hashicorp/terraform · error

connection type ' ' not supported

Error message

connection type '%s' not supported

What it means

Returned by the connection-type factory when the connection block's type attribute is set to a value other than 'ssh' or 'winrm' (the only two supported communicators). An empty/omitted type defaults to ssh, so this only fires for an explicitly unrecognized, non-empty type string.

Solutions

  1. Set connection.type to either "ssh" or "winrm" (or omit it to get the ssh default).
  2. For Windows targets use type = "winrm"; for Linux/Unix targets use type = "ssh" or omit.
  3. Remove any leading/trailing whitespace in the type string.

Example fix

// before
connection {
  type     = "winrmm"
  host     = aws_instance.web.public_ip
}

// after
connection {
  type     = "winrm"
  host     = aws_instance.web.public_ip
}
Defensive patterns

Strategy: validation

Validate before calling

# Validate before apply with a quick grep / policy check on connection.type:
# only 'ssh', 'winrm', or unset are allowed.
grep -RnE 'type\s*=\s*"(?!ssh|winrm)' *.tf && echo 'unsupported connection type' || echo ok

Type guard

# HCL: there is no native enum, but a sentinel check via locals:
locals {
  allowed_conn_types = toset(["ssh", "winrm"])
  # use only in modules that validate inputs; connection.type itself can't
  # be guard-checked inline without a custom validation block in a variable.
}

Prevention

When it happens

Trigger: A provisioner connection { type = "..." } block with a typo or unsupported value such as 'telnet', 'rdp', 'bash', or 'winrmm'. Any non-empty value that is not exactly 'ssh' or 'winrm' hits the default branch.

Common situations: Copy-paste from documentation of a different tool; typo like 'winrmm' or 'ssh2'; attempting to use a connection type that the local Terraform build does not support (older builds predate winrm).

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/2c9fcf4f37495d95. Report an issue: GitHub.

Appendix: source

Thrown at internal/communicator/communicator.go:70

func New(v cty.Value) (Communicator, error) {
	v, err := shared.ConnectionBlockSupersetSchema.CoerceValue(v)
	if err != nil {
		return nil, err
	}

	typeVal := v.GetAttr("type")
	connType := ""
	if !typeVal.IsNull() {
		connType = typeVal.AsString()
	}

	switch connType {
	case "ssh", "": // The default connection type is ssh, so if connType is empty use ssh
		return ssh.New(v)
	case "winrm":
		return winrm.New(v)
	default:
		return nil, fmt.Errorf("connection type '%s' not supported", connType)
	}
}

// maxBackoffDelay is the maximum delay between retry attempts
var maxBackoffDelay = 20 * time.Second
var initialBackoffDelay = time.Second

// in practice we want to abort the retry asap, but for tests we need to
// synchronize the return.
var retryTestWg *sync.WaitGroup

// Fatal is an interface that error values can return to halt Retry
type Fatal interface {
	FatalError() error
}

// Retry retries the function f until it returns a nil error, a Fatal error, or
// the context expires.

View on GitHub (pinned to d32a084675)