hashicorp/terraform · error
Connection Error: StatusCode
Error message
Connection Error: StatusCode: %d
What it means
Returned by the HTTP-proxy CONNECT helper when the proxy responded with a status code other than 200 OK. The proxy connection is closed and the numeric status is returned. This is the proxy's response to the CONNECT request, surfaced before any SSH traffic — i.e. the proxy refused to tunnel to the requested host:port.
Solutions
- Map the status code: 407 -> add proxy credentials; 403 -> allowlist the destination; 502/503 -> fix proxy-to-bastion reachability.
- Provide credentials in proxy_url: "http://user:pass@proxy:3128".
- Ask the proxy admin to allow CONNECT to bastion_host:bastion_port.
- Verify the bastion host/port are resolvable and reachable from the proxy itself.
Example fix
// before
connection {
host = "10.0.0.5"
bastion_host = "bastion.example.com"
proxy_url = "http://proxy.corp:3128" // returns 407
}
// after
connection {
host = "10.0.0.5"
bastion_host = "bastion.example.com"
proxy_url = "http://svc:secret@proxy.corp:3128"
} Defensive patterns
Strategy: try-catch
Validate before calling
# Decode the status code from the message and act: # 407 -> proxy auth; 403 -> policy/allowlist; 502/503 -> upstream reachability. # Test CONNECT manually: # curl -v -x http://<proxy> --proxytunnel https://<bastion>:<port>
Try / catch
// In Go, parse the status code from the message to drive behavior:
if strings.Contains(err.Error(), "Connection Error: StatusCode:") {
code := parseStatusCode(err.Error()) // extract the %d
switch code {
case 407: return fmt.Errorf("proxy auth required; add creds to proxy_url: %w", err)
case 403: return fmt.Errorf("proxy denied CONNECT; allowlist destination: %w", err)
default: return fmt.Errorf("proxy CONNECT failed with %d: %w", code, err)
}
} Prevention
- Embed proxy credentials in proxy_url when the proxy requires auth.
- Ask proxy admins to allowlist CONNECT to bastion_host:bastion_port.
- Confirm the proxy can resolve and reach the bastion upstream.
When it happens
Trigger: Proxy returns 407 (auth required / bad creds), 403 (forbidden / policy), 502/503 (proxy can't reach upstream), or 405 (CONNECT not allowed on this endpoint). Triggered only when proxy_url is set and the proxy is reachable.
Common situations: 407 Proxy Authentication Required with missing/wrong proxy_url credentials; 403 because the destination is not on the proxy's allowlist; 502 when the proxy cannot resolve/reach the bastion; corporate Zabbix/Squid policies blocking CONNECT to non-standard ports.
Related errors
- Error connecting to proxy
- Error creating new client connection via proxy
- SSH authentication failed
- Cannot quote scp command, target platform unknown
- connection type ' ' not supported
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/2279bcc6a9c26d0a.
Report an issue: GitHub.
Appendix: source
Thrown at internal/communicator/ssh/http_proxy.go:111
// Writes the request in the form expected by an HTTP proxy.
err = req.Write(c)
if err != nil {
c.Close()
return nil, err
}
res, err := http.ReadResponse(bufio.NewReader(c), req)
if err != nil {
c.Close()
return nil, err
}
res.Body.Close()
if res.StatusCode != http.StatusOK {
c.Close()
return nil, fmt.Errorf("Connection Error: StatusCode: %d", res.StatusCode)
}
return c, nil
}
// NewHttpProxyDialer generate Http Proxy Dialer
func newHttpProxyDialer(u *url.URL, forward proxy.Dialer) (proxy.Dialer, error) {
var proxyUserName, proxyPassword string
if u.User != nil {
proxyUserName = u.User.Username()
proxyPassword, _ = u.User.Password()
}
pd := &proxyDialer{
proxy: *newProxyInfo(u.Host, u.Scheme, proxyUserName, proxyPassword),
forward: forward,
}
View on GitHub (pinned to d32a084675)