hashicorp/terraform · error
failed to write temp known_hosts file
Error message
failed to write temp known_hosts file: %s
What it means
After successfully creating the temp known_hosts file, Terraform writes a single @cert-authority line (host + host_key) into it via tf.WriteString. If the write fails — disk full mid-write, I/O error, or the file handle became invalid — the HostKeyCallback cannot be constructed and SSH connection setup fails. Note that tf.Sync() on the following line ignores its return error, so sync failures are silently swallowed.
Solutions
- Free disk space on the volume hosting the temp directory and retry the Terraform run.
- Verify the host_key value is not corrupt or absurdly large — a valid host key is a single line.
- If on NFS or networked storage for /tmp, switch to local storage for the temp directory.
- Set TMPDIR to a volume with adequate free space and retry.
Example fix
# before
connection {
host_key = file("large-or-corrupt-key.txt")
}
# after — ensure host_key is a single valid known_hosts entry
connection {
host_key = "ssh-rsa AAAAB3Nza...validkey..."
} Defensive patterns
Strategy: validation
Validate before calling
// Validate the host_key is a single clean line before passing it in
func validateHostKey(hostKey string) error {
trimmed := strings.TrimSpace(hostKey)
if trimmed == "" {
return errors.New("host_key is empty")
}
if strings.Count(trimmed, "\n") > 0 {
return errors.New("host_key should be a single line")
}
return nil
} Prevention
- Ensure adequate free disk space before large provisioning runs.
- Avoid NFS or network-backed storage for the temp directory.
- Validate host_key input is a single well-formed known_hosts entry.
When it happens
Trigger: Providing a host_key in the connection block and hitting an I/O error during tf.WriteString of the @cert-authority line. Commonly triggered by ENOSPC after the temp file was created but before the write completes, or by a filesystem-level write error (NFS hiccup, overlay fs issue in containers).
Common situations: Disk fills up between file creation and write on a constrained CI runner. NFS-mounted temp directory with intermittent I/O errors. Container overlay filesystem failing to flush. Very large host_key string combined with low disk space.
Related errors
- Error creating temporary file for upload
- failed to create temp known_hosts file
- Cannot quote scp command, target platform unknown
- Connection Error: StatusCode
- connection type ' ' not supported
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/a573a38af43e026f.
Report an issue: GitHub.
Appendix: source
Thrown at internal/communicator/ssh/provisioner.go:348
hkCallback := ssh.InsecureIgnoreHostKey()
if opts.hostKey != "" {
// The knownhosts package only takes paths to files, but terraform
// generally wants to handle config data in-memory. Rather than making
// the known_hosts file an exception, write out the data to a temporary
// file to create the HostKeyCallback.
tf, err := ioutil.TempFile("", "tf-known_hosts")
if err != nil {
return nil, fmt.Errorf("failed to create temp known_hosts file: %s", err)
}
defer tf.Close()
defer os.RemoveAll(tf.Name())
// we mark this as a CA as well, but the host key fallback will still
// use it as a direct match if the remote host doesn't return a
// certificate.
if _, err := tf.WriteString(fmt.Sprintf("@cert-authority %s %s\n", opts.host, opts.hostKey)); err != nil {
return nil, fmt.Errorf("failed to write temp known_hosts file: %s", err)
}
tf.Sync()
hkCallback, err = knownhosts.New(tf.Name())
if err != nil {
return nil, err
}
}
conf := &ssh.ClientConfig{
HostKeyCallback: hkCallback,
User: opts.user,
}
if opts.privateKey != "" {
if opts.certificate != "" {
log.Println("using client certificate for authentication")
View on GitHub (pinned to d32a084675)