{"record":{"id":"0b1b6ae0e747ebc5","repo":"hashicorp/terraform","slug":"refresh-ecs-sts-token-err-fail-to-get-securitytok","errorCode":null,"errorMessage":"refresh Ecs sts token err, fail to get SecurityToken: %s","messagePattern":"refresh Ecs sts token err, fail to get SecurityToken: (.+?)","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/oss/backend.go","lineNumber":700,"sourceCode":"\t\treturn\n\t}\n\tif code.(string) != \"Success\" {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, Code is not Success\")\n\t\treturn\n\t}\n\taccessKeyId, err := jmespath.Search(\"AccessKeyId\", data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, fail to get AccessKeyId: %s\", err.Error())\n\t\treturn\n\t}\n\taccessKeySecret, err := jmespath.Search(\"AccessKeySecret\", data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, fail to get AccessKeySecret: %s\", err.Error())\n\t\treturn\n\t}\n\tsecurityToken, err := jmespath.Search(\"SecurityToken\", data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, fail to get SecurityToken: %s\", err.Error())\n\t\treturn\n\t}\n\n\tif accessKeyId == nil || accessKeySecret == nil || securityToken == nil {\n\t\terr = fmt.Errorf(\"there is no any available accesskey, secret and security token for Ecs role %s\", ecsRoleName)\n\t\treturn\n\t}\n\n\treturn accessKeyId.(string), accessKeySecret.(string), securityToken.(string), nil\n}\n\nfunc getHttpProxyUrl(rawUrl string) (*url.URL, error) {\n\tpc := httpproxy.FromEnvironment()\n\tu, err := url.Parse(rawUrl)\n\tif err != nil {\n\t\treturn nil, err\n\t}\n\treturn pc.ProxyFunc()(u)","sourceCodeStart":682,"sourceCodeEnd":718,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/oss/backend.go#L682-L718","documentation":"Thrown while refreshing an ECS STS token: JMESPath search for 'SecurityToken' errored after AccessKeyId/AccessKeySecret resolved. The Success response object did not expose SecurityToken in a traversable shape.","triggerScenarios":"Metadata endpoint returned Success with id/secret but the SecurityToken field is absent or nested in a non-traversable structure — e.g., the response shape changed to nest tokens under a sub-object, or a stale cached response omits the token.","commonSituations":"Credential rotation in progress where SecurityToken lags; region-specific metadata service differences; SDK/backend version mismatch.","solutions":["Curl the metadata endpoint and confirm SecurityToken is present at the top level of the Success object.","Force a credential refresh by re-attaching the RAM role.","Update SDK and backend versions to match the metadata service contract.","Verify there is no caching layer returning a partial document."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"tok, ok := data.(map[string]interface{})[\"SecurityToken\"].(string)\nif !ok || tok == \"\" {\n    return fmt.Errorf(\"metadata missing SecurityToken\")\n}","typeGuard":"func hasSecurityToken(v interface{}) bool {\n    m, ok := v.(map[string]interface{}); if !ok { return false }\n    s, ok := m[\"SecurityToken\"].(string); return ok && s != \"\"\n}","tryCatchPattern":null,"preventionTips":["Force a credential refresh if SecurityToken is absent while id/secret are present.","Do not cache STS credentials beyond their stated expiration.","Verify no caching proxy is serving partial metadata documents."],"tags":["alibaba-cloud","ecs","sts","jmespath","iam","credentials"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}