hashicorp/terraform · error
URL is not a valid S3 URL
Error message
URL is not a valid S3 URL
What it means
First S3 validity check in detectS3: the source contains '.amazonaws.com/' but splits into fewer than 2 parts, meaning there is no path after the host. The detector needs at least host + one path segment to identify a bucket/key, so it rejects the URL.
Solutions
- Provide the full path including bucket and key: '<region>.amazonaws.com/BUCKET/KEY'.
- Prefer the explicit s3:: form: 's3::https://<host>/<bucket>/<key>'.
- Copy the full object path from the S3 console.
Example fix
# before (no path) source = "s3.amazonaws.com/" # after source = "s3.amazonaws.com/my-bucket/modules/vpc.zip"
Defensive patterns
Strategy: validation
Validate before calling
// Ensure an S3-ish source has a path after the host.
// func validS3HasPath(src string) error {
// if !strings.Contains(src, ".amazonaws.com/") { return nil }
// if len(strings.Split(src, "/")) < 2 {
// return fmt.Errorf("S3 source needs bucket and key after the host")
// }
// return nil
// } Prevention
- Always include bucket and key in S3 sources.
- Prefer the explicit s3::https:// form.
- Copy the full object path from the S3 console.
When it happens
Trigger: Source is just 'something.amazonaws.com/' with no bucket or key path; the trigger substring matched but no object path follows.
Common situations: User pastes only the S3 endpoint host; bare region endpoint with no bucket; copy-paste truncation losing the key.
Related errors
- GitHub URLs should be github.com/username/repo
- invalid source address
- URL is not a valid GCS URL
- can't delete default state
- can't use local directory
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/0ede26d4c4fadd7d.
Report an issue: GitHub.
Appendix: source
Thrown at internal/getmodules/moduleaddrs/detect_s3.go:22
package moduleaddrs
import (
"fmt"
"net/url"
"strings"
)
// detectS3 detects strings that seem like schemeless references to
// Amazon S3 and translates them into URLs for the "s3" getter.
func detectS3(src string) (string, bool, error) {
if len(src) == 0 {
return "", false, nil
}
if strings.Contains(src, ".amazonaws.com/") {
parts := strings.Split(src, "/")
if len(parts) < 2 {
return "", false, fmt.Errorf(
"URL is not a valid S3 URL")
}
hostParts := strings.Split(parts[0], ".")
if len(hostParts) == 3 {
return detectS3PathStyle(hostParts[0], parts[1:])
} else if len(hostParts) == 4 {
return detectS3OldVhostStyle(hostParts[1], hostParts[0], parts[1:])
} else if len(hostParts) == 5 && hostParts[1] == "s3" {
return detectS3NewVhostStyle(hostParts[2], hostParts[0], parts[1:])
} else {
return "", false, fmt.Errorf(
"URL is not a valid S3 URL")
}
}
return "", false, nil
}View on GitHub (pinned to d32a084675)