{"record":{"id":"e36a70cd0709a4a2","repo":"hashicorp/terraform","slug":"unexpected-http-response-code-d","errorCode":null,"errorMessage":"Unexpected HTTP response code %d","messagePattern":"Unexpected HTTP response code (.+?)","errorType":"http","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/http/client.go","lineNumber":122,"sourceCode":"\t\tbody, err := io.ReadAll(resp.Body)\n\t\tif err != nil {\n\t\t\treturn \"\", &statemgr.LockError{\n\t\t\t\tErr: fmt.Errorf(\"HTTP remote state already locked, failed to read body\"),\n\t\t\t}\n\t\t}\n\t\texisting := statemgr.LockInfo{}\n\t\terr = json.Unmarshal(body, &existing)\n\t\tif err != nil {\n\t\t\treturn \"\", &statemgr.LockError{\n\t\t\t\tErr: fmt.Errorf(\"HTTP remote state already locked, failed to unmarshal body\"),\n\t\t\t}\n\t\t}\n\t\treturn \"\", &statemgr.LockError{\n\t\t\tInfo: &existing,\n\t\t\tErr:  fmt.Errorf(\"HTTP remote state already locked: ID=%s\", existing.ID),\n\t\t}\n\tdefault:\n\t\treturn \"\", fmt.Errorf(\"Unexpected HTTP response code %d\", resp.StatusCode)\n\t}\n}\n\nfunc (c *httpClient) Unlock(id string) error {\n\tif c.UnlockURL == nil {\n\t\treturn nil\n\t}\n\n\tresp, err := c.httpRequest(c.UnlockMethod, c.UnlockURL, &c.jsonLockInfo, \"unlock\")\n\tif err != nil {\n\t\treturn err\n\t}\n\tdefer resp.Body.Close()\n\n\tswitch resp.StatusCode {\n\tcase http.StatusOK:\n\t\treturn nil\n\tdefault:","sourceCodeStart":104,"sourceCodeEnd":140,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/http/client.go#L104-L140","documentation":"The lock response status code was not one of 200/401/403/409/423. '%d' is the unexpected status. Common culprits: 404 (lock_address points to a non-existent route), 405 (the configured lock_method is not allowed by the server), 500/502/503 (server/gateway error), or 301/302 (redirect the client did not follow).","triggerScenarios":"lock_address routes to a non-existent path (404); server does not implement the LOCK verb and returns 405 (typical when lock_method=LOCK against a generic web server); server error (500); reverse proxy misroutes the request.","commonSituations":"lock_address set equal to address but the server has no dedicated lock endpoint; lock_method=LOCK but the server only accepts POST/PUT; reverse proxy rewrites the path incorrectly; server's lock route moved.","solutions":["Confirm lock_address is correct: curl -i -X <lock_method> <lock_address>.","If the server does not support the configured method, set lock_method to a verb it accepts (commonly POST or PUT).","For 404, correct the lock_address path or remove it to disable locking.","For 5xx, address the server-side error and retry.","Ensure reverse proxies follow/forward the lock route and do not redirect to a different status."],"exampleFix":"// before (server does not support LOCK verb -> 405)\nlock_method   = \"LOCK\"\n// after\nlock_method   = \"POST\"","handlingStrategy":"validation","validationCode":"# Pre-flight: confirm the lock endpoint returns an expected status for the method\ncode=$(curl -sS -o /dev/null -w '%{http_code}' -u \"$TF_HTTP_USERNAME:$TF_HTTP_PASSWORD\" \\\n  -X \"${TF_HTTP_LOCK_METHOD:-LOCK}\" \"${TF_HTTP_LOCK_ADDRESS:-$TF_HTTP_ADDRESS}\")\ncase \"$code\" in\n  200|201|204|401|403|409|423) echo \"lock endpoint ok ($code)\" ;;\n  *) echo \"ERROR: unexpected lock status $code — check lock_address/lock_method\"; exit 1 ;;\nesac","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Confirm lock_address routes to a real lock endpoint (not the plain state URL).","Match lock_method to a verb the server supports (POST/PUT are safest).","Probe lock_address with curl -X <method> before terraform apply."],"tags":["http","lock","status-code","http-backend","config"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}