hashicorp/terraform · error

Error creating new client connection via proxy

Error message

Error creating new client connection via proxy: %s

What it means

Returned when ssh.NewClientConn fails over the already-established HTTP proxy tunnel to the bastion. The proxy CONNECT succeeded (otherwise 793 would fire) but the SSH handshake to the bastion itself failed. Identical class of failure as the direct SSH auth error (784) but scoped to the bastion leg.

Solutions

  1. Test the bastion directly through the proxy: ssh -o ProxyCommand='...' <bastion_user>@<bastion_host>.
  2. Confirm bastion_user and bastion_private_key/bastion_password are correct for the bastion (separate from the target host creds).
  3. Allow more time via connection.timeout for a bastion that boots slowly.
  4. Check the wrapped %s for the precise SSH handshake failure.

Example fix

// before
connection {
  host               = "10.0.0.5"
  user               = "appuser"
  bastion_host       = "bastion.example.com"
  bastion_user       = "appuser"   // wrong for bastion
  bastion_private_key = file("~/.ssh/app-key")
}

// after
connection {
  host               = "10.0.0.5"
  user               = "appuser"
  bastion_host       = "bastion.example.com"
  bastion_user       = "devops"
  bastion_private_key = file("~/.ssh/bastion-key")
}
Defensive patterns

Strategy: validation

Validate before calling

# Test SSH to the bastion through the proxy before apply:
#   ssh -o ProxyCommand='nc -X connect -x proxy:3128 %h %p' <bastion_user>@<bastion_host>
# Confirm bastion_user/bastion_private_key are correct for the bastion.

Try / catch

// In Go, separate bastion-handshake failure from target-handshake failure:
if strings.Contains(err.Error(), "client connection via proxy") {
    return fmt.Errorf("bastion SSH handshake via proxy failed; check bastion creds: %w", err)
}

Prevention

When it happens

Trigger: Wrong bastion user/key/password, host key verification failure, algorithm/KEX mismatch with the bastion sshd, or the bastion's sshd not yet ready. The proxy tunnel is up but the SSH protocol exchange to the bastion errors.

Common situations: bastion_user/bastion_private_key pointing at the wrong identity; bastion_user default not valid for that bastion; hardened bastion sshd disabling the negotiated ciphers; freshly-booted bastion not yet serving SSH.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/46d5bb824458902d. Report an issue: GitHub.

Appendix: source

Thrown at internal/communicator/ssh/communicator.go:852

		// Wrap connection to bastion server if proxy server is configured
		if p != nil {
			var pConn net.Conn
			var bConn ssh.Conn
			var bChans <-chan ssh.NewChannel
			var bReq <-chan *ssh.Request

			RegisterDialerType()
			pConn, err = newHttpProxyConn(p, bAddr)

			if err != nil {
				return nil, fmt.Errorf("Error connecting to proxy: %s", err)
			}

			bConn, bChans, bReq, err = ssh.NewClientConn(pConn, bAddr, bConf)

			if err != nil {
				return nil, fmt.Errorf("Error creating new client connection via proxy: %s", err)
			}

			bastion = ssh.NewClient(bConn, bChans, bReq)
		} else {
			bastion, err = ssh.Dial(bProto, bAddr, bConf)
		}

		if err != nil {
			return nil, fmt.Errorf("Error connecting to bastion: %s", err)
		}

		log.Printf("[DEBUG] Connecting via bastion (%s) to host: %s", bAddr, addr)
		conn, err := bastion.Dial(proto, addr)
		if err != nil {
			bastion.Close()
			return nil, err
		}

View on GitHub (pinned to d32a084675)