hashicorp/terraform · error
a network issue prevented cloud configuration;
Error message
a network issue prevented cloud configuration; %w
What it means
Thrown during HCP Terraform / Terraform Enterprise service discovery inside discoverTfeURL when the HTTP request to resolve the API service URL fails at the network layer. Terraform wraps the underlying *disco.ErrServiceDiscoveryNetworkRequest with a user-facing message indicating a network problem prevented cloud configuration. This occurs when the test runner resolves the hostname for cloud-backed terraform test execution.
Solutions
- Verify connectivity to the hostname: curl -v https://<hostname>/.well-known/terraform.json
- Set or correct HTTP_PROXY, HTTPS_PROXY, and NO_PROXY environment variables for proxy environments
- Confirm the hostname in your cloud configuration block or TF_CLOUD_HOSTNAME is correct and DNS-resolvable
- Retry the command if the failure was transient (intermittent network issues)
Defensive patterns
Strategy: retry
Validate before calling
// Pre-flight connectivity check before running cloud tests
func checkTfeReachable(hostname string) error {
url := fmt.Sprintf("https://%s/.well-known/terraform.json", hostname)
client := &http.Client{Timeout: 10 * time.Second}
resp, err := client.Get(url)
if err != nil {
return fmt.Errorf("cannot reach TFC/E host %s: %w", hostname, err)
}
defer resp.Body.Close()
if resp.StatusCode != http.StatusOK {
return fmt.Errorf("unexpected status %d from %s", resp.StatusCode, url)
}
return nil
} Prevention
- Verify the TFC/E hostname is DNS-resolvable and reachable before running terraform test
- Configure HTTP_PROXY, HTTPS_PROXY, and NO_PROXY in corporate network environments
- Use TF_CLOUD_HOSTNAME only when pointing to a known reachable TFE instance
- Add retry logic in CI for transient network failures during cloud operations
When it happens
Trigger: services.Discover(hostname) returns an error assignable to *disco.ErrServiceDiscoveryNetworkRequest. This happens when DNS resolution fails for the TFC/E hostname, the host is unreachable, a proxy blocks the HTTPS request to /.well-known/terraform.json, TLS negotiation fails, or the connection times out.
Common situations: Corporate firewall or proxy blocking outbound HTTPS to app.terraform.io; incorrect or unreachable hostname in a self-hosted TFE installation; DNS misconfiguration; transient network outage; missing HTTP_PROXY/HTTPS_PROXY env vars in proxy environments.
Related errors
- a network issue prevented cloud configuration;
- approved using the UI or API
- discarded using the UI or API
- Error downloading state
- error downloading state
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/60151db421ca36cb.
Report an issue: GitHub.
Appendix: source
Thrown at internal/cloud/test.go:329
return moduletest.Pass, diags
case tfe.TestPending:
return moduletest.Pending, diags
case tfe.TestSkip:
return moduletest.Skip, diags
default:
panic("found unrecognized test status: " + run.TestStatus)
}
}
// discover the TFC/E API service URL
func discoverTfeURL(hostname svchost.Hostname, services *disco.Disco) (*url.URL, error) {
host, err := services.Discover(hostname)
if err != nil {
var serviceDiscoErr *disco.ErrServiceDiscoveryNetworkRequest
switch {
case errors.As(err, &serviceDiscoErr):
err = fmt.Errorf("a network issue prevented cloud configuration; %w", err)
return nil, err
default:
return nil, err
}
}
return host.ServiceURL(tfeServiceID)
}
func (runner *TestSuiteRunner) client(addr tfaddr.Module, id tfe.RegistryModuleID) (*tfe.Client, *tfe.RegistryModule, tfdiags.Diagnostics) {
var diags tfdiags.Diagnostics
var client *tfe.Client
if runner.clientOverride != nil {
client = runner.clientOverride
} else {
service, err := discoverTfeURL(addr.Package.Host, runner.Services)
if err != nil {View on GitHub (pinned to d32a084675)