{"record":{"id":"9a428da8f66ba5c6","repo":"hashicorp/terraform","slug":"refresh-ecs-sts-token-err-fail-to-get-accesskeyse","errorCode":null,"errorMessage":"refresh Ecs sts token err, fail to get AccessKeySecret: %s","messagePattern":"refresh Ecs sts token err, fail to get AccessKeySecret: (.+?)","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/oss/backend.go","lineNumber":695,"sourceCode":"\t\treturn\n\t}\n\tcode, err := jmespath.Search(\"Code\", data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, fail to get Code: %s\", err.Error())\n\t\treturn\n\t}\n\tif code.(string) != \"Success\" {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, Code is not Success\")\n\t\treturn\n\t}\n\taccessKeyId, err := jmespath.Search(\"AccessKeyId\", data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, fail to get AccessKeyId: %s\", err.Error())\n\t\treturn\n\t}\n\taccessKeySecret, err := jmespath.Search(\"AccessKeySecret\", data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, fail to get AccessKeySecret: %s\", err.Error())\n\t\treturn\n\t}\n\tsecurityToken, err := jmespath.Search(\"SecurityToken\", data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, fail to get SecurityToken: %s\", err.Error())\n\t\treturn\n\t}\n\n\tif accessKeyId == nil || accessKeySecret == nil || securityToken == nil {\n\t\terr = fmt.Errorf(\"there is no any available accesskey, secret and security token for Ecs role %s\", ecsRoleName)\n\t\treturn\n\t}\n\n\treturn accessKeyId.(string), accessKeySecret.(string), securityToken.(string), nil\n}\n\nfunc getHttpProxyUrl(rawUrl string) (*url.URL, error) {\n\tpc := httpproxy.FromEnvironment()","sourceCodeStart":677,"sourceCodeEnd":713,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/oss/backend.go#L677-L713","documentation":"Thrown while refreshing an ECS STS token: JMESPath search for 'AccessKeySecret' errored after AccessKeyId resolved. The Success response object did not expose AccessKeySecret in a shape JMESPath could navigate.","triggerScenarios":"Same metadata endpoint returned Success and an AccessKeyId, but the AccessKeySecret field is missing, nested unexpectedly, or the data type for that path is not traversable (e.g., an array element).","commonSituations":"Partial credential payloads from a degraded metadata service, a RAM role whose temporary credentials are mid-rotation, or an SDK/backend version that parses only some credential fields.","solutions":["Dump the full metadata JSON and confirm AccessKeySecret is present at the top level.","Re-attach or re-select the RAM role on the ECS instance to refresh the credential document.","Update the Alibaba Cloud ECS SDK and this backend to a compatible version.","Rule out middleware truncating the response body."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"sec, ok := data.(map[string]interface{})[\"AccessKeySecret\"].(string)\nif !ok || sec == \"\" {\n    return fmt.Errorf(\"metadata missing AccessKeySecret\")\n}","typeGuard":"func hasAccessKeySecret(v interface{}) bool {\n    m, ok := v.(map[string]interface{}); if !ok { return false }\n    s, ok := m[\"AccessKeySecret\"].(string); return ok && s != \"\"\n}","tryCatchPattern":null,"preventionTips":["Treat partial credential payloads as a signal to re-attach the RAM role.","Avoid long-lived processes that outlive credential rotation windows.","Pin SDK versions compatible with the metadata service shape."],"tags":["alibaba-cloud","ecs","sts","jmespath","iam","credentials"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}