hashicorp/terraform · error
cannot write to temporary file
Error message
cannot write to temporary file %s: %s
What it means
Thrown when f.Write(newSrc) fails while writing the serialized credentials to the temp file. The file was successfully created (TempFile passed) but writing the JSON bytes failed — typically due to disk-full, quota, or an I/O error on the underlying device. The temp file is closed and the deferred cleanup removes it.
Solutions
- Free space in the credentials directory: `df -h <dir>`; remove unneeded files.
- Check user/filesystem quotas if applicable (`quota -u $USER`).
- If on a network filesystem, retry; if persistent, point TF_CLI_CONFIG_FILE / HOME at a local directory.
- Confirm the device is healthy (`dmesg | tail` for I/O errors).
Defensive patterns
Strategy: retry
Validate before calling
func freeSpaceOK(dir string) error {
var s syscall.Statfs_t
if err := syscall.Statfs(dir, &s); err != nil { return err }
if s.Bavail*uint64(s.Bsize) < uint64(1024) {
return fmt.Errorf("insufficient free space in %s", dir)
}
return nil
} Prevention
- Keep free disk space above a small floor in the credentials directory.
- Retry once on transient I/O errors before surfacing to the user.
- Avoid network filesystems for credentials when possible.
When it happens
Trigger: Disk runs out of space mid-write; a disk quota (user or filesystem) is exceeded; the device returns EIO; on some network filesystems the connection drops during write.
Common situations: CI runner out of disk; a small tmpfs mounted at HOME; NFS/CIFS hiccup; a previous near-full condition that this write tips over.
Related errors
- cannot create temporary file to update credentials
- failed to replace with temporary file
- cannot read
- cannot set mode for credentials file
- can not get from Terraform backend configuration
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/c8e08a6ab59802d6.
Report an issue: GitHub.
Appendix: source
Thrown at internal/command/cliconfig/credentials.go:418
return fmt.Errorf("cannot create temporary file to update credentials: %s", err)
}
tmpName := f.Name()
moved := false
defer func(f *os.File, name string) {
// Remove the temporary file if it hasn't been moved yet. We're
// ignoring errors here because there's nothing we can do about
// them anyway.
if !moved {
os.Remove(name)
}
}(f, tmpName)
// Write the credentials to the temporary file, then immediately close
// it, whether or not the write succeeds.
_, err = f.Write(newSrc)
f.Close()
if err != nil {
return fmt.Errorf("cannot write to temporary file %s: %s", tmpName, err)
}
// Temporary file now replaces the original file, as atomically as
// possible. (At the very least, we should not end up with a file
// containing only a partial JSON object.)
err = replacefile.AtomicRename(tmpName, filename)
if err != nil {
return fmt.Errorf("failed to replace %s with temporary file %s: %s", filename, tmpName, err)
}
// Credentials file should be readable only by its owner. (This may
// not be effective on all platforms, but should at least work on
// Unix-like targets and should be harmless elsewhere.)
if err := os.Chmod(filename, 0600); err != nil {
return fmt.Errorf("cannot set mode for credentials file %s: %s", filename, err)
}
moved = trueView on GitHub (pinned to d32a084675)