{"record":{"id":"d8afd0ef616061dc","repo":"hashicorp/terraform","slug":"invalid-provider-mirror-base-url-s-s","errorCode":null,"errorMessage":"invalid provider mirror base URL %s: %s","messagePattern":"invalid provider mirror base URL (.+?): (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/http_mirror_source.go","lineNumber":304,"sourceCode":"//\n// If the returned error is non-nil then the given hostname doesn't comply\n// with the IETF RFC 5891 section 5.3 and 5.4 validation rules, and thus cannot\n// be interpreted as a valid Terraform service host. The IDNA validation errors\n// are unfortunately usually not very user-friendly, but they are also\n// relatively rare because the IDNA normalization rules are quite tolerant.\nfunc (s *HTTPMirrorSource) mirrorHost() (svchost.Hostname, error) {\n\treturn svchostFromURL(s.baseURL)\n}\n\n// mirrorHostCredentials returns the HostCredentials, if any, for the hostname\n// included in the mirror base URL.\n//\n// It might return an error if the mirror base URL is invalid, or if the\n// credentials lookup itself fails.\nfunc (s *HTTPMirrorSource) mirrorHostCredentials() (svcauth.HostCredentials, error) {\n\thostname, err := s.mirrorHost()\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"invalid provider mirror base URL %s: %s\", s.baseURL.String(), err)\n\t}\n\n\tif s.creds == nil {\n\t\t// No host-specific credentials, then.\n\t\treturn nil, nil\n\t}\n\n\treturn s.creds.ForHost(hostname)\n}\n\n// get is the shared functionality for querying a JSON index from a mirror.\n//\n// It only handles the raw HTTP request. The \"body\" return value is the\n// reader from the response if and only if the response status code is 200 OK\n// and the Content-Type is application/json. In all other cases it's nil.\n// If body is non-nil then the caller must close it after reading it.\n//\n// If the \"finalURL\" return value is not empty then it's the URL that actually","sourceCodeStart":286,"sourceCodeEnd":322,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/http_mirror_source.go#L286-L322","documentation":"`mirrorHostCredentials` calls `mirrorHost()` to derive a `svchost.Hostname` from the mirror base URL. If that conversion fails (URL not parseable into a valid hostname), the error wraps the cause and names the base URL.","triggerScenarios":"`svchostFromURL(s.baseURL)` returns an error inside `mirrorHostCredentials`; error at http_mirror_source.go:304.","commonSituations":"`network_mirror.url` configured with a URL whose host is empty or invalid; URL using a scheme/host combination `svchost` rejects; runtime mutation of `baseURL` to something invalid.","solutions":["Validate the `network_mirror` URL in the CLI config (`~/.terraformrc` or `terraform.rc`): it must be a well-formed `https://hostname/...` URL.","Use an IP or hostname that `svchost.Hostname` can parse (no spaces, valid DNS chars).","Restart Terraform after fixing the config."],"exampleFix":"// before\nprovider_installation {\n  network_mirror { url = \"https:///mirror.local/\" } // empty host\n}\n// after\nprovider_installation {\n  network_mirror { url = \"https://mirror.local/\" }\n}","handlingStrategy":"validation","validationCode":"// Validate the configured mirror URL up front\nu, err := url.Parse(mirrorURL)\nif err != nil || u.Host == \"\" {\n    return fmt.Errorf(\"network_mirror.url %q has no usable host\", mirrorURL)\n}\nif _, err := svchost.FromString(u.Hostname()); err != nil {\n    return fmt.Errorf(\"network_mirror.url host %q is not a valid service hostname\", u.Hostname())\n}","typeGuard":"// isValidMirrorURL narrows to URLs whose host svchost accepts\nfunc isValidMirrorURL(s string) bool {\n    u, err := url.Parse(s)\n    if err != nil || u.Host == \"\" { return false }\n    _, err = svchost.FromString(u.Hostname())\n    return err == nil\n}","tryCatchPattern":null,"preventionTips":["Validate `network_mirror.url` at CLI config load time.","Use DNS hostnames, not raw IPs or empty hosts.","Keep CLI config under version control with CI checks.","Fail fast on config load rather than mid-request."],"tags":["network","mirror","config","url-parse"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}