hashicorp/terraform · error

Error connecting to proxy

Error message

Error connecting to proxy: %s

What it means

Returned when newHttpProxyConn fails while establishing the bastion hop through an HTTP CONNECT proxy. The proxy connection to the bastion address (bAddr) could not be opened: proxy unreachable, refused, auth failed, or the CONNECT tunne failed with a non-200 (the latter is wrapped from http_proxy.go).

Solutions

  1. Verify proxy_url is reachable and accepts CONNECT to the bastion host:port (test with curl -x).
  2. Provide proxy credentials in the URL if required: proxy_url = "http://user:pass@proxy:3128".
  3. Confirm the bastion address and port in bastion_host/bastion_port are correct.
  4. If the proxy returns a status code, see the wrapped 'Connection Error: StatusCode' message (797) for the code.

Example fix

// before
connection {
  host          = "10.0.0.5"
  bastion_host  = "bastion.example.com"
  proxy_url     = "http://proxy.corp:3128"
}

// after
connection {
  host          = "10.0.0.5"
  bastion_host  = "bastion.example.com"
  proxy_url     = "http://user:pass@proxy.corp:3128"
}
Defensive patterns

Strategy: validation

Validate before calling

# Before apply, verify the proxy accepts CONNECT to the bastion:
#   curl -v -x http://<proxy> --proxytunnel https://<bastion_host>:<bastion_port>
# Provide creds in the URL if required by the proxy.

Try / catch

// In Go, classify proxy-connect failure distinctly from SSH failures:
if strings.Contains(err.Error(), "Error connecting to proxy") {
    return fmt.Errorf("HTTP proxy refused CONNECT to bastion; check proxy_url/creds: %w", err)
}

Prevention

When it happens

Trigger: connection.bastion_host is set together with a proxy_url; the proxy at proxy_url is down, refuses CONNECT to the bastion:port, requires auth that was not supplied, or returns a non-200 status. Also fires if the proxy URL is malformed.

Common situations: Corporate proxy requiring credentials not set in proxy_url; typo in proxy_url; proxy allowing only whitelisted destinations that exclude the bastion; proxy behind a flaky link.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/3fc5ca0bdd180651. Report an issue: GitHub.

Appendix: source

Thrown at internal/communicator/ssh/communicator.go:846

	addr string,
	p *proxyInfo) func() (net.Conn, error) {
	return func() (net.Conn, error) {
		log.Printf("[DEBUG] Connecting to bastion: %s", bAddr)
		var bastion *ssh.Client
		var err error

		// Wrap connection to bastion server if proxy server is configured
		if p != nil {
			var pConn net.Conn
			var bConn ssh.Conn
			var bChans <-chan ssh.NewChannel
			var bReq <-chan *ssh.Request

			RegisterDialerType()
			pConn, err = newHttpProxyConn(p, bAddr)

			if err != nil {
				return nil, fmt.Errorf("Error connecting to proxy: %s", err)
			}

			bConn, bChans, bReq, err = ssh.NewClientConn(pConn, bAddr, bConf)

			if err != nil {
				return nil, fmt.Errorf("Error creating new client connection via proxy: %s", err)
			}

			bastion = ssh.NewClient(bConn, bChans, bReq)
		} else {
			bastion, err = ssh.Dial(bProto, bAddr, bConf)
		}

		if err != nil {
			return nil, fmt.Errorf("Error connecting to bastion: %s", err)
		}

		log.Printf("[DEBUG] Connecting via bastion (%s) to host: %s", bAddr, addr)

View on GitHub (pinned to d32a084675)