hashicorp/terraform · error

invalid hostname in provider matching pattern

Error message

invalid hostname in provider matching pattern %q: %s

What it means

Thrown when a 3-segment pattern has a host segment that is not '*' and fails svchost.ForComparison normalization. svchost.ForComparison applies IDNA/punycode normalization and rejects hostnames with invalid characters, bad punycode labels, or other RFC 1035 violations. The wrapped %s is the underlying svchost error.

Solutions

  1. Correct the hostname to a valid DNS name (letters, digits, hyphens, dots) matching what svchost.ForComparison accepts.
  2. Use '*' as the host segment if you want any host, but remember that forces '*/*' for namespace and type.
  3. Test the host alone with svchost.ForComparison(host) to surface the exact normalization error before wiring it into a pattern.
  4. Drop the host segment entirely (use a 2-segment pattern) if the default registry host is what you meant.

Example fix

// before
include = ["artifacts_acme.corp/hashicorp/aws"]

// after
include = ["artifacts-acme.corp/hashicorp/aws"]
Defensive patterns

Strategy: validation

Validate before calling

import svchost "github.com/hashicorp/terraform-svchost"

func validHostSegment(host string) error {
    if host == "*" {
        return nil
    }
    if _, err := svchost.ForComparison(host); err != nil {
        return fmt.Errorf("invalid host %q: %w", host, err)
    }
    return nil
}

Prevention

When it happens

Trigger: A 3-segment pattern whose first segment is not '*' and is malformed: e.g. 'exam_ple.com/hashicorp/aws', 'has space.com/hashicorp/aws', 'xn--invalid punycode/hashicorp/aws', or a host with an underscore label. Triggered at multi_source.go:160-162 when svchost.ForComparison(givenHost) returns err.

Common situations: Pointing a mirror/include pattern at a private registry hostname that contains underscores or other non-DNS characters; pasting a hostname with a trailing dot or port; copy-paste introducing a space or non-ASCII character; an internal registry whose DNS name uses characters svchost rejects.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/b9b59f4ac8bbc598. Report an issue: GitHub.

Appendix: source

Thrown at internal/getproviders/multi_source.go:162

		return nil, nil
	}

	ret := make(MultiSourceMatchingPatterns, len(strs))
	for i, str := range strs {
		parts := strings.Split(str, "/")
		if len(parts) < 2 || len(parts) > 3 {
			return nil, fmt.Errorf("invalid provider matching pattern %q: must have either two or three slash-separated segments", str)
		}
		host := defaultRegistryHost
		explicitHost := len(parts) == 3
		if explicitHost {
			givenHost := parts[0]
			if givenHost == "*" {
				host = svchost.Hostname(Wildcard)
			} else {
				normalHost, err := svchost.ForComparison(givenHost)
				if err != nil {
					return nil, fmt.Errorf("invalid hostname in provider matching pattern %q: %s", str, err)
				}

				// The remaining code below deals only with the namespace/type portions.
				host = normalHost
			}

			parts = parts[1:]
		}

		pType, err := normalizeProviderNameOrWildcard(parts[1])
		if err != nil {
			return nil, fmt.Errorf("invalid provider type %q in provider matching pattern %q: must either be the wildcard * or a provider type name", parts[1], str)
		}
		namespace, err := normalizeProviderNamespaceOrWildcard(parts[0])
		if err != nil {
			return nil, fmt.Errorf("invalid registry namespace %q in provider matching pattern %q: must either be the wildcard * or a literal namespace", parts[1], str)
		}

View on GitHub (pinned to d32a084675)