hashicorp/terraform · error

a network issue prevented cloud configuration;

Error message

a network issue prevented cloud configuration; %w

What it means

Thrown during HCP Terraform / Terraform Enterprise service discovery inside discoverTfeURL when the HTTP request to resolve the API service URL fails at the network layer. Terraform wraps the underlying *disco.ErrServiceDiscoveryNetworkRequest with a user-facing message indicating a network problem prevented cloud configuration. This occurs when the test runner resolves the hostname for cloud-backed terraform test execution.

Solutions

  1. Verify connectivity to the hostname: curl -v https://<hostname>/.well-known/terraform.json
  2. Set or correct HTTP_PROXY, HTTPS_PROXY, and NO_PROXY environment variables for proxy environments
  3. Confirm the hostname in your cloud configuration block or TF_CLOUD_HOSTNAME is correct and DNS-resolvable
  4. Retry the command if the failure was transient (intermittent network issues)
Defensive patterns

Strategy: retry

Validate before calling

// Pre-flight connectivity check before running cloud tests
func checkTfeReachable(hostname string) error {
    url := fmt.Sprintf("https://%s/.well-known/terraform.json", hostname)
    client := &http.Client{Timeout: 10 * time.Second}
    resp, err := client.Get(url)
    if err != nil {
        return fmt.Errorf("cannot reach TFC/E host %s: %w", hostname, err)
    }
    defer resp.Body.Close()
    if resp.StatusCode != http.StatusOK {
        return fmt.Errorf("unexpected status %d from %s", resp.StatusCode, url)
    }
    return nil
}

Prevention

When it happens

Trigger: services.Discover(hostname) returns an error assignable to *disco.ErrServiceDiscoveryNetworkRequest. This happens when DNS resolution fails for the TFC/E hostname, the host is unreachable, a proxy blocks the HTTPS request to /.well-known/terraform.json, TLS negotiation fails, or the connection times out.

Common situations: Corporate firewall or proxy blocking outbound HTTPS to app.terraform.io; incorrect or unreachable hostname in a self-hosted TFE installation; DNS misconfiguration; transient network outage; missing HTTP_PROXY/HTTPS_PROXY env vars in proxy environments.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/60151db421ca36cb. Report an issue: GitHub.

Appendix: source

Thrown at internal/cloud/test.go:329

		return moduletest.Pass, diags
	case tfe.TestPending:
		return moduletest.Pending, diags
	case tfe.TestSkip:
		return moduletest.Skip, diags
	default:
		panic("found unrecognized test status: " + run.TestStatus)
	}
}

// discover the TFC/E API service URL
func discoverTfeURL(hostname svchost.Hostname, services *disco.Disco) (*url.URL, error) {
	host, err := services.Discover(hostname)
	if err != nil {
		var serviceDiscoErr *disco.ErrServiceDiscoveryNetworkRequest

		switch {
		case errors.As(err, &serviceDiscoErr):
			err = fmt.Errorf("a network issue prevented cloud configuration; %w", err)
			return nil, err
		default:
			return nil, err
		}
	}

	return host.ServiceURL(tfeServiceID)
}

func (runner *TestSuiteRunner) client(addr tfaddr.Module, id tfe.RegistryModuleID) (*tfe.Client, *tfe.RegistryModule, tfdiags.Diagnostics) {
	var diags tfdiags.Diagnostics

	var client *tfe.Client
	if runner.clientOverride != nil {
		client = runner.clientOverride
	} else {
		service, err := discoverTfeURL(addr.Package.Host, runner.Services)
		if err != nil {

View on GitHub (pinned to d32a084675)