hashicorp/terraform · error

Connection Error: StatusCode

Error message

Connection Error: StatusCode: %d

What it means

Returned by the HTTP-proxy CONNECT helper when the proxy responded with a status code other than 200 OK. The proxy connection is closed and the numeric status is returned. This is the proxy's response to the CONNECT request, surfaced before any SSH traffic — i.e. the proxy refused to tunnel to the requested host:port.

Solutions

  1. Map the status code: 407 -> add proxy credentials; 403 -> allowlist the destination; 502/503 -> fix proxy-to-bastion reachability.
  2. Provide credentials in proxy_url: "http://user:pass@proxy:3128".
  3. Ask the proxy admin to allow CONNECT to bastion_host:bastion_port.
  4. Verify the bastion host/port are resolvable and reachable from the proxy itself.

Example fix

// before
connection {
  host         = "10.0.0.5"
  bastion_host = "bastion.example.com"
  proxy_url    = "http://proxy.corp:3128"   // returns 407
}

// after
connection {
  host         = "10.0.0.5"
  bastion_host = "bastion.example.com"
  proxy_url    = "http://svc:secret@proxy.corp:3128"
}
Defensive patterns

Strategy: try-catch

Validate before calling

# Decode the status code from the message and act:
#   407 -> proxy auth; 403 -> policy/allowlist; 502/503 -> upstream reachability.
# Test CONNECT manually:
#   curl -v -x http://<proxy> --proxytunnel https://<bastion>:<port>

Try / catch

// In Go, parse the status code from the message to drive behavior:
if strings.Contains(err.Error(), "Connection Error: StatusCode:") {
    code := parseStatusCode(err.Error()) // extract the %d
    switch code {
    case 407: return fmt.Errorf("proxy auth required; add creds to proxy_url: %w", err)
    case 403: return fmt.Errorf("proxy denied CONNECT; allowlist destination: %w", err)
    default:  return fmt.Errorf("proxy CONNECT failed with %d: %w", code, err)
    }
}

Prevention

When it happens

Trigger: Proxy returns 407 (auth required / bad creds), 403 (forbidden / policy), 502/503 (proxy can't reach upstream), or 405 (CONNECT not allowed on this endpoint). Triggered only when proxy_url is set and the proxy is reachable.

Common situations: 407 Proxy Authentication Required with missing/wrong proxy_url credentials; 403 because the destination is not on the proxy's allowlist; 502 when the proxy cannot resolve/reach the bastion; corporate Zabbix/Squid policies blocking CONNECT to non-standard ports.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/2279bcc6a9c26d0a. Report an issue: GitHub.

Appendix: source

Thrown at internal/communicator/ssh/http_proxy.go:111

	// Writes the request in the form expected by an HTTP proxy.
	err = req.Write(c)
	if err != nil {
		c.Close()
		return nil, err
	}

	res, err := http.ReadResponse(bufio.NewReader(c), req)

	if err != nil {
		c.Close()
		return nil, err
	}

	res.Body.Close()

	if res.StatusCode != http.StatusOK {
		c.Close()
		return nil, fmt.Errorf("Connection Error: StatusCode: %d", res.StatusCode)
	}

	return c, nil
}

// NewHttpProxyDialer generate Http Proxy Dialer
func newHttpProxyDialer(u *url.URL, forward proxy.Dialer) (proxy.Dialer, error) {
	var proxyUserName, proxyPassword string
	if u.User != nil {
		proxyUserName = u.User.Username()
		proxyPassword, _ = u.User.Password()
	}

	pd := &proxyDialer{
		proxy:   *newProxyInfo(u.Host, u.Scheme, proxyUserName, proxyPassword),
		forward: forward,
	}

View on GitHub (pinned to d32a084675)