{"record":{"id":"63dbbe11e3240c77","repo":"hashicorp/terraform","slug":"error-getting-bucket-v","errorCode":null,"errorMessage":"error getting bucket: %#v","messagePattern":"error getting bucket: %#v","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/oss/backend_state.go","lineNumber":61,"sourceCode":"\t}\n\tif b.otsEndpoint != \"\" && b.otsTable != \"\" {\n\t\t_, err := b.otsClient.DescribeTable(&tablestore.DescribeTableRequest{\n\t\t\tTableName: b.otsTable,\n\t\t})\n\t\tif err != nil {\n\t\t\treturn client, fmt.Errorf(\"error describing table store %s: %#v\", b.otsTable, err)\n\t\t}\n\t}\n\n\treturn client, nil\n}\n\nfunc (b *Backend) Workspaces() ([]string, tfdiags.Diagnostics) {\n\tvar diags tfdiags.Diagnostics\n\n\tbucket, err := b.ossClient.Bucket(b.bucketName)\n\tif err != nil {\n\t\treturn []string{\"\"}, diags.Append(fmt.Errorf(\"error getting bucket: %#v\", err))\n\t}\n\n\tvar options []oss.Option\n\toptions = append(options, oss.Prefix(b.statePrefix+\"/\"), oss.MaxKeys(1000))\n\tresp, err := bucket.ListObjects(options...)\n\tif err != nil {\n\t\treturn nil, diags.Append(err)\n\t}\n\n\tresult := []string{backend.DefaultStateName}\n\tprefix := b.statePrefix\n\tlastObj := \"\"\n\tfor {\n\t\tfor _, obj := range resp.Objects {\n\t\t\t// we have 3 parts, the state prefix, the workspace name, and the state file: <prefix>/<worksapce-name>/<key>\n\t\t\tif path.Join(b.statePrefix, b.stateKey) == obj.Key {\n\t\t\t\t// filter the default workspace\n\t\t\t\tcontinue","sourceCodeStart":43,"sourceCodeEnd":79,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/oss/backend_state.go#L43-L79","documentation":"Thrown by Workspaces() when ossClient.Bucket(bucketName) fails. This is the SDK call that resolves a Bucket handle for the configured OSS bucket; failure indicates the OSS client itself rejected the configuration or could not resolve the bucket metadata.","triggerScenarios":"ossClient.Bucket returns an error during workspace enumeration — typically an invalid bucket name format, missing client configuration, or an SDK initialization defect surfacing here.","commonSituations":"Malformed bucket name (uppercase, underscores, too long), access_key_id / access_key_secret / security_token not set, region/endpoint misconfiguration, or running with stale credentials during STS refresh.","solutions":["Validate the bucket name (lowercase, 3–63 chars, DNS-compatible) in the backend config.","Ensure access_key_id, access_key_secret, and (if using STS) security_token / assumed-role are all provided.","Confirm endpoint and region match the bucket's actual region.","Re-run after refreshing credentials if this followed an STS expiry."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Validate the bucket name format before relying on the SDK.\nimport \"regexp\"\nvar bucketRe = regexp.MustCompile(`^[a-z0-9][a-z0-9-]{1,61}[a-z0-9]$`)\nif !bucketRe.MatchString(bucketName) { return fmt.Errorf(\"invalid OSS bucket name %q\", bucketName) }","typeGuard":"func validBucketName(name string) bool {\n    if len(name) < 3 || len(name) > 63 { return false }\n    match, _ := regexp.MatchString(`^[a-z0-9][a-z0-9.-]*[a-z0-9]$`, name)\n    return match\n}","tryCatchPattern":null,"preventionTips":["Configure all required credential fields (access_key_id, access_key_secret, security_token).","Match bucket region and endpoint.","Re-run 'terraform init' after credential rotation."],"tags":["alibaba-cloud","oss","bucket","terraform-backend","configuration"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}