hashicorp/terraform · error
Error connecting to proxy
Error message
Error connecting to proxy: %s
What it means
Returned when newHttpProxyConn fails while establishing the bastion hop through an HTTP CONNECT proxy. The proxy connection to the bastion address (bAddr) could not be opened: proxy unreachable, refused, auth failed, or the CONNECT tunne failed with a non-200 (the latter is wrapped from http_proxy.go).
Solutions
- Verify proxy_url is reachable and accepts CONNECT to the bastion host:port (test with curl -x).
- Provide proxy credentials in the URL if required: proxy_url = "http://user:pass@proxy:3128".
- Confirm the bastion address and port in bastion_host/bastion_port are correct.
- If the proxy returns a status code, see the wrapped 'Connection Error: StatusCode' message (797) for the code.
Example fix
// before
connection {
host = "10.0.0.5"
bastion_host = "bastion.example.com"
proxy_url = "http://proxy.corp:3128"
}
// after
connection {
host = "10.0.0.5"
bastion_host = "bastion.example.com"
proxy_url = "http://user:pass@proxy.corp:3128"
} Defensive patterns
Strategy: validation
Validate before calling
# Before apply, verify the proxy accepts CONNECT to the bastion: # curl -v -x http://<proxy> --proxytunnel https://<bastion_host>:<bastion_port> # Provide creds in the URL if required by the proxy.
Try / catch
// In Go, classify proxy-connect failure distinctly from SSH failures:
if strings.Contains(err.Error(), "Error connecting to proxy") {
return fmt.Errorf("HTTP proxy refused CONNECT to bastion; check proxy_url/creds: %w", err)
} Prevention
- Test the proxy CONNECT path manually before apply.
- Embed credentials in proxy_url when the proxy requires auth.
- Whitelist bastion_host:bastion_port on the proxy.
When it happens
Trigger: connection.bastion_host is set together with a proxy_url; the proxy at proxy_url is down, refuses CONNECT to the bastion:port, requires auth that was not supplied, or returns a non-200 status. Also fires if the proxy URL is malformed.
Common situations: Corporate proxy requiring credentials not set in proxy_url; typo in proxy_url; proxy allowing only whitelisted destinations that exclude the bastion; proxy behind a flaky link.
Related errors
- Connection Error: StatusCode
- Error connecting to bastion
- Error creating new client connection via proxy
- connection type ' ' not supported
- host for provisioner cannot be empty
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/3fc5ca0bdd180651.
Report an issue: GitHub.
Appendix: source
Thrown at internal/communicator/ssh/communicator.go:846
addr string,
p *proxyInfo) func() (net.Conn, error) {
return func() (net.Conn, error) {
log.Printf("[DEBUG] Connecting to bastion: %s", bAddr)
var bastion *ssh.Client
var err error
// Wrap connection to bastion server if proxy server is configured
if p != nil {
var pConn net.Conn
var bConn ssh.Conn
var bChans <-chan ssh.NewChannel
var bReq <-chan *ssh.Request
RegisterDialerType()
pConn, err = newHttpProxyConn(p, bAddr)
if err != nil {
return nil, fmt.Errorf("Error connecting to proxy: %s", err)
}
bConn, bChans, bReq, err = ssh.NewClientConn(pConn, bAddr, bConf)
if err != nil {
return nil, fmt.Errorf("Error creating new client connection via proxy: %s", err)
}
bastion = ssh.NewClient(bConn, bChans, bReq)
} else {
bastion, err = ssh.Dial(bProto, bAddr, bConf)
}
if err != nil {
return nil, fmt.Errorf("Error connecting to bastion: %s", err)
}
log.Printf("[DEBUG] Connecting via bastion (%s) to host: %s", bAddr, addr)View on GitHub (pinned to d32a084675)