{"record":{"id":"bae00a6e1de004d9","repo":"kubernetes/kops","slug":"reading-metadata-token-response-w","errorCode":null,"errorMessage":"reading metadata token response: %w","messagePattern":"reading metadata token response: %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"upup/pkg/fi/cloudup/linode/linodemetadata/authenticator.go","lineNumber":94,"sourceCode":"\ttokenReq, err := http.NewRequestWithContext(ctx, http.MethodPut, metadataBaseURL+\"/v1/token\", nil)\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"building metadata token request: %w\", err)\n\t}\n\ttokenReq.Header.Set(\"Metadata-Token-Expiry-Seconds\", linodeMetadataTokenTTL)\n\n\ttokenResp, err := client.Do(tokenReq)\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"fetching metadata token: %w\", err)\n\t}\n\tdefer tokenResp.Body.Close()\n\n\tif tokenResp.StatusCode != http.StatusOK {\n\t\treturn \"\", fmt.Errorf(\"fetching metadata token: unexpected status code %d\", tokenResp.StatusCode)\n\t}\n\n\ttokenBytes, err := io.ReadAll(tokenResp.Body)\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"reading metadata token response: %w\", err)\n\t}\n\n\ttoken := strings.TrimSpace(string(tokenBytes))\n\tif token == \"\" {\n\t\treturn \"\", fmt.Errorf(\"metadata token was empty\")\n\t}\n\n\tinstanceReq, err := http.NewRequestWithContext(ctx, http.MethodGet, metadataBaseURL+\"/v1/instance\", nil)\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"building instance metadata request: %w\", err)\n\t}\n\tinstanceReq.Header.Set(\"Metadata-Token\", token)\n\n\tinstanceResp, err := client.Do(instanceReq)\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"fetching instance metadata: %w\", err)\n\t}\n\tdefer instanceResp.Body.Close()","sourceCodeStart":76,"sourceCodeEnd":112,"githubUrl":"https://github.com/kubernetes/kops/blob/4c8573c808a73d578c5eadc86d410646ea0b0d73/upup/pkg/fi/cloudup/linode/linodemetadata/authenticator.go#L76-L112","documentation":"getLinodeMetadataValue wraps io.ReadAll failure on the metadata token response body. It fires when the connection is truncated or reset mid-response after a 200 status, so the token bytes cannot be read even though the server accepted the request.","triggerScenarios":"Thrown at upup/pkg/fi/cloudup/linode/linodemetadata/authenticator.go:94 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Retry the token request; this is typically a transient network truncation","Check for flaky networking or middleboxes resetting connections to the metadata endpoint"],"exampleFix":null,"handlingStrategy":"retry","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"4c8573c808a73d578c5eadc86d410646ea0b0d73","analyzedAt":"2026-09-05T04:13:19.212Z","contentChangedAt":"2026-09-05T04:13:19.212Z","schemaVersion":2},"datasetVersion":"2026-09-12T07:17:12.445Z"}