{"record":{"id":"71cbb6eb37672969","repo":"kubernetes/kops","slug":"metadata-token-was-empty","errorCode":null,"errorMessage":"metadata token was empty","messagePattern":"metadata token was empty","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"upup/pkg/fi/cloudup/linode/linodemetadata/authenticator.go","lineNumber":99,"sourceCode":"\n\ttokenResp, err := client.Do(tokenReq)\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"fetching metadata token: %w\", err)\n\t}\n\tdefer tokenResp.Body.Close()\n\n\tif tokenResp.StatusCode != http.StatusOK {\n\t\treturn \"\", fmt.Errorf(\"fetching metadata token: unexpected status code %d\", tokenResp.StatusCode)\n\t}\n\n\ttokenBytes, err := io.ReadAll(tokenResp.Body)\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"reading metadata token response: %w\", err)\n\t}\n\n\ttoken := strings.TrimSpace(string(tokenBytes))\n\tif token == \"\" {\n\t\treturn \"\", fmt.Errorf(\"metadata token was empty\")\n\t}\n\n\tinstanceReq, err := http.NewRequestWithContext(ctx, http.MethodGet, metadataBaseURL+\"/v1/instance\", nil)\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"building instance metadata request: %w\", err)\n\t}\n\tinstanceReq.Header.Set(\"Metadata-Token\", token)\n\n\tinstanceResp, err := client.Do(instanceReq)\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"fetching instance metadata: %w\", err)\n\t}\n\tdefer instanceResp.Body.Close()\n\n\tif instanceResp.StatusCode != http.StatusOK {\n\t\treturn \"\", fmt.Errorf(\"fetching instance metadata: unexpected status code %d\", instanceResp.StatusCode)\n\t}\n","sourceCodeStart":81,"sourceCodeEnd":117,"githubUrl":"https://github.com/kubernetes/kops/blob/4c8573c808a73d578c5eadc86d410646ea0b0d73/upup/pkg/fi/cloudup/linode/linodemetadata/authenticator.go#L81-L117","documentation":"getLinodeMetadataValue returns this sentinel error when the metadata service responded 200 to PUT /v1/token but the trimmed body is empty, meaning no usable metadata token was issued. It is a guard against proceeding to the instance call without credentials.","triggerScenarios":"Thrown at upup/pkg/fi/cloudup/linode/linodemetadata/authenticator.go:99 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Retry the request, as the service may have transiently returned an empty body","Check Linode metadata service health and instance metadata configuration","Log the raw response to diagnose server-side anomalies"],"exampleFix":null,"handlingStrategy":"retry","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"4c8573c808a73d578c5eadc86d410646ea0b0d73","analyzedAt":"2026-09-05T04:13:19.212Z","contentChangedAt":"2026-09-05T04:13:19.212Z","schemaVersion":2},"datasetVersion":"2026-09-12T07:17:12.445Z"}