hashicorp/terraform · error
failed to determine request credentials
Error message
failed to determine request credentials: %s
What it means
During request building, the mirror client calls `mirrorHostCredentials()` to attach host credentials. If that lookup itself errors (see 895: invalid base URL, or the credentials source fails for the host), the error is wrapped with this prefix.
Solutions
- Fix the mirror base URL so `mirrorHost` succeeds.
- Verify credentials configuration for the mirror hostname in the CLI config / credentials helper.
- Run `terraform providers mirror` or a manual `curl` with the same creds to isolate auth vs URL issues.
- Remove the credentials block temporarily to see if the URL itself is the problem.
Example fix
// before: creds block references unknown host
credentials "mirror.local" { token = "..." } // but url is https://other.local/
// after: align URL and creds
provider_installation {
network_mirror { url = "https://mirror.local/" }
}
credentials "mirror.local" { token = "..." } Defensive patterns
Strategy: validation
Validate before calling
// Pre-flight: confirm creds resolve before the request loop
if creds, err := s.mirrorHostCredentials(); err != nil {
return fmt.Errorf("mirror credentials unavailable: %w", err)
} else if creds == nil {
log.Printf("[INFO] no mirror credentials configured; proceeding anonymous")
} Try / catch
creds, err := s.mirrorHostCredentials()
if err != nil {
// retry without creds as anonymous fallback
log.Printf("[WARN] mirror creds failed (%s); retrying anonymous", err)
creds = nil
} Prevention
- Validate credentials for the mirror hostname with `terraform login <host>` (where applicable).
- Keep credentials helper plugin versions aligned.
- Test credentials with a direct `curl -u` before wiring them into Terraform.
- Log credential resolution failures distinctly from request failures.
When it happens
Trigger: `s.mirrorHostCredentials()` returns an error inside the GET helper; wrapped at http_mirror_source.go:341.
Common situations: Same root causes as 895 (bad base URL) plus: the configured credentials source for the mirror hostname fails (bad token, unreachable `cli_credentials_host`); credentials helper plugin error.
Related errors
- invalid provider mirror base URL
- can not get from Terraform backend configuration
- cannot create temporary file to update credentials
- cannot read
- credentials file has invalid value for "credentials"…
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/5280b0fed5c7b060.
Report an issue: GitHub.
Appendix: source
Thrown at internal/getproviders/http_mirror_source.go:341
// produced the returned response, possibly after following some redirects.
func (s *HTTPMirrorSource) get(ctx context.Context, relativePath string) (statusCode int, body io.ReadCloser, finalURL *url.URL, error error) {
endpointPath, err := url.Parse(relativePath)
if err != nil {
// Should never happen because the caller should validate all of the
// components it's including in the path.
return 0, nil, nil, err
}
endpointURL := s.baseURL.ResolveReference(endpointPath)
req, err := retryablehttp.NewRequest("GET", endpointURL.String(), nil)
if err != nil {
return 0, nil, endpointURL, err
}
req = req.WithContext(ctx)
req.Request.Header.Set(terraformVersionHeader, version.String())
creds, err := s.mirrorHostCredentials()
if err != nil {
return 0, nil, endpointURL, fmt.Errorf("failed to determine request credentials: %s", err)
}
if creds != nil {
// Note that if the initial requests gets redirected elsewhere
// then the credentials will still be included in the new request,
// even if they are on a different hostname. This is intentional
// and consistent with how we handle credentials for other
// Terraform-native services, because the user model is to configure
// credentials for the "friendly hostname" they configured, not for
// whatever hostname ends up ultimately serving the request as an
// implementation detail.
creds.PrepareRequest(req.Request)
}
resp, err := s.httpClient.Do(req)
if err != nil {
return 0, nil, endpointURL, err
}
defer func() {View on GitHub (pinned to d32a084675)