{"record":{"id":"f9e49900a4a7983a","repo":"hashicorp/terraform","slug":"failed-to-s-v","errorCode":null,"errorMessage":"Failed to %s: %v","messagePattern":"Failed to (.+?): (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/http/client.go","lineNumber":74,"sourceCode":"\tif c.Username != \"\" {\n\t\treq.SetBasicAuth(c.Username, c.Password)\n\t}\n\n\t// Work with data/body\n\tif data != nil {\n\t\treq.Header.Set(\"Content-Type\", \"application/json\")\n\t\treq.ContentLength = int64(len(*data))\n\n\t\t// Generate the MD5\n\t\thash := md5.Sum(*data)\n\t\tb64 := base64.StdEncoding.EncodeToString(hash[:])\n\t\treq.Header.Set(\"Content-MD5\", b64)\n\t}\n\n\t// Make the request\n\tresp, err := c.Client.Do(req)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"Failed to %s: %v\", what, err)\n\t}\n\n\treturn resp, nil\n}\n\nfunc (c *httpClient) Lock(info *statemgr.LockInfo) (string, error) {\n\tif c.LockURL == nil {\n\t\treturn \"\", nil\n\t}\n\tc.lockID = \"\"\n\n\tjsonLockInfo := info.Marshal()\n\tresp, err := c.httpRequest(c.LockMethod, c.LockURL, &jsonLockInfo, \"lock\")\n\tif err != nil {\n\t\treturn \"\", err\n\t}\n\tdefer resp.Body.Close()\n","sourceCodeStart":56,"sourceCodeEnd":92,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/http/client.go#L56-L92","documentation":"c.Client.Do(req) failed — the actual HTTP round-trip errored. This is a transport-level failure: DNS resolution error, connection refused, TLS handshake error, read/write timeout, proxy failure, or the server closed the connection mid-request. The '%s' is the operation label ('get state', 'upload state', 'lock', 'unlock', 'delete state'). The retryablehttp client will have already retried up to retry_max times.","triggerScenarios":"Server unreachable (DNS NXDOMAIN, connection refused, network down); TLS certificate verification failure; read/write timeout exceeded; HTTPS_PROXY/HTTP_PROXY pointing at a dead or misconfigured proxy; self-signed server cert without skip_cert_verification or client_ca_certificate_pem.","commonSituations":"Wrong hostname in address; egress firewall blocks the endpoint; server temporarily down; self-signed cert not trusted; corporate proxy env vars incorrect; DNS misconfiguration in the CI runner.","solutions":["Verify connectivity from the same host: curl -v <ADDRESS> (and curl the lock/unlock URLs).","If the server uses a self-signed or private CA, set client_ca_certificate_pem to the CA bundle, or set skip_cert_verification = true only for testing.","Check DNS: nslookup <host> or getent hosts <host>.","Inspect HTTPS_PROXY/HTTP_PROXY/NO_PROXY and confirm the proxy is reachable and allows the endpoint.","Raise retry_max and retry_wait_max to ride out transient outages.","Confirm the server is running and listening on the expected port."],"exampleFix":"// before\naddress = \"https://state.example.invalid/terraform\"\n// after (correct host + trust private CA)\naddress              = \"https://state.example.com/terraform\"\nclient_ca_certificate_pem = file(\"${path.module}/internal-ca.pem\")","handlingStrategy":"retry","validationCode":"# Pre-flight: prove the endpoint is reachable and TLS-valid from this host\ncurl -fsS --connect-timeout 5 -o /dev/null -w 'http=%{http_code}\\n' \"$TF_HTTP_ADDRESS\" \\\n  || { echo \"ERROR: cannot reach $TF_HTTP_ADDRESS (network/DNS/TLS)\"; exit 1; }","typeGuard":null,"tryCatchPattern":"# Terraform has no try/catch; wrap invocations and retry on transient transport errors.\nfor i in 1 2 3; do\n  terraform apply -auto-approve && break\n  rc=$?; echo \"apply failed (rc=$rc), retrying ($i/3)...\"; sleep 5\ndone","preventionTips":["Run a curl probe against address/lock/unlock URLs before terraform init in CI.","For private/self-signed CAs, supply client_ca_certificate_pem rather than disabling verification.","Tune retry_max/retry_wait_max to absorb transient outages.","Verify HTTPS_PROXY/HTTP_PROXY/NO_PROXY are correct for the network path."],"tags":["network","transport","tls","http-backend","timeout"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}