{"record":{"id":"cbb4be9884610c89","repo":"hashicorp/terraform","slug":"invalid-provider-matching-pattern-q-hostname-can","errorCode":null,"errorMessage":"invalid provider matching pattern %q: hostname can be a wildcard only if both namespace and provider type are also wildcards","messagePattern":"invalid provider matching pattern %q: hostname can be a wildcard only if both namespace and provider type are also wildcards","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/multi_source.go","lineNumber":188,"sourceCode":"\t\t}\n\n\t\tpType, err := normalizeProviderNameOrWildcard(parts[1])\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"invalid provider type %q in provider matching pattern %q: must either be the wildcard * or a provider type name\", parts[1], str)\n\t\t}\n\t\tnamespace, err := normalizeProviderNamespaceOrWildcard(parts[0])\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"invalid registry namespace %q in provider matching pattern %q: must either be the wildcard * or a literal namespace\", parts[1], str)\n\t\t}\n\n\t\tret[i] = addrs.Provider{\n\t\t\tHostname:  host,\n\t\t\tNamespace: namespace,\n\t\t\tType:      pType,\n\t\t}\n\n\t\tif ret[i].Hostname == svchost.Hostname(Wildcard) && !(ret[i].Namespace == Wildcard && ret[i].Type == Wildcard) {\n\t\t\treturn nil, fmt.Errorf(\"invalid provider matching pattern %q: hostname can be a wildcard only if both namespace and provider type are also wildcards\", str)\n\t\t}\n\t\tif ret[i].Namespace == Wildcard && ret[i].Type != Wildcard {\n\t\t\treturn nil, fmt.Errorf(\"invalid provider matching pattern %q: namespace can be a wildcard only if the provider type is also a wildcard\", str)\n\t\t}\n\t}\n\treturn ret, nil\n}\n\n// CanHandleProvider returns true if and only if the given provider address\n// is both included by the selector's include patterns and _not_ excluded\n// by its exclude patterns.\n//\n// The absense of any include patterns is treated the same as a pattern\n// that matches all addresses. Exclusions take priority over inclusions.\nfunc (s MultiSourceSelector) CanHandleProvider(addr addrs.Provider) bool {\n\tswitch {\n\tcase s.Exclude.MatchesProvider(addr):\n\t\treturn false","sourceCodeStart":170,"sourceCodeEnd":206,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/multi_source.go#L170-L206","documentation":"Thrown when the host segment is the wildcard '*' but at least one of namespace or type is not also '*'. The parser only permits a wildcard hostname in the fully-wildcard form '*/*/*'; a wildcard host with any concrete namespace or type is ambiguous and rejected. Checked at multi_source.go:187-188 after all three segments are normalized.","triggerScenarios":"Patterns like '*/hashicorp/aws', '*/*/aws', or '*/hashicorp/*'. Any 3-segment pattern whose first segment is '*' but whose remaining two are not both '*' hits this branch.","commonSituations":"Wanting 'any host for a specific provider' (not supported by the model — host wildcard forces total wildcard); mixing a literal host with '*' by mistake; building exclude patterns intending broad coverage but over-wildcarding the host.","solutions":["If you truly want all hosts, use '*/*/*' (matches every provider on every host).","Otherwise drop the host wildcard and name the concrete host: 'registry.terraform.io/hashicorp/aws'.","To match a provider across namespaces on a known host, wildcard only the namespace: 'host/*/aws' (allowed) rather than '*/namespace/aws'."],"exampleFix":"// before\ninclude = [\"*/hashicorp/aws\"]\n\n// after\ninclude = [\"registry.terraform.io/hashicorp/aws\"]","handlingStrategy":"validation","validationCode":"func validWildcardCombination(host, ns, typ string) error {\n    // after normalization, host == \"*\" forces ns == \"*\" and typ == \"*\"\n    if host == \"*\" && !(ns == \"*\" && typ == \"*\") {\n        return fmt.Errorf(\"hostname wildcard requires namespace and type to also be '*/*/*'\")\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Only use '*/*/*' when wildcarding the host.","For a specific provider on a specific host, name the host explicitly.","Lint wildcard combinations in config tests."],"tags":["provider-config","pattern","wildcard","hostname","validation","multi-source"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}