{"record":{"id":"795f181a56e08c87","repo":"hashicorp/terraform","slug":"failed-to-open-file-at-v-v","errorCode":null,"errorMessage":"failed to open file at %v: %v","messagePattern":"failed to open file at (.+?): (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/cos/client.go","lineNumber":186,"sourceCode":"\t\treturn nil, fmt.Errorf(\"lock file %s not exists\", c.lockFile)\n\t}\n\n\tinfo := &statemgr.LockInfo{}\n\tif err := json.Unmarshal(data, info); err != nil {\n\t\treturn nil, err\n\t}\n\n\tinfo.ID = checksum\n\n\treturn info, nil\n}\n\n// getObject get remote object\nfunc (c *remoteClient) getObject(cosFile string) (exists bool, data []byte, checksum string, err error) {\n\trsp, err := c.cosClient.Object.Get(c.cosContext, cosFile, nil)\n\tif rsp == nil {\n\t\tlog.Printf(\"[DEBUG] getObject %s: error: %v\", cosFile, err)\n\t\terr = fmt.Errorf(\"failed to open file at %v: %v\", cosFile, err)\n\t\treturn\n\t}\n\tdefer rsp.Body.Close()\n\n\tlog.Printf(\"[DEBUG] getObject %s: code: %d, error: %v\", cosFile, rsp.StatusCode, err)\n\tif err != nil {\n\t\tif rsp.StatusCode == 404 {\n\t\t\terr = nil\n\t\t} else {\n\t\t\terr = fmt.Errorf(\"failed to open file at %v: %v\", cosFile, err)\n\t\t}\n\t\treturn\n\t}\n\n\tchecksum = rsp.Header.Get(\"X-Cos-Meta-Md5\")\n\tlog.Printf(\"[DEBUG] getObject %s: checksum: %s\", cosFile, checksum)\n\tif len(checksum) != 32 {\n\t\terr = fmt.Errorf(\"failed to open file at %v: checksum %s invalid\", cosFile, checksum)","sourceCodeStart":168,"sourceCodeEnd":204,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/cos/client.go#L168-L204","documentation":"Emitted by getObject() in the COS backend when the COS SDK returns a nil response pointer (rsp==nil) from Object.Get. A nil response means the SDK never received an HTTP response — typically a transport-level failure (DNS, TLS, connection refused, timeout, bad credentials producing no body). The original SDK error is wrapped for context.","triggerScenarios":"c.cosClient.Object.Get(...) returns (nil, err) due to: network unreachable, invalid endpoint/region in the COS client URL, missing or expired SecretId/SecretKey, proxy interception dropping the connection, or SDK context cancellation before any response arrived.","commonSituations":"Misconfigured `region`/`endpoint` in the COS backend config; rotated Tencent Cloud API keys not updated in TF_* env vars or backend block; running Terraform from an environment without outbound internet access to `cos.<region>.myqcloud.com`; stale `cosContext` cancelled by a parent operation.","solutions":["Check the wrapped error and the preceding DEBUG log line `getObject <file>: error:` for the SDK's underlying cause.","Verify COS credentials: ensure TENCENTCLOUD_SECRETID/TENCENTCLOUD_SECRETKEY (or backend `secret_id`/`secret_key`) are set, valid, and not expired.","Confirm the bucket region and endpoint resolve: test `cos.<region>.myqcloud.com` reachability and TLS from the host running Terraform.","Retry the operation once transient network blips are ruled out; if using a proxy, ensure HTTPS_PROXY is set correctly."],"exampleFix":"// before: backend configured without region, SDK cannot resolve endpoint\nbackend \"cos\" { bucket=\"tf-state\"; secret_id=\"...\"; secret_key=\"...\" }\n// after: supply region so the COS client URL is correct\nbackend \"cos\" { bucket=\"tf-state\"; region=\"ap-guangzhou\"; secret_id=\"...\"; secret_key=\"...\" }","handlingStrategy":"validation","validationCode":"// Validate COS client reachability and credentials before running Terraform:\nfunc cosClientWorks(ctx context.Context, client *cos.Client, bucket string) error {\n    _, rsp, err := client.Bucket.Get(ctx, &cos.BucketGetOptions{Prefix: \"\"})\n    if rsp == nil {\n        return fmt.Errorf(\"transport failure reaching COS for bucket %s: %w\", bucket, err)\n    }\n    rsp.Body.Close()\n    if rsp.StatusCode >= 400 && rsp.StatusCode != 404 {\n        return fmt.Errorf(\"COS returned status %d for bucket %s: %w\", rsp.StatusCode, bucket, err)\n    }\n    return nil\n}","typeGuard":"// Distinguish 'no response' (transport) from 'response with error' (HTTP)\nfunc isTransportFailure(rsp *cos.Response, err error) bool {\n    return rsp == nil && err != nil\n}","tryCatchPattern":"err := backend.Configure(...)\n// or after a Get/Put; if err contains 'failed to open file at' AND a network\n// error type, classify as transient and retry with backoff:\nif isTransportFailure(rsp, err) {\n    backoff.Retry(func() error { /* reissue */ }, backoff.NewExponentialBackOff())\n}","preventionTips":["Pin the COS backend `region` in the backend block so the endpoint always resolves.","Inject credentials via env vars or a secret manager; never hardcode and never let them expire silently.","Pre-flight a `cos:GetBucket` call from the host before `terraform init` to catch transport/auth issues early.","Run Terraform from a network position with reliable outbound HTTPS to Tencent Cloud."],"tags":["terraform","cos","tencent-cloud","network","credentials","remote-state","go"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}