hashicorp/terraform · error
Failed to
Error message
Failed to %s: %v
What it means
c.Client.Do(req) failed — the actual HTTP round-trip errored. This is a transport-level failure: DNS resolution error, connection refused, TLS handshake error, read/write timeout, proxy failure, or the server closed the connection mid-request. The '%s' is the operation label ('get state', 'upload state', 'lock', 'unlock', 'delete state'). The retryablehttp client will have already retried up to retry_max times.
Solutions
- Verify connectivity from the same host: curl -v <ADDRESS> (and curl the lock/unlock URLs).
- If the server uses a self-signed or private CA, set client_ca_certificate_pem to the CA bundle, or set skip_cert_verification = true only for testing.
- Check DNS: nslookup <host> or getent hosts <host>.
- Inspect HTTPS_PROXY/HTTP_PROXY/NO_PROXY and confirm the proxy is reachable and allows the endpoint.
- Raise retry_max and retry_wait_max to ride out transient outages.
- Confirm the server is running and listening on the expected port.
Example fix
// before
address = "https://state.example.invalid/terraform"
// after (correct host + trust private CA)
address = "https://state.example.com/terraform"
client_ca_certificate_pem = file("${path.module}/internal-ca.pem") Defensive patterns
Strategy: retry
Validate before calling
# Pre-flight: prove the endpoint is reachable and TLS-valid from this host
curl -fsS --connect-timeout 5 -o /dev/null -w 'http=%{http_code}\n' "$TF_HTTP_ADDRESS" \
|| { echo "ERROR: cannot reach $TF_HTTP_ADDRESS (network/DNS/TLS)"; exit 1; } Try / catch
# Terraform has no try/catch; wrap invocations and retry on transient transport errors. for i in 1 2 3; do terraform apply -auto-approve && break rc=$?; echo "apply failed (rc=$rc), retrying ($i/3)..."; sleep 5 done
Prevention
- Run a curl probe against address/lock/unlock URLs before terraform init in CI.
- For private/self-signed CAs, supply client_ca_certificate_pem rather than disabling verification.
- Tune retry_max/retry_wait_max to absorb transient outages.
- Verify HTTPS_PROXY/HTTP_PROXY/NO_PROXY are correct for the network path.
When it happens
Trigger: Server unreachable (DNS NXDOMAIN, connection refused, network down); TLS certificate verification failure; read/write timeout exceeded; HTTPS_PROXY/HTTP_PROXY pointing at a dead or misconfigured proxy; self-signed server cert without skip_cert_verification or client_ca_certificate_pem.
Common situations: Wrong hostname in address; egress firewall blocks the endpoint; server temporarily down; self-signed cert not trusted; corporate proxy env vars incorrect; DNS misconfiguration in the CI runner.
Related errors
- a network issue prevented cloud configuration;
- a network issue prevented cloud configuration;
- cannot load client certificate
- client_certificate_pem is set but client_private_key_pem is…
- client_private_key_pem is set but client_certificate_pem is…
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/f9e49900a4a7983a.
Report an issue: GitHub.
Appendix: source
Thrown at internal/backend/remote-state/http/client.go:74
if c.Username != "" {
req.SetBasicAuth(c.Username, c.Password)
}
// Work with data/body
if data != nil {
req.Header.Set("Content-Type", "application/json")
req.ContentLength = int64(len(*data))
// Generate the MD5
hash := md5.Sum(*data)
b64 := base64.StdEncoding.EncodeToString(hash[:])
req.Header.Set("Content-MD5", b64)
}
// Make the request
resp, err := c.Client.Do(req)
if err != nil {
return nil, fmt.Errorf("Failed to %s: %v", what, err)
}
return resp, nil
}
func (c *httpClient) Lock(info *statemgr.LockInfo) (string, error) {
if c.LockURL == nil {
return "", nil
}
c.lockID = ""
jsonLockInfo := info.Marshal()
resp, err := c.httpRequest(c.LockMethod, c.LockURL, &jsonLockInfo, "lock")
if err != nil {
return "", err
}
defer resp.Body.Close()
View on GitHub (pinned to d32a084675)