{"record":{"id":"a66426e01ee17fba","repo":"hashicorp/terraform","slug":"target-platform-for-provisioner-has-to-be-either","errorCode":null,"errorMessage":"target_platform for provisioner has to be either %s or %s","messagePattern":"target_platform for provisioner has to be either (.+?) or (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/communicator/ssh/provisioner.go","lineNumber":203,"sourceCode":"\n\t// Check if host is empty.\n\t// Otherwise return error.\n\tif connInfo.Host == \"\" {\n\t\treturn nil, fmt.Errorf(\"host for provisioner cannot be empty\")\n\t}\n\n\t// Format the host if needed.\n\t// Needed for IPv6 support.\n\tconnInfo.Host = shared.IpFormat(connInfo.Host)\n\n\tif connInfo.Port == 0 {\n\t\tconnInfo.Port = DefaultPort\n\t}\n\t// Set default targetPlatform to unix if it's empty\n\tif connInfo.TargetPlatform == \"\" {\n\t\tconnInfo.TargetPlatform = TargetPlatformUnix\n\t} else if connInfo.TargetPlatform != TargetPlatformUnix && connInfo.TargetPlatform != TargetPlatformWindows {\n\t\treturn nil, fmt.Errorf(\"target_platform for provisioner has to be either %s or %s\", TargetPlatformUnix, TargetPlatformWindows)\n\t}\n\t// Choose an appropriate default script path based on the target platform. There is no single\n\t// suitable default script path which works on both UNIX and Windows targets.\n\tif connInfo.ScriptPath == \"\" && connInfo.TargetPlatform == TargetPlatformUnix {\n\t\tconnInfo.ScriptPath = DefaultUnixScriptPath\n\t}\n\tif connInfo.ScriptPath == \"\" && connInfo.TargetPlatform == TargetPlatformWindows {\n\t\tconnInfo.ScriptPath = DefaultWindowsScriptPath\n\t}\n\tif connInfo.Timeout != \"\" {\n\t\tconnInfo.TimeoutVal = safeDuration(connInfo.Timeout, DefaultTimeout)\n\t} else {\n\t\tconnInfo.TimeoutVal = DefaultTimeout\n\t}\n\n\t// Default all bastion config attrs to their non-bastion counterparts\n\tif connInfo.BastionHost != \"\" {\n\t\t// Format the bastion host if needed.","sourceCodeStart":185,"sourceCodeEnd":221,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/communicator/ssh/provisioner.go#L185-L221","documentation":"Returned by parseConnectionInfo when target_platform is a non-empty value that is neither 'unix' nor 'windows'. The field controls scp command quoting and default script_path; only two platforms are implemented. An empty value is defaulted to unix, so this fires only for an explicit, unrecognized non-empty value.","triggerScenarios":"connection.target_platform set to a typo or unsupported value such as 'linux', 'macos', 'win', or 'unixx'. Any non-empty value that is not exactly 'unix' or 'windows' triggers it.","commonSituations":"Guessing 'linux' instead of 'unix'; using 'win' instead of 'windows'; copy-paste from non-Terraform docs; trailing whitespace in the value.","solutions":["Set target_platform to \"unix\" or \"windows\" (or omit it to default to unix).","Remove trailing/leading whitespace from the value.","Use \"windows\" for WinRM targets and \"unix\" (or omit) for SSH/Linux/BSD targets."],"exampleFix":"// before\nconnection {\n  host            = aws_instance.win.public_ip\n  type            = \"winrm\"\n  target_platform = \"win\"\n}\n\n// after\nconnection {\n  host            = aws_instance.win.public_ip\n  type            = \"winrm\"\n  target_platform = \"windows\"\n}","handlingStrategy":"validation","validationCode":"# Before apply, validate target_platform is one of the allowed values:\n#   grep -RnE 'target_platform\\s*=\\s*\"(?!unix|windows)' *.tf && echo bad || echo ok\n# In HCL, drive it from a variable with a validation block:\nvariable \"target_platform\" {\n  type    = string\n  default = \"unix\"\n  validation {\n    condition     = contains([\"unix\", \"windows\"], var.target_platform)\n    error_message = \"target_platform must be 'unix' or 'windows'.\"\n  }\n}","typeGuard":"// Go guard if constructing connection info directly:\nfunc validTargetPlatform(p string) bool {\n    return p == \"\" || p == \"unix\" || p == \"windows\"\n}","tryCatchPattern":null,"preventionTips":["Use 'unix' or 'windows' (or omit) for target_platform.","Drive the value from a validated variable in reusable modules.","Add an OPA/Sentinel policy rejecting unsupported platform values."],"tags":["terraform","connection","target-platform","validation","config","provisioner"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}