{"record":{"id":"cb74b1cb2a77add1","repo":"hashicorp/terraform","slug":"address-must-be-http-or-https","errorCode":null,"errorMessage":"address must be HTTP or HTTPS","messagePattern":"address must be HTTP or HTTPS","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/http/backend.go","lineNumber":138,"sourceCode":"func (b *Backend) Configure(configVal cty.Value) tfdiags.Diagnostics {\n\taddress := backendbase.GetAttrEnvDefaultFallback(\n\t\tconfigVal, \"address\",\n\t\t\"TF_HTTP_ADDRESS\", cty.StringVal(\"\"),\n\t).AsString()\n\tif address == \"\" {\n\t\treturn backendbase.ErrorAsDiagnostics(\n\t\t\tfmt.Errorf(\"address argument is required\"),\n\t\t)\n\t}\n\tupdateURL, err := url.Parse(address)\n\tif err != nil {\n\t\treturn backendbase.ErrorAsDiagnostics(\n\t\t\tfmt.Errorf(\"failed to parse address URL: %s\", err),\n\t\t)\n\t}\n\tif updateURL.Scheme != \"http\" && updateURL.Scheme != \"https\" {\n\t\treturn backendbase.ErrorAsDiagnostics(\n\t\t\tfmt.Errorf(\"address must be HTTP or HTTPS\"),\n\t\t)\n\t}\n\n\tupdateMethod := backendbase.GetAttrEnvDefaultFallback(\n\t\tconfigVal, \"update_method\",\n\t\t\"TF_HTTP_UPDATE_METHOD\", cty.StringVal(\"POST\"),\n\t).AsString()\n\n\tvar lockURL *url.URL\n\tif v := backendbase.GetAttrEnvDefault(configVal, \"lock_address\", \"TF_HTTP_LOCK_ADDRESS\"); !v.IsNull() {\n\t\tvar err error\n\t\tlockURL, err = url.Parse(v.AsString())\n\t\tif err != nil {\n\t\t\treturn backendbase.ErrorAsDiagnostics(\n\t\t\t\tfmt.Errorf(\"failed to parse lock_address URL: %s\", err),\n\t\t\t)\n\t\t}\n\t\tif lockURL.Scheme != \"http\" && lockURL.Scheme != \"https\" {","sourceCodeStart":120,"sourceCodeEnd":156,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/http/backend.go#L120-L156","documentation":"Thrown by Backend.Configure after url.Parse(address) succeeds but the URL scheme is neither 'http' nor 'https'. The HTTP backend only speaks HTTP(S); other schemes are rejected to prevent ambiguous behavior. The value comes from the 'address' attribute in the backend block or the TF_HTTP_ADDRESS environment variable.","triggerScenarios":"terraform init runs with the 'address' attribute (or TF_HTTP_ADDRESS) set to a URL whose scheme is not http/https — e.g. 'ftp://host', 'file:///path', 's3://bucket/key', or a bare host parsed with an unexpected scheme.","commonSituations":"Copy-pasting a storage URI from another backend (s3://, gcs://); omitting the https:// prefix so the host becomes a path; a typo like 'httpss://'; trailing whitespace or a newline appended by a secret manager.","solutions":["Set address to a full absolute HTTP(S) URL, e.g. 'https://state.example.com/terraform/default'.","If using TF_HTTP_ADDRESS, export it WITH the scheme: export TF_HTTP_ADDRESS=https://state.example.com/...","Strip trailing whitespace/newlines from the value (e.g. tr -d '\\r\\n') when sourcing from a file or secret store.","Confirm there is exactly one scheme token and no embedded spaces."],"exampleFix":"// before\naddress = \"state.example.com/terraform\"\n// or\naddress = \"s3://mybucket/state\"\n// after\naddress = \"https://state.example.com/terraform\"","handlingStrategy":"validation","validationCode":"# Pre-flight: ensure address is http(s) before terraform init\naddr=\"${TF_HTTP_ADDRESS:-https://state.example.com/terraform}\"\ncase \"$addr\" in\n  http://*|https://*) echo \"ok: $addr\" ;;\n  *) echo \"ERROR: address must start with http:// or https:// — got: $addr\"; exit 1 ;;\nesac","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Always write the http(s) scheme explicitly in the address attribute — never a bare host.","Never paste URIs from other backends (s3://, gcs://, azurandom://) into the http backend.","When sourcing address from a secret/env, trim whitespace and assert the scheme in a pre-flight check."],"tags":["config","url-validation","http-backend","scheme"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}