,"sourceCodeEnd":366,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/communicator/ssh/provisioner.go#L330-L366","documentation":"After successfully creating the temp known_hosts file, Terraform writes a single @cert-authority line (host + host_key) into it via tf.WriteString. If the write fails — disk full mid-write, I/O error, or the file handle became invalid — the HostKeyCallback cannot be constructed and SSH connection setup fails. Note that tf.Sync() on the following line ignores its return error, so sync failures are silently swallowed.","triggerScenarios":"Providing a host_key in the connection block and hitting an I/O error during tf.WriteString of the @cert-authority line. Commonly triggered by ENOSPC after the temp file was created but before the write completes, or by a filesystem-level write error (NFS hiccup, overlay fs issue in containers).","commonSituations":"Disk fills up between file creation and write on a constrained CI runner. NFS-mounted temp directory with intermittent I/O errors. Container overlay filesystem failing to flush. Very large host_key string combined with low disk space.","solutions":["Free disk space on the volume hosting the temp directory and retry the Terraform run.","Verify the host_key value is not corrupt or absurdly large — a valid host key is a single line.","If on NFS or networked storage for /tmp, switch to local storage for the temp directory.","Set TMPDIR to a volume with adequate free space and retry."],"exampleFix":"# before\nconnection {\n  host_key = file(\"large-or-corrupt-key.txt\")\n}\n\n# after — ensure host_key is a single valid known_hosts entry\nconnection {\n  host_key = \"ssh-rsa AAAAB3Nza...validkey...\"\n}","handlingStrategy":"validation","validationCode":"// Validate the host_key is a single clean line before passing it in\nfunc validateHostKey(hostKey string) error {\n    trimmed := strings.TrimSpace(hostKey)\n    if trimmed == \"\" {\n        return errors.New(\"host_key is empty\")\n    }\n    if strings.Count(trimmed, \"\\n\") > 0 {\n        return errors.New(\"host_key should be a single line\")\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Ensure adequate free disk space before large provisioning runs.","Avoid NFS or network-backed storage for the temp directory.","Validate host_key input is a single well-formed known_hosts entry."],"tags":["ssh","filesystem","io-write","provisioner","host-key"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}