hashicorp/terraform · error
invalid provider matching pattern
Error message
invalid provider matching pattern %q: hostname can be a wildcard only if both namespace and provider type are also wildcards
What it means
Thrown when the host segment is the wildcard '*' but at least one of namespace or type is not also '*'. The parser only permits a wildcard hostname in the fully-wildcard form '*/*/*'; a wildcard host with any concrete namespace or type is ambiguous and rejected. Checked at multi_source.go:187-188 after all three segments are normalized.
Solutions
- If you truly want all hosts, use '*/*/*' (matches every provider on every host).
- Otherwise drop the host wildcard and name the concrete host: 'registry.terraform.io/hashicorp/aws'.
- To match a provider across namespaces on a known host, wildcard only the namespace: 'host/*/aws' (allowed) rather than '*/namespace/aws'.
Example fix
// before include = ["*/hashicorp/aws"] // after include = ["registry.terraform.io/hashicorp/aws"]
Defensive patterns
Strategy: validation
Validate before calling
func validWildcardCombination(host, ns, typ string) error {
// after normalization, host == "*" forces ns == "*" and typ == "*"
if host == "*" && !(ns == "*" && typ == "*") {
return fmt.Errorf("hostname wildcard requires namespace and type to also be '*/*/*'")
}
return nil
} Prevention
- Only use '*/*/*' when wildcarding the host.
- For a specific provider on a specific host, name the host explicitly.
- Lint wildcard combinations in config tests.
When it happens
Trigger: Patterns like '*/hashicorp/aws', '*/*/aws', or '*/hashicorp/*'. Any 3-segment pattern whose first segment is '*' but whose remaining two are not both '*' hits this branch.
Common situations: Wanting 'any host for a specific provider' (not supported by the model — host wildcard forces total wildcard); mixing a literal host with '*' by mistake; building exclude patterns intending broad coverage but over-wildcarding the host.
Related errors
- invalid provider matching pattern
- invalid hostname in provider matching pattern
- invalid provider matching pattern
- invalid provider type
- invalid registry namespace
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/cbb4be9884610c89.
Report an issue: GitHub.
Appendix: source
Thrown at internal/getproviders/multi_source.go:188
}
pType, err := normalizeProviderNameOrWildcard(parts[1])
if err != nil {
return nil, fmt.Errorf("invalid provider type %q in provider matching pattern %q: must either be the wildcard * or a provider type name", parts[1], str)
}
namespace, err := normalizeProviderNamespaceOrWildcard(parts[0])
if err != nil {
return nil, fmt.Errorf("invalid registry namespace %q in provider matching pattern %q: must either be the wildcard * or a literal namespace", parts[1], str)
}
ret[i] = addrs.Provider{
Hostname: host,
Namespace: namespace,
Type: pType,
}
if ret[i].Hostname == svchost.Hostname(Wildcard) && !(ret[i].Namespace == Wildcard && ret[i].Type == Wildcard) {
return nil, fmt.Errorf("invalid provider matching pattern %q: hostname can be a wildcard only if both namespace and provider type are also wildcards", str)
}
if ret[i].Namespace == Wildcard && ret[i].Type != Wildcard {
return nil, fmt.Errorf("invalid provider matching pattern %q: namespace can be a wildcard only if the provider type is also a wildcard", str)
}
}
return ret, nil
}
// CanHandleProvider returns true if and only if the given provider address
// is both included by the selector's include patterns and _not_ excluded
// by its exclude patterns.
//
// The absense of any include patterns is treated the same as a pattern
// that matches all addresses. Exclusions take priority over inclusions.
func (s MultiSourceSelector) CanHandleProvider(addr addrs.Provider) bool {
switch {
case s.Exclude.MatchesProvider(addr):
return falseView on GitHub (pinned to d32a084675)