hashicorp/terraform · error
invalid provider matching pattern
Error message
invalid provider matching pattern %q: namespace can be a wildcard only if the provider type is also a wildcard
What it means
Thrown when the namespace is the wildcard '*' but the type is not also '*'. The model only allows a wildcard namespace together with a wildcard type (i.e. 'host/*/*' or '*/*'); wildcarding the namespace while pinning a concrete type is not a meaningful selector and is rejected at multi_source.go:190-191.
Solutions
- If you want a concrete provider, also pin the namespace: 'hashicorp/aws' instead of '*/aws'.
- If you want broad coverage, wildcard the type too: 'host/*/*' or '*/*'.
- Prefer listing each concrete 'namespace/type' pair over trying to wildcard just the namespace.
Example fix
// before include = ["*/aws"] // after include = ["hashicorp/aws"] // or, to match everything on the default host: // include = ["*/*"]
Defensive patterns
Strategy: validation
Validate before calling
func validNamespaceWildcard(ns, typ string) error {
if ns == "*" && typ != "*" {
return fmt.Errorf("namespace wildcard requires the type to also be '*'")
}
return nil
} Prevention
- Never wildcard just the namespace; wildcard the type too, or pin the namespace.
- Prefer listing concrete 'namespace/type' pairs over broad wildcarding.
- Encode the wildcard-hierarchy rule in pattern-authoring UIs.
When it happens
Trigger: Patterns like '*/aws', 'host/*/aws', or 'registry.terraform.io/*/aws'. Any pattern (2- or 3-segment) where the namespace is '*' but the final type segment is a literal name.
Common situations: Trying to express 'this provider type from any namespace' — not supported; copy-paste turning a namespace into '*' while leaving the type concrete; building include patterns intending broad namespace coverage for one provider.
Related errors
- invalid provider matching pattern
- invalid registry namespace
- invalid provider matching pattern
- invalid provider type
- invalid hostname in provider matching pattern
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/f62ef8f14074bfd2.
Report an issue: GitHub.
Appendix: source
Thrown at internal/getproviders/multi_source.go:191
if err != nil {
return nil, fmt.Errorf("invalid provider type %q in provider matching pattern %q: must either be the wildcard * or a provider type name", parts[1], str)
}
namespace, err := normalizeProviderNamespaceOrWildcard(parts[0])
if err != nil {
return nil, fmt.Errorf("invalid registry namespace %q in provider matching pattern %q: must either be the wildcard * or a literal namespace", parts[1], str)
}
ret[i] = addrs.Provider{
Hostname: host,
Namespace: namespace,
Type: pType,
}
if ret[i].Hostname == svchost.Hostname(Wildcard) && !(ret[i].Namespace == Wildcard && ret[i].Type == Wildcard) {
return nil, fmt.Errorf("invalid provider matching pattern %q: hostname can be a wildcard only if both namespace and provider type are also wildcards", str)
}
if ret[i].Namespace == Wildcard && ret[i].Type != Wildcard {
return nil, fmt.Errorf("invalid provider matching pattern %q: namespace can be a wildcard only if the provider type is also a wildcard", str)
}
}
return ret, nil
}
// CanHandleProvider returns true if and only if the given provider address
// is both included by the selector's include patterns and _not_ excluded
// by its exclude patterns.
//
// The absense of any include patterns is treated the same as a pattern
// that matches all addresses. Exclusions take priority over inclusions.
func (s MultiSourceSelector) CanHandleProvider(addr addrs.Provider) bool {
switch {
case s.Exclude.MatchesProvider(addr):
return false
case len(s.Include) > 0:
return s.Include.MatchesProvider(addr)
default:View on GitHub (pinned to d32a084675)