hashicorp/terraform · error
invalid retry_max
Error message
invalid retry_max: %s
What it means
backendbase.IntValue failed to convert the retry_max value (attribute or TF_HTTP_RETRY_MAX, default 2) to a Go int. IntValue rejects fractional numbers (e.g. 2.5), NaN/Infinity, and values outside the int range. retry_max must be a whole number.
Solutions
- Set retry_max to a non-negative integer (e.g. retry_max = 2).
- Remove the retry_max setting to fall back to the default of 2.
- If sourcing from a variable, ensure its type is number and the value is integral.
Example fix
// before retry_max = 2.5 // after retry_max = 2
Defensive patterns
Strategy: validation
Validate before calling
# Pre-flight: retry_max must be a non-negative integer
if [ -n "$TF_HTTP_RETRY_MAX" ]; then
case "$TF_HTTP_RETRY_MAX" in
''|*[!0-9]*) echo "ERROR: retry_max must be a non-negative integer, got: $TF_HTTP_RETRY_MAX"; exit 1 ;;
esac
fi Type guard
// In Go-land embedding this backend: validate the cty value is integral.
func isIntegral(n cty.Value) bool {
if !n.IsKnown() || n.IsNull() { return false }
f, _ := n.AsBigFloat().Float64()
return n.AsBigFloat().IsInt() || f == float64(int64(f))
} Prevention
- Always set retry_max to a whole number literal (retry_max = 2).
- Type-tighten any variable feeding retry_max to an integer.
- Leave the setting unset to accept the default of 2.
When it happens
Trigger: retry_max set to a fractional number like 2.5, an extremely large number exceeding int64, or NaN/Infinity via a computed expression.
Common situations: User sets retry_max = 2.5 assuming floats are allowed; a variable evaluates to a float; copy from documentation that used a decimal.
Related errors
- invalid retry_wait_max
- invalid retry_wait_min
- client_certificate_pem is set but client_private_key_pem is…
- client_private_key_pem is set but client_certificate_pem is…
- address must be HTTP or HTTPS
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/489f75a320d8edc3.
Report an issue: GitHub.
Appendix: source
Thrown at internal/backend/remote-state/http/backend.go:195
return backendbase.ErrorAsDiagnostics(
fmt.Errorf("unlock_address must be HTTP or HTTPS"),
)
}
}
unlockMethod := backendbase.GetAttrEnvDefaultFallback(
configVal, "unlock_method",
"TF_HTTP_UNLOCK_METHOD", cty.StringVal("UNLOCK"),
).AsString()
retryMax, err := backendbase.IntValue(
backendbase.GetAttrEnvDefaultFallback(
configVal, "retry_max",
"TF_HTTP_RETRY_MAX", cty.NumberIntVal(2),
),
)
if err != nil {
return backendbase.ErrorAsDiagnostics(
fmt.Errorf("invalid retry_max: %s", err),
)
}
retryWaitMin, err := backendbase.IntValue(
backendbase.GetAttrEnvDefaultFallback(
configVal, "retry_wait_min",
"TF_HTTP_RETRY_WAIT_MIN", cty.NumberIntVal(1),
),
)
if err != nil {
return backendbase.ErrorAsDiagnostics(
fmt.Errorf("invalid retry_wait_min: %s", err),
)
}
retryWaitMax, err := backendbase.IntValue(
backendbase.GetAttrEnvDefaultFallback(
configVal, "retry_wait_max",
"TF_HTTP_RETRY_WAIT_MAX", cty.NumberIntVal(30),
),View on GitHub (pinned to d32a084675)