hashicorp/terraform · error

failed to write temp known_hosts file

Error message

failed to write temp known_hosts file: %s

What it means

After successfully creating the temp known_hosts file, Terraform writes a single @cert-authority line (host + host_key) into it via tf.WriteString. If the write fails — disk full mid-write, I/O error, or the file handle became invalid — the HostKeyCallback cannot be constructed and SSH connection setup fails. Note that tf.Sync() on the following line ignores its return error, so sync failures are silently swallowed.

Solutions

  1. Free disk space on the volume hosting the temp directory and retry the Terraform run.
  2. Verify the host_key value is not corrupt or absurdly large — a valid host key is a single line.
  3. If on NFS or networked storage for /tmp, switch to local storage for the temp directory.
  4. Set TMPDIR to a volume with adequate free space and retry.

Example fix

# before
connection {
  host_key = file("large-or-corrupt-key.txt")
}

# after — ensure host_key is a single valid known_hosts entry
connection {
  host_key = "ssh-rsa AAAAB3Nza...validkey..."
}
Defensive patterns

Strategy: validation

Validate before calling

// Validate the host_key is a single clean line before passing it in
func validateHostKey(hostKey string) error {
    trimmed := strings.TrimSpace(hostKey)
    if trimmed == "" {
        return errors.New("host_key is empty")
    }
    if strings.Count(trimmed, "\n") > 0 {
        return errors.New("host_key should be a single line")
    }
    return nil
}

Prevention

When it happens

Trigger: Providing a host_key in the connection block and hitting an I/O error during tf.WriteString of the @cert-authority line. Commonly triggered by ENOSPC after the temp file was created but before the write completes, or by a filesystem-level write error (NFS hiccup, overlay fs issue in containers).

Common situations: Disk fills up between file creation and write on a constrained CI runner. NFS-mounted temp directory with intermittent I/O errors. Container overlay filesystem failing to flush. Very large host_key string combined with low disk space.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/a573a38af43e026f. Report an issue: GitHub.

Appendix: source

Thrown at internal/communicator/ssh/provisioner.go:348

	hkCallback := ssh.InsecureIgnoreHostKey()

	if opts.hostKey != "" {
		// The knownhosts package only takes paths to files, but terraform
		// generally wants to handle config data in-memory. Rather than making
		// the known_hosts file an exception, write out the data to a temporary
		// file to create the HostKeyCallback.
		tf, err := ioutil.TempFile("", "tf-known_hosts")
		if err != nil {
			return nil, fmt.Errorf("failed to create temp known_hosts file: %s", err)
		}
		defer tf.Close()
		defer os.RemoveAll(tf.Name())

		// we mark this as a CA as well, but the host key fallback will still
		// use it as a direct match if the remote host doesn't return a
		// certificate.
		if _, err := tf.WriteString(fmt.Sprintf("@cert-authority %s %s\n", opts.host, opts.hostKey)); err != nil {
			return nil, fmt.Errorf("failed to write temp known_hosts file: %s", err)
		}
		tf.Sync()

		hkCallback, err = knownhosts.New(tf.Name())
		if err != nil {
			return nil, err
		}
	}

	conf := &ssh.ClientConfig{
		HostKeyCallback: hkCallback,
		User:            opts.user,
	}

	if opts.privateKey != "" {
		if opts.certificate != "" {
			log.Println("using client certificate for authentication")

View on GitHub (pinned to d32a084675)