{"record":{"id":"29779c6ff26f42c0","repo":"hashicorp/terraform","slug":"failed-to-access-object-httpstatuscode-d-opcrequ","errorCode":null,"errorMessage":"failed to access object HttpStatusCode: %d\nOpcRequestId: %s\n message: %s\n ErrorCode: %s","messagePattern":"failed to access object HttpStatusCode: (.+?)\nOpcRequestId: (.+?)\n message: (.+?)\n ErrorCode: (.+?)","errorType":"http","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/oci/client.go","lineNumber":97,"sourceCode":"\t\tNamespaceName: common.String(c.namespace),\n\t\tObjectName:    common.String(c.path),\n\t\tBucketName:    common.String(c.bucketName),\n\t\tIfMatch:       headResponse.ETag,\n\t\tRequestMetadata: common.RequestMetadata{\n\t\t\tRetryPolicy: getDefaultRetryPolicy(),\n\t\t},\n\t}\n\tif c.SSECustomerKey != \"\" && c.SSECustomerKeySHA256 != \"\" {\n\t\tgetRequest.OpcSseCustomerKey = common.String(c.SSECustomerKey)\n\t\tgetRequest.OpcSseCustomerKeySha256 = common.String(c.SSECustomerKeySHA256)\n\t\tgetRequest.OpcSseCustomerAlgorithm = common.String(c.SSECustomerAlgorithm)\n\t}\n\t// Get object from OCI\n\tgetResponse, err := c.objectStorageClient.GetObject(ctx, getRequest)\n\tif err != nil {\n\t\tvar ociErr common.ServiceError\n\t\tif errors.As(err, &ociErr) {\n\t\t\treturn nil, fmt.Errorf(\"failed to access object HttpStatusCode: %d\\nOpcRequestId: %s\\n message: %s\\n ErrorCode: %s\", ociErr.GetHTTPStatusCode(), ociErr.GetOpcRequestID(), ociErr.GetMessage(), ociErr.GetCode())\n\n\t\t}\n\t\treturn nil, fmt.Errorf(\"failed to access object '%s' in bucket '%s': %w\", c.path, c.bucketName, err)\n\t}\n\tdefer getResponse.Content.Close()\n\n\t// Read object content\n\tcontentArray, err := io.ReadAll(getResponse.Content)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"unable to read 'content' from response: %w\", err)\n\t}\n\n\t// Compute MD5 hash\n\tmd5Hash := getResponse.ContentMd5\n\tif md5Hash == nil || len(*md5Hash) == 0 {\n\t\tmd5Hash = getResponse.OpcMultipartMd5\n\t}\n\t// Construct payload","sourceCodeStart":79,"sourceCodeEnd":115,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/oci/client.go#L79-L115","documentation":"GetObject (the body fetch in the download path) failed with an error that satisfies errors.As for common.ServiceError. The backend prints the structured OCI failure: HTTP status, OPC request ID, message, and error code. This is the detailed counterpart to 305 and is the primary error for OCI-recognized failures (4xx/5xx from the service).","triggerScenarios":"412 Precondition Failed — the IfMatch etag from the prior HeadObject changed because another writer persisted state between the head and the get; 401/403 expired token or revoked permission; 429 throttling; 500/503 service errors; 409 conflicts.","commonSituations":"Two CI jobs writing state concurrently (etag races → 412); long-running apply whose token expired mid-run; throttling under high CI concurrency against the same bucket; OCI regional incident.","solutions":["Copy the OpcRequestId and look it up in OCI Console > Governance > Audit / Object Storage diagnostics to pinpoint the failure.","For HTTP 412, retry the full Get — the etag moved; the retry policy will re-Head and get a fresh etag only if the whole getObject is retried.","For 401/403, refresh the principal/token (instance metadata, OCI config, session token) before retrying.","For 429/5xx, reduce concurrency and apply backoff."],"exampleFix":"// before: long apply whose pre-token expired or whose etag raced\n//   -> \"failed to access object HttpStatusCode: 412 ... OpcRequestId: ABC\"\n// after: retry the read on 412 and refresh creds on 401/403\nfor attempt := 0; attempt < 3; attempt++ {\n    payload, err := client.Get()\n    if err == nil { break }\n    var se common.ServiceError\n    if errors.As(err, &se) && (se.GetHTTPStatusCode() == 412 || se.GetHTTPStatusCode() >= 500) {\n        time.Sleep(time.Duration(1<<attempt) * time.Second)\n        continue\n    }\n    return err\n}","handlingStrategy":"try-catch","validationCode":null,"typeGuard":"func serviceErrorOf(err error) (common.ServiceError, bool) {\n    var se common.ServiceError\n    return se, errors.As(err, &se)\n}","tryCatchPattern":"payload, err := c.objectStorageClient.GetObject(ctx, getRequest)\nif err != nil {\n    var se common.ServiceError\n    if errors.As(err, &se) {\n        switch code := se.GetHTTPStatusCode(); {\n        case code == 412: // etag race -> re-Head and retry the whole getObject\n        case code == 401 || code == 403: // refresh creds\n        case code == 429 || code >= 500: // backoff and retry\n        }\n    }\n}","preventionTips":["Avoid concurrent writers to the same workspace to prevent etag races (412).","Refresh long-lived credentials before large state downloads.","Capture OpcRequestId in logs for OCI-side lookup.","Throttle CI concurrency against the same bucket to avoid 429s."],"tags":["oci","object-storage","network","iam","diagnostics"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}