hashicorp/terraform · error

invalid source address

Error message

invalid source address: %s

What it means

The terminal fallback of the remote-shorthand detector: no detector matched and the source is not a recognizable remote address. After all detectors (GitHub, BitBucket, GCS, S3, etc.) and forced-source handling fail to produce a result, the function gives up and labels the source invalid.

Solutions

  1. If the module is local, prefix it with './' or '../' so it is treated as a local path.
  2. If remote, add an explicit scheme/force prefix: 'git::https://...' or 'git::ssh://...'.
  3. Fix typos in the host name (github.com, bitbucket.org, etc.).
  4. Confirm the source is one of the supported detector formats.

Example fix

# before (typo, no detector matches)
source = "gihub.com/org/repo"

# after
source = "github.com/org/repo"
# or for an unsupported host:
source = "git::https://git.example.com/org/repo.git"
Defensive patterns

Strategy: validation

Validate before calling

// Classify a source before passing it to the detector.
// func classifySource(src string) (kind string, err error) {
//     if strings.HasPrefix(src, "./") || strings.HasPrefix(src, "../") { return "local", nil }
//     for _, p := range []string{"github.com/", "bitbucket.org/", "googleapis.com/", ".amazonaws.com/"} {
//         if strings.HasPrefix(src, p) || strings.Contains(src, p) { return "remote", nil }
//     }
//     if ms := forcedRegexp.FindStringSubmatch(src); ms != nil { return "remote", nil }
//     return "", fmt.Errorf("invalid source address: %s", src)
// }

Prevention

When it happens

Trigger: A module source that is neither a local path nor a recognized remote scheme reaches the detector — e.g. an unrecognizable host, a typo'd scheme, or a bare filename.

Common situations: Typo in source ('gihub.com/...'); unsupported host; missing scheme on a custom Git server; using a source format the legacy detector does not handle.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/09329302662f97dd. Report an issue: GitHub.

Appendix: source

Thrown at internal/getmodules/moduleaddrs/detect_remote_shorthands.go:93

			// have to ensure the path isn't escaped.
			u.RawPath = u.Path

			result = u.String()
		}

		// Preserve the forced getter if it exists. We try to use the
		// original set force first, followed by any force set by the
		// detector.
		if getForce != "" {
			result = fmt.Sprintf("%s::%s", getForce, result)
		} else if detectForce != "" {
			result = fmt.Sprintf("%s::%s", detectForce, result)
		}

		return result, nil
	}

	return "", fmt.Errorf("invalid source address: %s", src)
}

func getForcedSourceType(src string) (string, string) {
	var forced string
	if ms := forcedRegexp.FindStringSubmatch(src); ms != nil {
		forced = ms[1]
		src = ms[2]
	}

	return forced, src
}

View on GitHub (pinned to d32a084675)