{"record":{"id":"8f1d20d0d987910d","repo":"hashicorp/terraform","slug":"get-ecs-sts-token-err-httpstatus-d-message","errorCode":null,"errorMessage":"get Ecs sts token err, httpStatus: %d, message = %s","messagePattern":"get Ecs sts token err, httpStatus: (.+?), message = (.+?)","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/oss/backend.go","lineNumber":670,"sourceCode":"\t\terr = fmt.Errorf(\"build sts requests err: %s\", err.Error())\n\t\treturn\n\t}\n\thttpClient := &http.Client{}\n\thttpResponse, err := httpClient.Do(httpRequest)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"get Ecs sts token err : %s\", err.Error())\n\t\treturn\n\t}\n\n\tresponse := responses.NewCommonResponse()\n\terr = responses.Unmarshal(response, httpResponse, \"\")\n\tif err != nil {\n\t\terr = fmt.Errorf(\"unmarshal Ecs sts token response err : %s\", err.Error())\n\t\treturn\n\t}\n\n\tif response.GetHttpStatus() != http.StatusOK {\n\t\terr = fmt.Errorf(\"get Ecs sts token err, httpStatus: %d, message = %s\", response.GetHttpStatus(), response.GetHttpContentString())\n\t\treturn\n\t}\n\tvar data interface{}\n\terr = json.Unmarshal(response.GetHttpContentBytes(), &data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, json.Unmarshal fail: %s\", err.Error())\n\t\treturn\n\t}\n\tcode, err := jmespath.Search(\"Code\", data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, fail to get Code: %s\", err.Error())\n\t\treturn\n\t}\n\tif code.(string) != \"Success\" {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, Code is not Success\")\n\t\treturn\n\t}\n\taccessKeyId, err := jmespath.Search(\"AccessKeyId\", data)","sourceCodeStart":652,"sourceCodeEnd":688,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/oss/backend.go#L652-L688","documentation":"Thrown by getAuthCredentialByEcsRoleName() when the ECS metadata service responds with an HTTP status code other than 200 OK. The error includes the status code and the response body content for diagnostics. This indicates the metadata endpoint was reached but returned an error.","triggerScenarios":"response.GetHttpStatus() != http.StatusOK after successful response parsing. The metadata service at 100.100.100.200 returns 404 (role not found), 403 (instance doesn't have this RAM role), 500 (internal metadata service error), or 429 (rate limited).","commonSituations":"RAM role name doesn't match any role attached to the ECS instance (404). Instance has no RAM role attached at all. The role was recently detached but the backend config still references it. Metadata service rate-limited due to frequent credential refresh calls. Alibaba Cloud metadata service transient error (5xx).","solutions":["Verify the RAM role specified in ecs_role_name is actually attached to the ECS instance in the Alibaba Cloud console.","Check that the ECS instance has a RAM role assigned — 'Instance Details > RAM Role' in the console.","If rate-limited (429), reduce the frequency of Terraform operations or cache credentials.","Retry transient 5xx errors — the metadata service may recover.","Ensure the role name matches exactly (case-sensitive) as configured in RAM."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Validate RAM role attachment before relying on ECS metadata credentials\nfunc validateRAMRoleAttached(roleName string) error {\n    url := fmt.Sprintf(\"http://100.100.100.200/latest/meta-data/ram/security-credentials/%s\", roleName)\n    resp, err := http.Get(url)\n    if err != nil {\n        return fmt.Errorf(\"metadata service unreachable: %w\", err)\n    }\n    defer resp.Body.Close()\n    if resp.StatusCode == 404 {\n        return fmt.Errorf(\"RAM role %q is not attached to this ECS instance (HTTP 404)\", roleName)\n    }\n    if resp.StatusCode != 200 {\n        return fmt.Errorf(\"metadata service returned HTTP %d for role %q\", resp.StatusCode, roleName)\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Verify in the Alibaba Cloud console that the ECS instance has the RAM role attached.","Ensure the ecs_role_name exactly matches the RAM role name (case-sensitive).","If the role was recently attached/detached, allow time for propagation before running Terraform.","Avoid frequent credential refresh calls to prevent metadata service rate limiting (429)."],"tags":["oss","ecs","metadata-service","http-status","ram-role"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}