{"record":{"id":"88e6c3c9c8a4c47e","repo":"hashicorp/terraform","slug":"get-ecs-sts-token-err-s","errorCode":null,"errorMessage":"get Ecs sts token err : %s","messagePattern":"get Ecs sts token err : (.+?)","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/oss/backend.go","lineNumber":658,"sourceCode":"// Actually, the job should be done by sdk, but currently not all resources and products support alibaba-cloud-sdk-go,\n// and their go sdk does support ecs role name.\n// This method is a temporary solution and it should be removed after all go sdk support ecs role name\n// The related PR: https://github.com/terraform-providers/terraform-provider-alicloud/pull/731\nfunc getAuthCredentialByEcsRoleName(ecsRoleName string) (accessKey, secretKey, token string, err error) {\n\n\tif ecsRoleName == \"\" {\n\t\treturn\n\t}\n\trequestUrl := securityCredURL + ecsRoleName\n\thttpRequest, err := http.NewRequest(requests.GET, requestUrl, strings.NewReader(\"\"))\n\tif err != nil {\n\t\terr = fmt.Errorf(\"build sts requests err: %s\", err.Error())\n\t\treturn\n\t}\n\thttpClient := &http.Client{}\n\thttpResponse, err := httpClient.Do(httpRequest)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"get Ecs sts token err : %s\", err.Error())\n\t\treturn\n\t}\n\n\tresponse := responses.NewCommonResponse()\n\terr = responses.Unmarshal(response, httpResponse, \"\")\n\tif err != nil {\n\t\terr = fmt.Errorf(\"unmarshal Ecs sts token response err : %s\", err.Error())\n\t\treturn\n\t}\n\n\tif response.GetHttpStatus() != http.StatusOK {\n\t\terr = fmt.Errorf(\"get Ecs sts token err, httpStatus: %d, message = %s\", response.GetHttpStatus(), response.GetHttpContentString())\n\t\treturn\n\t}\n\tvar data interface{}\n\terr = json.Unmarshal(response.GetHttpContentBytes(), &data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, json.Unmarshal fail: %s\", err.Error())","sourceCodeStart":640,"sourceCodeEnd":676,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/oss/backend.go#L640-L676","documentation":"Thrown by getAuthCredentialByEcsRoleName() when the HTTP client fails to reach the ECS instance metadata service at http://100.100.100.200. This IP is the link-local address for Alibaba Cloud's instance metadata service (similar to AWS 169.254.169.254). The error indicates the request could not be completed.","triggerScenarios":"httpClient.Do(httpRequest) returns an error. The request targets http://100.100.100.200/latest/meta-data/ram/security-credentials/<role>. Fails when: the machine is not an Alibaba Cloud ECS instance, the metadata service is unreachable (network/firewall), DNS/routing issue, or connection timeout.","commonSituations":"Running Terraform/OpenTofu outside of Alibaba Cloud ECS (local machine, on-premises, AWS/GCP) with ecs_role_name configured. Running inside a container without host network access to the metadata IP. Security group or iptables rules blocking access to 100.100.100.200. Network namespace isolation in Kubernetes pods.","solutions":["Do not configure ecs_role_name unless running on an Alibaba Cloud ECS instance with a RAM role attached.","If on ECS, ensure security groups allow outbound traffic to 100.100.100.200.","For containerized environments, use host networking or ensure the metadata IP is routable.","Switch to static credentials (access_key/secret_key) or STS tokens when not on ECS."],"exampleFix":"// before — running outside ECS with ecs_role_name\nterraform {\n  backend \"oss\" {\n    ecs_role_name = \"my-ram-role\"\n    // no access_key / secret_key provided\n  }\n}\n// after — use static credentials when not on ECS\nterraform {\n  backend \"oss\" {\n    access_key = \"AKIAXXXXXXXX\"\n    secret_key = \"your-secret-key\"\n  }\n}","handlingStrategy":"validation","validationCode":"// Validate that ECS metadata service is reachable before using ecs_role_name\nfunc checkECSMetadataService() error {\n    conn, err := net.DialTimeout(\"tcp\", \"100.100.100.200:80\", 3*time.Second)\n    if err != nil {\n        return fmt.Errorf(\"ECS metadata service unreachable — you are likely not on an Alibaba Cloud ECS instance: %w\", err)\n    }\n    conn.Close()\n    return nil\n}\n\n// Call this before relying on ecs_role_name authentication:\nif err := checkECSMetadataService(); err != nil {\n    log.Fatal(\"ecs_role_name requires running on Alibaba Cloud ECS; use access_key/secret_key instead\")\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Only use ecs_role_name when running Terraform/OpenTofu on an Alibaba Cloud ECS instance.","For local, CI/CD, or cross-cloud environments, use static credentials or STS tokens instead.","In containers, ensure the pod can route to 100.100.100.200 (use host networking if needed).","Check security group rules allow outbound to the metadata service IP."],"tags":["oss","ecs","metadata-service","network","authentication"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}