{"record":{"id":"bc9d1fd37f88b322","repo":"hashicorp/terraform","slug":"refresh-ecs-sts-token-err-fail-to-get-code-s","errorCode":null,"errorMessage":"refresh Ecs sts token err, fail to get Code: %s","messagePattern":"refresh Ecs sts token err, fail to get Code: (.+?)","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/oss/backend.go","lineNumber":681,"sourceCode":"\terr = responses.Unmarshal(response, httpResponse, \"\")\n\tif err != nil {\n\t\terr = fmt.Errorf(\"unmarshal Ecs sts token response err : %s\", err.Error())\n\t\treturn\n\t}\n\n\tif response.GetHttpStatus() != http.StatusOK {\n\t\terr = fmt.Errorf(\"get Ecs sts token err, httpStatus: %d, message = %s\", response.GetHttpStatus(), response.GetHttpContentString())\n\t\treturn\n\t}\n\tvar data interface{}\n\terr = json.Unmarshal(response.GetHttpContentBytes(), &data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, json.Unmarshal fail: %s\", err.Error())\n\t\treturn\n\t}\n\tcode, err := jmespath.Search(\"Code\", data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, fail to get Code: %s\", err.Error())\n\t\treturn\n\t}\n\tif code.(string) != \"Success\" {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, Code is not Success\")\n\t\treturn\n\t}\n\taccessKeyId, err := jmespath.Search(\"AccessKeyId\", data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, fail to get AccessKeyId: %s\", err.Error())\n\t\treturn\n\t}\n\taccessKeySecret, err := jmespath.Search(\"AccessKeySecret\", data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, fail to get AccessKeySecret: %s\", err.Error())\n\t\treturn\n\t}\n\tsecurityToken, err := jmespath.Search(\"SecurityToken\", data)\n\tif err != nil {","sourceCodeStart":663,"sourceCodeEnd":699,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/oss/backend.go#L663-L699","documentation":"Thrown while refreshing an ECS (Elastic Compute Service) STS token from the ECS metadata service. After HTTP 200 and successful JSON parse, a JMESPath search for the 'Code' field failed. This means the parsed response body was not a JSON object graph that JMESPath could traverse (e.g., a bare array, scalar, or unexpected shape), so the search itself errored rather than returning nil.","triggerScenarios":"Calling the ECS RAM role metadata endpoint (typically http://100.100.100.200/latest/meta-data/.../security-credentials/<role>) where the returned body parses as valid JSON but is not an object — for example a top-level array, a string, or a body whose shape changed because the metadata service returned an unexpected envelope.","commonSituations":"Running terraform init/plan on an ECS instance configured with an assumed RAM role, but the metadata service returned an error envelope in a non-object shape, or a proxy/middleware rewrote the response. Also seen when the ECS SDK version returns a different response structure than the JMESPath expression expects.","solutions":["From the instance, curl the ECS metadata URL directly (curl 'http://100.100.100.200/latest/meta-data/ram/security-credentials/<role-name>') and inspect the raw JSON shape.","Confirm the response is a JSON object containing a 'Code' key; if the envelope differs, update the Alibaba Cloud ECS SDK or this backend to a version matching the metadata service contract.","Verify no HTTP proxy is intercepting and rewriting the metadata response (check HTTP_PROXY/HTTPS_PROXY).","Ensure the ECS instance actually has a RAM role attached; a missing role can produce a non-standard error body."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Before calling the metadata-backed refresh, sanity-check that the parsed body is an object.\n// (Mirrors what the backend itself does; do this in your own wrapper / integration tests.)\nvar data interface{}\nif err := json.Unmarshal(body, &data); err != nil { return err }\nif _, ok := data.(map[string]interface{}); !ok {\n    return fmt.Errorf(\"metadata response is not a JSON object: %T\", data)\n}","typeGuard":"// Ensure the parsed metadata body is a JSON object before JMESPath traversal.\nfunc isJSONObject(v interface{}) bool {\n    _, ok := v.(map[string]interface{})\n    return ok\n}","tryCatchPattern":null,"preventionTips":["Pin the Alibaba Cloud ECS SDK and backend versions known to match your region's metadata service contract.","Disable HTTP proxying for the 100.100.100.200 metadata endpoint.","In CI on ECS, run a pre-flight curl of the metadata endpoint that asserts JSON-object shape and a 'Code':'Success' field."],"tags":["alibaba-cloud","ecs","sts","jmespath","metadata-service","iam"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}