You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

执行terraform init失败,遇connection reset by peer错误求助

Terraform Init 连接重置问题(公司新增CA证书后)

执行terraform init时出现如下报错:

>terraform init     

Initializing modules...

Initializing the backend...

Initializing provider plugins...
- Reusing previous version of hashicorp/template from the dependency lock file
- Reusing previous version of cloudflare/cloudflare from the dependency lock file
- Reusing previous version of hashicorp/aws from the dependency lock file
- Reusing previous version of hashicorp/null from the dependency lock file
- Installing hashicorp/template v2.2.0...
- Using previously-installed cloudflare/cloudflare v3.18.0
- Installing hashicorp/aws v3.30.0...
- Installing hashicorp/null v3.1.1...
╷
│ Error: Failed to install provider
│ 
│ Error while installing hashicorp/template v2.2.0: Get "https://releases.hashicorp.com/terraform-provider-template/2.2.0/terraform-provider-template_2.2.0_linux_amd64.zip": read tcp 10.250.192.121:45540->108.157.30.78:443: read:
│ connection reset by peer
╵

╷
│ Error: Failed to install provider
│ 
│ Error while installing hashicorp/aws v3.30.0: Get "https://releases.hashicorp.com/terraform-provider-aws/3.30.0/terraform-provider-aws_3.30.0_linux_amd64.zip": read tcp 10.250.192.121:37686->108.157.30.40:443: read: connection reset
│ by peer
╵

╷
│ Error: Failed to install provider
│ 
│ Error while installing hashicorp/null v3.1.1: Get "https://releases.hashicorp.com/terraform-provider-null/3.1.1/terraform-provider-null_3.1.1_linux_amd64.zip": read tcp 10.250.192.121:45552->108.157.30.78:443: read: connection reset
│ by peer

原因分析

公司网络新增CA证书后,Terraform默认的证书信任列表未包含该新证书,导致HTTPS请求到Hashicorp仓库时无法通过证书验证,被网络设备主动重置连接。

解决方案

1. 配置Terraform使用公司CA证书

  • 从IT部门获取公司的CA证书文件(通常为.crt或.pem格式)
  • 设置环境变量指定证书路径:
    # 临时生效(当前会话)
    export SSL_CERT_FILE=/path/to/company-ca.crt
    export CURL_CA_BUNDLE=/path/to/company-ca.crt
    
  • 永久生效(写入shell配置文件):
    echo 'export SSL_CERT_FILE=/path/to/company-ca.crt' >> ~/.bashrc
    echo 'export CURL_CA_BUNDLE=/path/to/company-ca.crt' >> ~/.bashrc
    source ~/.bashrc
    

2. 检查代理配置(若公司使用网络代理)

如果服务器需通过代理访问外网,需确保代理环境变量正确设置,且代理已信任新增的CA证书:

export HTTP_PROXY=http://your-proxy-ip:port
export HTTPS_PROXY=http://your-proxy-ip:port
export NO_PROXY=localhost,127.0.0.1

3. 手动安装插件(备选方案)

若环境变量配置后仍无法解决,可手动下载插件并放置到Terraform插件目录:

  1. 下载对应版本的插件包(如terraform-provider-aws_3.30.0_linux_amd64.zip)
  2. 解压后将插件二进制文件放到以下路径:
    ~/.terraform.d/plugins/hashicorp/aws/3.30.0/linux_amd64/terraform-provider-aws_v3.30.0_x5
    
    (其他插件同理,替换provider名称、版本和系统架构)
  3. 重新执行terraform init

执行完上述操作后,再次运行terraform init即可正常安装插件。

内容的提问来源于stack exchange,提问作者duyluan97

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 15:45:33