{"record":{"id":"166ac2ce7b90cdc7","repo":"kubernetes/kops","slug":"fetching-metadata-token-w","errorCode":null,"errorMessage":"fetching metadata token: %w","messagePattern":"fetching metadata token: %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"upup/pkg/fi/cloudup/linode/linodemetadata/authenticator.go","lineNumber":84,"sourceCode":"\n// GetMetadataValue fetches the given field from the Akamai (Linode) instance metadata service\n// using the standard metadata endpoint and default HTTP client.\nfunc GetMetadataValue(ctx context.Context, key string) (string, error) {\n\treturn getLinodeMetadataValue(ctx, http.DefaultClient, linodeMetadataBaseURL, key)\n}\n\n// getLinodeMetadataValue queries the Akamai (Linode) metadata service for the given key\n// and returns the value as a string.\nfunc getLinodeMetadataValue(ctx context.Context, client *http.Client, metadataBaseURL, key string) (string, error) {\n\ttokenReq, err := http.NewRequestWithContext(ctx, http.MethodPut, metadataBaseURL+\"/v1/token\", nil)\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"building metadata token request: %w\", err)\n\t}\n\ttokenReq.Header.Set(\"Metadata-Token-Expiry-Seconds\", linodeMetadataTokenTTL)\n\n\ttokenResp, err := client.Do(tokenReq)\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"fetching metadata token: %w\", err)\n\t}\n\tdefer tokenResp.Body.Close()\n\n\tif tokenResp.StatusCode != http.StatusOK {\n\t\treturn \"\", fmt.Errorf(\"fetching metadata token: unexpected status code %d\", tokenResp.StatusCode)\n\t}\n\n\ttokenBytes, err := io.ReadAll(tokenResp.Body)\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"reading metadata token response: %w\", err)\n\t}\n\n\ttoken := strings.TrimSpace(string(tokenBytes))\n\tif token == \"\" {\n\t\treturn \"\", fmt.Errorf(\"metadata token was empty\")\n\t}\n\n\tinstanceReq, err := http.NewRequestWithContext(ctx, http.MethodGet, metadataBaseURL+\"/v1/instance\", nil)","sourceCodeStart":66,"sourceCodeEnd":102,"githubUrl":"https://github.com/kubernetes/kops/blob/4c8573c808a73d578c5eadc86d410646ea0b0d73/upup/pkg/fi/cloudup/linode/linodemetadata/authenticator.go#L66-L102","documentation":"getLinodeMetadataValue wraps the client.Do error from the PUT /v1/token request to the Linode metadata service. It fires when the metadata endpoint is unreachable, DNS fails, the context is cancelled, or a proxy blocks the connection — meaning no metadata token can be issued.","triggerScenarios":"Thrown at upup/pkg/fi/cloudup/linode/linodemetadata/authenticator.go:84 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Check network reachability of the Linode metadata service from the node","Confirm the instance has the metadata service enabled","Increase or verify the context timeout for the metadata call","Inspect DNS and proxy settings on the node"],"exampleFix":null,"handlingStrategy":"retry","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"4c8573c808a73d578c5eadc86d410646ea0b0d73","analyzedAt":"2026-09-05T04:13:19.212Z","contentChangedAt":"2026-09-05T04:13:19.212Z","schemaVersion":2},"datasetVersion":"2026-09-12T07:17:12.445Z"}