hashicorp/terraform · error

Using the C:\Windows\Temp folder is not supported. Please…

Error message

Using the C:\Windows\Temp folder is not supported. Please use a different 'script_path'.

What it means

The WinRM communicator validates the script_path connection setting before connecting. Files placed in C:\Windows\Temp early during Windows boot can be deleted by the OS cleanup process before the provisioner gets to execute them, causing silent provisioning failures. This hard guard rejects any script_path that begins with C:/Windows/Temp (matched case-insensitively via filepath.ToSlash) to prevent that race condition.

Solutions

  1. Set script_path to a non-system temp location, e.g., script_path = "C:\\Temp\\terraform_%RAND%.cmd".
  2. Use the user's temp directory instead: script_path = "%TEMP%\\tf_%RAND%.cmd" (typically C:\Users\<user>\AppData\Local\Temp).
  3. Create the target directory beforehand or ensure the WinRM user has write access to the chosen path.
  4. Remove the script_path override entirely to use Terraform's safe default.

Example fix

# before
connection {
  type        = "winrm"
  script_path = "C:\\Windows\\Temp\\terraform_%RAND%.cmd"
}

# after
connection {
  type        = "winrm"
  script_path = "C:\\Terraform\\tf_%RAND%.cmd"
}
Defensive patterns

Strategy: validation

Validate before calling

// Validate the script_path before passing it to the winrm connection
import (
    "path/filepath"
    "strings"
)

func validateWinRMScriptPath(scriptPath string) error {
    normalized := filepath.ToSlash(scriptPath)
    if strings.HasPrefix(strings.ToLower(normalized), "c:/windows/temp") {
        return errors.New("script_path must not use C:\\Windows\\Temp; use a custom directory")
    }
    return nil
}

Prevention

When it happens

Trigger: Setting script_path in a winrm connection block to a path under C:\Windows\Temp (or C:/Windows/Temp). The check normalizes backslashes to forward slashes via filepath.ToSlash and checks the prefix string, so any casing or slash variant of that path triggers it.

Common situations: User copies a connection block from a Linux example and leaves or sets the default Windows temp path. User explicitly sets script_path = "C:\\Windows\\Temp\\terraform_%RAND%.cmd" thinking it's a safe temp location. Default script_path was overridden to point to the system temp folder.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/a45a6d2ccfecd330. Report an issue: GitHub.

Appendix: source

Thrown at internal/communicator/winrm/provisioner.go:114

// a ConnectionInfo struct
func parseConnectionInfo(v cty.Value) (*connectionInfo, error) {
	v, err := shared.ConnectionBlockSupersetSchema.CoerceValue(v)
	if err != nil {
		return nil, err
	}

	connInfo, err := decodeConnInfo(v)
	if err != nil {
		return nil, err
	}
	// Check on script paths which point to the default Windows TEMP folder because files
	// which are put in there very early in the boot process could get cleaned/deleted
	// before you had the change to execute them.
	//
	// TODO (SvH) Needs some more debugging to fully understand the exact sequence of events
	// causing this...
	if strings.HasPrefix(filepath.ToSlash(connInfo.ScriptPath), "C:/Windows/Temp") {
		return nil, fmt.Errorf(
			`Using the C:\Windows\Temp folder is not supported. Please use a different 'script_path'.`)
	}

	if connInfo.User == "" {
		connInfo.User = DefaultUser
	}

	// Format the host if needed.
	// Needed for IPv6 support.
	connInfo.Host = shared.IpFormat(connInfo.Host)

	if connInfo.Port == 0 {
		if connInfo.HTTPS {
			connInfo.Port = DefaultHTTPSPort
		} else {
			connInfo.Port = DefaultPort
		}
	}

View on GitHub (pinned to d32a084675)