hashicorp/terraform · error

Failed to

Error message

Failed to %s: %v

What it means

c.Client.Do(req) failed — the actual HTTP round-trip errored. This is a transport-level failure: DNS resolution error, connection refused, TLS handshake error, read/write timeout, proxy failure, or the server closed the connection mid-request. The '%s' is the operation label ('get state', 'upload state', 'lock', 'unlock', 'delete state'). The retryablehttp client will have already retried up to retry_max times.

Solutions

  1. Verify connectivity from the same host: curl -v <ADDRESS> (and curl the lock/unlock URLs).
  2. If the server uses a self-signed or private CA, set client_ca_certificate_pem to the CA bundle, or set skip_cert_verification = true only for testing.
  3. Check DNS: nslookup <host> or getent hosts <host>.
  4. Inspect HTTPS_PROXY/HTTP_PROXY/NO_PROXY and confirm the proxy is reachable and allows the endpoint.
  5. Raise retry_max and retry_wait_max to ride out transient outages.
  6. Confirm the server is running and listening on the expected port.

Example fix

// before
address = "https://state.example.invalid/terraform"
// after (correct host + trust private CA)
address              = "https://state.example.com/terraform"
client_ca_certificate_pem = file("${path.module}/internal-ca.pem")
Defensive patterns

Strategy: retry

Validate before calling

# Pre-flight: prove the endpoint is reachable and TLS-valid from this host
curl -fsS --connect-timeout 5 -o /dev/null -w 'http=%{http_code}\n' "$TF_HTTP_ADDRESS" \
  || { echo "ERROR: cannot reach $TF_HTTP_ADDRESS (network/DNS/TLS)"; exit 1; }

Try / catch

# Terraform has no try/catch; wrap invocations and retry on transient transport errors.
for i in 1 2 3; do
  terraform apply -auto-approve && break
  rc=$?; echo "apply failed (rc=$rc), retrying ($i/3)..."; sleep 5
done

Prevention

When it happens

Trigger: Server unreachable (DNS NXDOMAIN, connection refused, network down); TLS certificate verification failure; read/write timeout exceeded; HTTPS_PROXY/HTTP_PROXY pointing at a dead or misconfigured proxy; self-signed server cert without skip_cert_verification or client_ca_certificate_pem.

Common situations: Wrong hostname in address; egress firewall blocks the endpoint; server temporarily down; self-signed cert not trusted; corporate proxy env vars incorrect; DNS misconfiguration in the CI runner.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/f9e49900a4a7983a. Report an issue: GitHub.

Appendix: source

Thrown at internal/backend/remote-state/http/client.go:74

	if c.Username != "" {
		req.SetBasicAuth(c.Username, c.Password)
	}

	// Work with data/body
	if data != nil {
		req.Header.Set("Content-Type", "application/json")
		req.ContentLength = int64(len(*data))

		// Generate the MD5
		hash := md5.Sum(*data)
		b64 := base64.StdEncoding.EncodeToString(hash[:])
		req.Header.Set("Content-MD5", b64)
	}

	// Make the request
	resp, err := c.Client.Do(req)
	if err != nil {
		return nil, fmt.Errorf("Failed to %s: %v", what, err)
	}

	return resp, nil
}

func (c *httpClient) Lock(info *statemgr.LockInfo) (string, error) {
	if c.LockURL == nil {
		return "", nil
	}
	c.lockID = ""

	jsonLockInfo := info.Marshal()
	resp, err := c.httpRequest(c.LockMethod, c.LockURL, &jsonLockInfo, "lock")
	if err != nil {
		return "", err
	}
	defer resp.Body.Close()

View on GitHub (pinned to d32a084675)