hashicorp/terraform · error

cannot write to temporary file

Error message

cannot write to temporary file %s: %s

What it means

Thrown when f.Write(newSrc) fails while writing the serialized credentials to the temp file. The file was successfully created (TempFile passed) but writing the JSON bytes failed — typically due to disk-full, quota, or an I/O error on the underlying device. The temp file is closed and the deferred cleanup removes it.

Solutions

  1. Free space in the credentials directory: `df -h <dir>`; remove unneeded files.
  2. Check user/filesystem quotas if applicable (`quota -u $USER`).
  3. If on a network filesystem, retry; if persistent, point TF_CLI_CONFIG_FILE / HOME at a local directory.
  4. Confirm the device is healthy (`dmesg | tail` for I/O errors).
Defensive patterns

Strategy: retry

Validate before calling

func freeSpaceOK(dir string) error {
    var s syscall.Statfs_t
    if err := syscall.Statfs(dir, &s); err != nil { return err }
    if s.Bavail*uint64(s.Bsize) < uint64(1024) {
        return fmt.Errorf("insufficient free space in %s", dir)
    }
    return nil
}

Prevention

When it happens

Trigger: Disk runs out of space mid-write; a disk quota (user or filesystem) is exceeded; the device returns EIO; on some network filesystems the connection drops during write.

Common situations: CI runner out of disk; a small tmpfs mounted at HOME; NFS/CIFS hiccup; a previous near-full condition that this write tips over.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/c8e08a6ab59802d6. Report an issue: GitHub.

Appendix: source

Thrown at internal/command/cliconfig/credentials.go:418

			return fmt.Errorf("cannot create temporary file to update credentials: %s", err)
		}
		tmpName := f.Name()
		moved := false
		defer func(f *os.File, name string) {
			// Remove the temporary file if it hasn't been moved yet. We're
			// ignoring errors here because there's nothing we can do about
			// them anyway.
			if !moved {
				os.Remove(name)
			}
		}(f, tmpName)

		// Write the credentials to the temporary file, then immediately close
		// it, whether or not the write succeeds.
		_, err = f.Write(newSrc)
		f.Close()
		if err != nil {
			return fmt.Errorf("cannot write to temporary file %s: %s", tmpName, err)
		}

		// Temporary file now replaces the original file, as atomically as
		// possible. (At the very least, we should not end up with a file
		// containing only a partial JSON object.)
		err = replacefile.AtomicRename(tmpName, filename)
		if err != nil {
			return fmt.Errorf("failed to replace %s with temporary file %s: %s", filename, tmpName, err)
		}

		// Credentials file should be readable only by its owner. (This may
		// not be effective on all platforms, but should at least work on
		// Unix-like targets and should be harmless elsewhere.)
		if err := os.Chmod(filename, 0600); err != nil {
			return fmt.Errorf("cannot set mode for credentials file %s: %s", filename, err)
		}

		moved = true

View on GitHub (pinned to d32a084675)