hashicorp/terraform · error

Error creating temporary file for upload

Error message

Error creating temporary file for upload: %s

What it means

Raised in scpUploadFile when ioutil.TempFile fails to create the staging file used to determine length for zero-size inputs (SCP is length-prefixed). The temp file lives in the OS default temp dir (os.TempDir()). A failure here is an environment problem on the Terraform-running machine, not the remote host.

Solutions

  1. Ensure TMPDIR/TEMP is writable and has free space (df -h $TMPDIR; touch $TMPDIR/tf-test).
  2. Free disk space or raise the container's tmpfs size.
  3. Raise the open-file ulimit if 'too many open files' appears in the wrapped error.
  4. If possible, avoid uploading genuinely empty files (omit the resource or supply minimal content).

Example fix

// before
provisioner "file" {
  source      = "empty.txt"   // 0-byte file
  destination = "/etc/app/empty.txt"
}

// after
provisioner "file" {
  source      = "config.txt"  // non-empty
  destination = "/etc/app/config.txt"
}
Defensive patterns

Strategy: validation

Validate before calling

# Before apply, confirm TMPDIR is writable with free space:
#   df -h "${TMPDIR:-/tmp}" && touch "${TMPDIR:-/tmp}/tf-probe" && rm "${TMPDIR:-/tmp}/tf-probe"
# In CI, mount a writable tmpfs/emptyDir of adequate size.

Try / catch

// In Go, if you control the upload path, skip staging for known sizes:
if size > 0 {
    return scpUploadFile(dst, src, w, r, size)
}
// otherwise surface tempfile errors with environment guidance:
if err != nil && strings.Contains(err.Error(), "temporary file for upload") {
    return fmt.Errorf("cannot stage upload; check TMPDIR/space/ulimit: %w", err)
}

Prevention

When it happens

Trigger: The local temp directory does not exist or is not writable, the disk is full, the process hit an open-file limit, or a security policy blocks temp file creation. Triggered specifically when uploading a zero-length file (size == 0) so Terraform must buffer it to compute length.

Common situations: Running Terraform in a container/CI with a read-only or size-limited TMPDIR; disk pressure on the runner; ulimit -n too low; SELinux denying tempfile creation.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/4598a213a09538dc. Report an issue: GitHub.

Appendix: source

Thrown at internal/communicator/ssh/communicator.go:659

		return errors.New(string(message))
	}

	return nil
}

var testUploadSizeHook func(size int64)

func scpUploadFile(dst string, src io.Reader, w io.Writer, r *bufio.Reader, size int64) error {
	if testUploadSizeHook != nil {
		testUploadSizeHook(size)
	}

	if size == 0 {
		// Create a temporary file where we can copy the contents of the src
		// so that we can determine the length, since SCP is length-prefixed.
		tf, err := ioutil.TempFile("", "terraform-upload")
		if err != nil {
			return fmt.Errorf("Error creating temporary file for upload: %s", err)
		}
		defer os.Remove(tf.Name())
		defer tf.Close()

		log.Println("[DEBUG] Copying input data into temporary file so we can read the length")
		if _, err := io.Copy(tf, src); err != nil {
			return err
		}

		// Sync the file so that the contents are definitely on disk, then
		// read the length of it.
		if err := tf.Sync(); err != nil {
			return fmt.Errorf("Error creating temporary file for upload: %s", err)
		}

		// Seek the file to the beginning so we can re-read all of it
		if _, err := tf.Seek(0, 0); err != nil {
			return fmt.Errorf("Error creating temporary file for upload: %s", err)

View on GitHub (pinned to d32a084675)