{"record":{"id":"b6a845b696c3689a","repo":"hashicorp/terraform","slug":"unable-to-initialize-the-location-client-v","errorCode":null,"errorMessage":"unable to initialize the location client: %#v","messagePattern":"unable to initialize the location client: %#v","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/oss/backend.go","lineNumber":452,"sourceCode":"\t\tif otsInstanceName == \"\" {\n\t\t\totsInstanceName = strings.Split(strings.TrimPrefix(strings.TrimPrefix(otsEndpoint, \"https://\"), \"http://\"), \".\")[0]\n\t\t}\n\t\tb.otsClient = tablestore.NewClientWithConfig(otsEndpoint, otsInstanceName, accessKey, secretKey, securityToken, tablestore.NewDefaultTableStoreConfig())\n\t}\n\tb.otsTable = d.Get(\"tablestore_table\").(string)\n\n\treturn err\n}\n\nfunc (b *Backend) getOSSEndpointByRegion(access_key, secret_key, security_token, region string) (*location.DescribeEndpointsResponse, error) {\n\targs := location.CreateDescribeEndpointsRequest()\n\targs.ServiceCode = \"oss\"\n\targs.Id = region\n\targs.Domain = \"location-readonly.aliyuncs.com\"\n\n\tlocationClient, err := location.NewClientWithOptions(region, getSdkConfig(), credentials.NewStsTokenCredential(access_key, secret_key, security_token))\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"unable to initialize the location client: %#v\", err)\n\n\t}\n\tlocationClient.AppendUserAgent(TerraformUA, TerraformVersion)\n\tendpointsResponse, err := locationClient.DescribeEndpoints(args)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"describe oss endpoint using region: %#v got an error: %#v\", region, err)\n\t}\n\treturn endpointsResponse, nil\n}\n\nfunc getAssumeRoleAK(accessKey, secretKey, stsToken, region, roleArn, sessionName, policy, stsEndpoint string, sessionExpiration int) (string, string, string, error) {\n\trequest := sts.CreateAssumeRoleRequest()\n\trequest.RoleArn = roleArn\n\trequest.RoleSessionName = sessionName\n\trequest.DurationSeconds = requests.NewInteger(sessionExpiration)\n\trequest.Policy = policy\n\trequest.Scheme = \"https\"\n","sourceCodeStart":434,"sourceCodeEnd":470,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/oss/backend.go#L434-L470","documentation":"Thrown by getOSSEndpointByRegion() when location.NewClientWithOptions() fails to create an Alibaba Cloud Location Service client. This client is used to discover the correct OSS endpoint for a given region. The error is formatted with %#v (Go syntax representation) of the underlying SDK error.","triggerScenarios":"location.NewClientWithOptions(region, getSdkConfig(), credentials.NewStsTokenCredential(access_key, secret_key, security_token)) returns an error. Common causes: invalid STS token credentials (nil access_key/secret_key/security_token), unsupported region string, or SDK configuration failure.","commonSituations":"Expired or invalid STS security token passed to the backend. Region string not recognized by the Alibaba Cloud SDK. Missing or invalid access_key/secret_key when not using STS. Network DNS resolution failure for the location service endpoint. Misconfigured endpoint override settings.","solutions":["Verify the access_key, secret_key, and security_token (if using STS) are valid and not expired.","Check that the region is a valid Alibaba Cloud region identifier (e.g. 'cn-hangzhou', 'us-east-1').","Ensure network connectivity to 'location-readonly.aliyuncs.com'.","If not using STS, verify static credentials are set via environment variables or the shared credentials file."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":"// Pre-validate STS credentials before backend initialization\nfunc validateSTSCredentials(accessKey, secretKey, securityToken string) error {\n    if accessKey == \"\" || secretKey == \"\" {\n        return fmt.Errorf(\"access_key and secret_key are required when using STS tokens\")\n    }\n    if securityToken == \"\" {\n        return fmt.Errorf(\"security_token is required for STS credential mode\")\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":"// Handle location client initialization failure with fallback\nresp, err := b.getOSSEndpointByRegion(ak, sk, token, region)\nif err != nil {\n    log.Printf(\"[WARN] location service failed, trying direct endpoint: %v\", err)\n    // Fall back to constructing endpoint manually\n    endpoint = fmt.Sprintf(\"https://%s.oss-%s.aliyuncs.com\", bucket, region)\n}","preventionTips":["Verify STS tokens are fresh — tokens expire and must be rotated before backend init.","Ensure the region string is a valid Alibaba Cloud region.","Test location service connectivity from your environment before running Terraform."],"tags":["oss","location-service","authentication","sts","network"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}