{"record":{"id":"a314ea14555c5e4f","repo":"hashicorp/terraform","slug":"bucket-s-not-exists","errorCode":null,"errorMessage":"bucket %s not exists","messagePattern":"bucket (.+?) not exists","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/cos/client.go","lineNumber":285,"sourceCode":"\n\tlog.Printf(\"[DEBUG] deleteObject %s: code: %d, error: %v\", cosFile, rsp.StatusCode, err)\n\tif rsp.StatusCode == 404 {\n\t\treturn nil\n\t}\n\n\tif err != nil {\n\t\treturn fmt.Errorf(\"failed to delete file %v: %v\", cosFile, err)\n\t}\n\n\treturn nil\n}\n\n// getBucket list bucket by prefix\nfunc (c *remoteClient) getBucket(prefix string) (obs []cos.Object, err error) {\n\tfs, rsp, err := c.cosClient.Bucket.Get(c.cosContext, &cos.BucketGetOptions{Prefix: prefix})\n\tif rsp == nil {\n\t\tlog.Printf(\"[DEBUG] getBucket %s/%s: error: %v\", c.bucket, prefix, err)\n\t\terr = fmt.Errorf(\"bucket %s not exists\", c.bucket)\n\t\treturn\n\t}\n\tdefer rsp.Body.Close()\n\n\tlog.Printf(\"[DEBUG] getBucket %s/%s: code: %d, error: %v\", c.bucket, prefix, rsp.StatusCode, err)\n\tif rsp.StatusCode == 404 {\n\t\terr = fmt.Errorf(\"bucket %s not exists\", c.bucket)\n\t\treturn\n\t}\n\n\tif err != nil {\n\t\treturn\n\t}\n\n\treturn fs.Contents, nil\n}\n\n// putBucket create cos bucket","sourceCodeStart":267,"sourceCodeEnd":303,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/cos/client.go#L267-L303","documentation":"Returned by getBucket() when the COS SDK returns a nil response pointer from Bucket.Get (list). On the list path the backend interprets a nil response as 'bucket not exists', which is an imperfect mapping — the real cause may be transport failure rather than absence.","triggerScenarios":"c.cosClient.Bucket.Get(...) returns (nil, rsp, err). Network failure, invalid endpoint, bad credentials, or the bucket genuinely being unreachable all collapse into this single message.","commonSituations":"Wrong `region` for the bucket name; APPID not embedded in the bucket name (`<bucket>-<appid>`); credentials lack `cos:GetBucket`; no outbound connectivity; transient DNS failure.","solutions":["Look at DEBUG line `getBucket <bucket>/<prefix>: error:` for the underlying SDK error.","Confirm the bucket name includes the APPID suffix and the region matches.","Grant `cos:GetBucket` (list) permission to the principal.","Verify network reachability to COS and retry."],"exampleFix":"// before: bucket name without APPID\nbackend \"cos\" { bucket=\"tf-state\"; region=\"ap-guangzhou\" }\n// after: append APPID\nbackend \"cos\" { bucket=\"tf-state-1250000000\"; region=\"ap-guangzhou\" }","handlingStrategy":"validation","validationCode":"// Pre-flight: validate the bucket name (with APPID) and list permission\nfunc bucketAccessible(ctx context.Context, client *cos.Client, bucket string) error {\n    _, rsp, err := client.Bucket.Get(ctx, &cos.BucketGetOptions{Prefix: \"\"})\n    if rsp == nil { return fmt.Errorf(\"could not reach COS for bucket %s: %w\", bucket, err) }\n    defer rsp.Body.Close()\n    if rsp.StatusCode == 404 { return fmt.Errorf(\"bucket %s not found (check name-APPID and region)\", bucket) }\n    if rsp.StatusCode == 403 { return fmt.Errorf(\"principal lacks cos:GetBucket on %s\", bucket) }\n    return nil\n}","typeGuard":"func looksLikeCOSBucketName(name string) bool {\n    // <3-63 chars, lowercase, digits, hyphen>, ends with -<10 digit APPID>\n    matched, _ := regexp.MatchString(`^[a-z0-9-]{3,63}-[0-9]{10}$`, name)\n    return matched\n}","tryCatchPattern":"// Distinguish 404 (genuine absence) from nil-response (transport)\nif rsp == nil { /* transport: retry */ } else if rsp.StatusCode == 404 { /* real absence: fix config */ }","preventionTips":["Always include the APPID suffix in the COS bucket name.","Match the backend `region` to the bucket's actual region.","Grant `cos:GetBucket` to the principal.","Validate outbound connectivity before `terraform init`."],"tags":["terraform","cos","tencent-cloud","bucket","permissions","network","remote-state","go"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}