{"record":{"id":"5ada72864d11c620","repo":"hashicorp/terraform","slug":"describe-oss-endpoint-using-region-v-got-an-err","errorCode":null,"errorMessage":"describe oss endpoint using region: %#v got an error: %#v","messagePattern":"describe oss endpoint using region: %#v got an error: %#v","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/oss/backend.go","lineNumber":458,"sourceCode":"\n\treturn err\n}\n\nfunc (b *Backend) getOSSEndpointByRegion(access_key, secret_key, security_token, region string) (*location.DescribeEndpointsResponse, error) {\n\targs := location.CreateDescribeEndpointsRequest()\n\targs.ServiceCode = \"oss\"\n\targs.Id = region\n\targs.Domain = \"location-readonly.aliyuncs.com\"\n\n\tlocationClient, err := location.NewClientWithOptions(region, getSdkConfig(), credentials.NewStsTokenCredential(access_key, secret_key, security_token))\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"unable to initialize the location client: %#v\", err)\n\n\t}\n\tlocationClient.AppendUserAgent(TerraformUA, TerraformVersion)\n\tendpointsResponse, err := locationClient.DescribeEndpoints(args)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"describe oss endpoint using region: %#v got an error: %#v\", region, err)\n\t}\n\treturn endpointsResponse, nil\n}\n\nfunc getAssumeRoleAK(accessKey, secretKey, stsToken, region, roleArn, sessionName, policy, stsEndpoint string, sessionExpiration int) (string, string, string, error) {\n\trequest := sts.CreateAssumeRoleRequest()\n\trequest.RoleArn = roleArn\n\trequest.RoleSessionName = sessionName\n\trequest.DurationSeconds = requests.NewInteger(sessionExpiration)\n\trequest.Policy = policy\n\trequest.Scheme = \"https\"\n\n\tvar client *sts.Client\n\tvar err error\n\tif stsToken == \"\" {\n\t\tclient, err = sts.NewClientWithAccessKey(region, accessKey, secretKey)\n\t} else {\n\t\tclient, err = sts.NewClientWithStsToken(region, accessKey, secretKey, stsToken)","sourceCodeStart":440,"sourceCodeEnd":476,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/oss/backend.go#L440-L476","documentation":"Thrown by getOSSEndpointByRegion() when the DescribeEndpoints API call to the Alibaba Cloud Location Service fails. This call discovers the regional OSS endpoint by querying location-readonly.aliyuncs.com with ServiceCode='oss' and the region as Id. The error includes the region and the underlying SDK error.","triggerScenarios":"locationClient.DescribeEndpoints(args) returns an error after the client was successfully initialized. Triggers include: region not supported by the location service, authentication failure (insufficient RAM permissions), network timeout, or the location service being temporarily unavailable.","commonSituations":"Using a new or rarely-used Alibaba Cloud region that the location service doesn't recognize. RAM user lacking permission to call location:DescribeEndpoints. Corporate firewall blocking access to location-readonly.aliyuncs.com. Transient location service outage. Region ID typo (e.g. 'cn-hangzhou' vs 'cn-hangzhou-west').","solutions":["Verify the region ID is a valid Alibaba Cloud OSS region.","Grant the location:DescribeEndpoints permission to the RAM user/role.","Check network access to 'location-readonly.aliyuncs.com' from your environment.","Consider setting an explicit endpoint override in the backend config to bypass location discovery.","Retry — the location service may have transient outages."],"exampleFix":null,"handlingStrategy":"retry","validationCode":"// Pre-check location service reachability\nfunc checkLocationServiceReachable() error {\n    conn, err := net.DialTimeout(\"tcp\", \"location-readonly.aliyuncs.com:443\", 5*time.Second)\n    if err != nil {\n        return fmt.Errorf(\"cannot reach location service: %w\", err)\n    }\n    conn.Close()\n    return nil\n}","typeGuard":null,"tryCatchPattern":"// Retry DescribeEndpoints with fallback to manual endpoint construction\nmaxRetries := 3\nvar endpointsResponse *location.DescribeEndpointsResponse\nfor i := 0; i < maxRetries; i++ {\n    endpointsResponse, err = locationClient.DescribeEndpoints(args)\n    if err == nil {\n        break\n    }\n    time.Sleep(time.Duration(1<<i) * time.Second)\n}\nif err != nil {\n    // Fallback: construct endpoint manually for well-known regions\n    log.Printf(\"[WARN] DescribeEndpoints failed, using default endpoint pattern: %v\", err)\n}","preventionTips":["Ensure the RAM user/role has location:DescribeEndpoints permission.","Use a valid Alibaba Cloud region identifier.","Consider setting an explicit OSS endpoint to bypass location discovery entirely.","Test connectivity to location-readonly.aliyuncs.com from your network."],"tags":["oss","location-service","network","region","permissions"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}