{"record":{"id":"db51f8c5be8b81f1","repo":"hashicorp/terraform","slug":"there-is-no-any-available-accesskey-secret-and-se","errorCode":null,"errorMessage":"there is no any available accesskey, secret and security token for Ecs role %s","messagePattern":"there is no any available accesskey, secret and security token for Ecs role (.+?)","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/oss/backend.go","lineNumber":705,"sourceCode":"\t}\n\taccessKeyId, err := jmespath.Search(\"AccessKeyId\", data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, fail to get AccessKeyId: %s\", err.Error())\n\t\treturn\n\t}\n\taccessKeySecret, err := jmespath.Search(\"AccessKeySecret\", data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, fail to get AccessKeySecret: %s\", err.Error())\n\t\treturn\n\t}\n\tsecurityToken, err := jmespath.Search(\"SecurityToken\", data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, fail to get SecurityToken: %s\", err.Error())\n\t\treturn\n\t}\n\n\tif accessKeyId == nil || accessKeySecret == nil || securityToken == nil {\n\t\terr = fmt.Errorf(\"there is no any available accesskey, secret and security token for Ecs role %s\", ecsRoleName)\n\t\treturn\n\t}\n\n\treturn accessKeyId.(string), accessKeySecret.(string), securityToken.(string), nil\n}\n\nfunc getHttpProxyUrl(rawUrl string) (*url.URL, error) {\n\tpc := httpproxy.FromEnvironment()\n\tu, err := url.Parse(rawUrl)\n\tif err != nil {\n\t\treturn nil, err\n\t}\n\treturn pc.ProxyFunc()(u)\n}\n","sourceCodeStart":687,"sourceCodeEnd":720,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/oss/backend.go#L687-L720","documentation":"Thrown after successfully extracting Code, AccessKeyId, AccessKeySecret, and SecurityToken via JMESPath without error: at least one of the three credential values was nil. The metadata service's Success response did not actually contain usable credentials.","triggerScenarios":"JMESPath searches returned nil (rather than erroring) for one or more of AccessKeyId / AccessKeySecret / SecurityToken — i.e., the fields exist as traversable structure but are absent. Typically the role has no temporary credentials to issue, or the role name does not match an attached role.","commonSituations":"The ecs_role_name configured points to a role that is not actually attached to the instance, the role was deleted, or the metadata service returned a Success envelope with empty credential fields during a rotation window.","solutions":["Verify ecs_role_name in the backend config matches a RAM role attached to this ECS instance.","In the Alibaba Cloud console, confirm the RAM role exists and grants the ECS service principal.","Curl the metadata endpoint with the configured role name and confirm all three credential fields are populated.","Retry shortly; if mid-rotation, the next refresh usually succeeds."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// After all three JMESPath lookups return without error, assert none are nil.\nif accessKeyId == nil || accessKeySecret == nil || securityToken == nil {\n    return fmt.Errorf(\"role %s has no usable temporary credentials\", ecsRoleName)\n}","typeGuard":"func allCredentialsPresent(id, secret, token interface{}) bool {\n    return id != nil && secret != nil && token != nil\n}","tryCatchPattern":null,"preventionTips":["Validate ecs_role_name against the RAM role actually attached to the instance.","Alert on ECS RAM role detachment.","Pre-flight probe the metadata endpoint for a fully populated credential document."],"tags":["alibaba-cloud","ecs","sts","iam","ram-role","credentials"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}