hashicorp/terraform · error
Using the C:\Windows\Temp folder is not supported. Please…
Error message
Using the C:\Windows\Temp folder is not supported. Please use a different 'script_path'.
What it means
The WinRM communicator validates the script_path connection setting before connecting. Files placed in C:\Windows\Temp early during Windows boot can be deleted by the OS cleanup process before the provisioner gets to execute them, causing silent provisioning failures. This hard guard rejects any script_path that begins with C:/Windows/Temp (matched case-insensitively via filepath.ToSlash) to prevent that race condition.
Solutions
- Set script_path to a non-system temp location, e.g., script_path = "C:\\Temp\\terraform_%RAND%.cmd".
- Use the user's temp directory instead: script_path = "%TEMP%\\tf_%RAND%.cmd" (typically C:\Users\<user>\AppData\Local\Temp).
- Create the target directory beforehand or ensure the WinRM user has write access to the chosen path.
- Remove the script_path override entirely to use Terraform's safe default.
Example fix
# before
connection {
type = "winrm"
script_path = "C:\\Windows\\Temp\\terraform_%RAND%.cmd"
}
# after
connection {
type = "winrm"
script_path = "C:\\Terraform\\tf_%RAND%.cmd"
} Defensive patterns
Strategy: validation
Validate before calling
// Validate the script_path before passing it to the winrm connection
import (
"path/filepath"
"strings"
)
func validateWinRMScriptPath(scriptPath string) error {
normalized := filepath.ToSlash(scriptPath)
if strings.HasPrefix(strings.ToLower(normalized), "c:/windows/temp") {
return errors.New("script_path must not use C:\\Windows\\Temp; use a custom directory")
}
return nil
} Prevention
- Set script_path to a dedicated directory like C:\\Terraform or the user's %TEMP%.
- Avoid copying connection blocks from Linux-oriented examples for Windows hosts.
- Document the Windows-safe script_path convention in your team's Terraform style guide.
When it happens
Trigger: Setting script_path in a winrm connection block to a path under C:\Windows\Temp (or C:/Windows/Temp). The check normalizes backslashes to forward slashes via filepath.ToSlash and checks the prefix string, so any casing or slash variant of that path triggers it.
Common situations: User copies a connection block from a Linux example and leaves or sets the default Windows temp path. User explicitly sets script_path = "C:\\Windows\\Temp\\terraform_%RAND%.cmd" thinking it's a safe temp location. Default script_path was overridden to point to the system temp folder.
Related errors
- connection type ' ' not supported
- address argument is required
- argument is required
- attribute is required
- auth must be one of ' ' or ' ' or ' ' or ' ' or ' ' or
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/a45a6d2ccfecd330.
Report an issue: GitHub.
Appendix: source
Thrown at internal/communicator/winrm/provisioner.go:114
// a ConnectionInfo struct
func parseConnectionInfo(v cty.Value) (*connectionInfo, error) {
v, err := shared.ConnectionBlockSupersetSchema.CoerceValue(v)
if err != nil {
return nil, err
}
connInfo, err := decodeConnInfo(v)
if err != nil {
return nil, err
}
// Check on script paths which point to the default Windows TEMP folder because files
// which are put in there very early in the boot process could get cleaned/deleted
// before you had the change to execute them.
//
// TODO (SvH) Needs some more debugging to fully understand the exact sequence of events
// causing this...
if strings.HasPrefix(filepath.ToSlash(connInfo.ScriptPath), "C:/Windows/Temp") {
return nil, fmt.Errorf(
`Using the C:\Windows\Temp folder is not supported. Please use a different 'script_path'.`)
}
if connInfo.User == "" {
connInfo.User = DefaultUser
}
// Format the host if needed.
// Needed for IPv6 support.
connInfo.Host = shared.IpFormat(connInfo.Host)
if connInfo.Port == 0 {
if connInfo.HTTPS {
connInfo.Port = DefaultHTTPSPort
} else {
connInfo.Port = DefaultPort
}
}View on GitHub (pinned to d32a084675)