{"record":{"id":"a9314101b1269f39","repo":"hashicorp/terraform","slug":"unmarshal-ecs-sts-token-response-err-s","errorCode":null,"errorMessage":"unmarshal Ecs sts token response err : %s","messagePattern":"unmarshal Ecs sts token response err : (.+?)","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/oss/backend.go","lineNumber":665,"sourceCode":"\t\treturn\n\t}\n\trequestUrl := securityCredURL + ecsRoleName\n\thttpRequest, err := http.NewRequest(requests.GET, requestUrl, strings.NewReader(\"\"))\n\tif err != nil {\n\t\terr = fmt.Errorf(\"build sts requests err: %s\", err.Error())\n\t\treturn\n\t}\n\thttpClient := &http.Client{}\n\thttpResponse, err := httpClient.Do(httpRequest)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"get Ecs sts token err : %s\", err.Error())\n\t\treturn\n\t}\n\n\tresponse := responses.NewCommonResponse()\n\terr = responses.Unmarshal(response, httpResponse, \"\")\n\tif err != nil {\n\t\terr = fmt.Errorf(\"unmarshal Ecs sts token response err : %s\", err.Error())\n\t\treturn\n\t}\n\n\tif response.GetHttpStatus() != http.StatusOK {\n\t\terr = fmt.Errorf(\"get Ecs sts token err, httpStatus: %d, message = %s\", response.GetHttpStatus(), response.GetHttpContentString())\n\t\treturn\n\t}\n\tvar data interface{}\n\terr = json.Unmarshal(response.GetHttpContentBytes(), &data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, json.Unmarshal fail: %s\", err.Error())\n\t\treturn\n\t}\n\tcode, err := jmespath.Search(\"Code\", data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, fail to get Code: %s\", err.Error())\n\t\treturn\n\t}","sourceCodeStart":647,"sourceCodeEnd":683,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/oss/backend.go#L647-L683","documentation":"Thrown by getAuthCredentialByEcsRoleName() when responses.Unmarshal() fails to parse the HTTP response from the ECS metadata service into a CommonResponse. This wraps the SDK's response unmarshaling logic. The error indicates the response body could not be processed by the Alibaba Cloud SDK's response parser.","triggerScenarios":"responses.Unmarshal(response, httpResponse, \"\") returns an error after the HTTP request to 100.100.100.200 succeeds. Triggers when the metadata service returns a response in an unexpected format — not valid HTTP, missing headers, or body encoding that the SDK parser cannot handle.","commonSituations":"Metadata service returning a non-standard response (e.g. HTML error page from a transparent proxy, or an empty body). A network appliance (corporate proxy, WAF) intercepting traffic to 100.100.100.200 and returning a non-conforming response. Corrupted network data. Metadata service returning an unexpected content-encoding.","solutions":["Verify the response from 100.100.100.200 is well-formed — run 'curl http://100.100.100.200/latest/meta-data/ram/security-credentials/<role>' from the ECS instance.","Check for any network proxies or security appliances intercepting metadata traffic.","Ensure the ECS instance and its RAM role are properly configured.","If the metadata service is malfunctioning, fall back to static credentials or STS tokens."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":"// Pre-validate metadata service response format\nfunc probeMetadataService(roleName string) error {\n    url := fmt.Sprintf(\"http://100.100.100.200/latest/meta-data/ram/security-credentials/%s\", roleName)\n    resp, err := http.Get(url)\n    if err != nil {\n        return err\n    }\n    defer resp.Body.Close()\n    if resp.StatusCode != 200 {\n        return fmt.Errorf(\"metadata service returned HTTP %d\", resp.StatusCode)\n    }\n    body, err := io.ReadAll(resp.Body)\n    if err != nil {\n        return err\n    }\n    var test interface{}\n    if err := json.Unmarshal(body, &test); err != nil {\n        return fmt.Errorf(\"metadata service returned non-JSON response: %w\", err)\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":"// Handle metadata response unmarshal failure with credential fallback\nresp, err := getAuthCredentialByEcsRoleName(roleName)\nif err != nil && strings.Contains(err.Error(), \"unmarshal Ecs sts token\") {\n    log.Printf(\"[WARN] metadata service returned malformed response; falling back to static credentials\")\n    // Fall back to ALICLOUD_ACCESS_KEY / ALICLOUD_SECRET_KEY env vars\n}","preventionTips":["Verify the metadata service returns clean responses with 'curl' from the ECS instance.","Check for network proxies that may intercept metadata traffic.","Have a fallback credential strategy (static keys or STS) when ECS metadata is unreliable."],"tags":["oss","ecs","metadata-service","unmarshal","parsing"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}