{"record":{"id":"dd5a5aa88c78ff3e","repo":"hashicorp/terraform","slug":"refresh-ecs-sts-token-err-fail-to-get-accesskeyid","errorCode":null,"errorMessage":"refresh Ecs sts token err, fail to get AccessKeyId: %s","messagePattern":"refresh Ecs sts token err, fail to get AccessKeyId: (.+?)","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/oss/backend.go","lineNumber":690,"sourceCode":"\t}\n\tvar data interface{}\n\terr = json.Unmarshal(response.GetHttpContentBytes(), &data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, json.Unmarshal fail: %s\", err.Error())\n\t\treturn\n\t}\n\tcode, err := jmespath.Search(\"Code\", data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, fail to get Code: %s\", err.Error())\n\t\treturn\n\t}\n\tif code.(string) != \"Success\" {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, Code is not Success\")\n\t\treturn\n\t}\n\taccessKeyId, err := jmespath.Search(\"AccessKeyId\", data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, fail to get AccessKeyId: %s\", err.Error())\n\t\treturn\n\t}\n\taccessKeySecret, err := jmespath.Search(\"AccessKeySecret\", data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, fail to get AccessKeySecret: %s\", err.Error())\n\t\treturn\n\t}\n\tsecurityToken, err := jmespath.Search(\"SecurityToken\", data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, fail to get SecurityToken: %s\", err.Error())\n\t\treturn\n\t}\n\n\tif accessKeyId == nil || accessKeySecret == nil || securityToken == nil {\n\t\terr = fmt.Errorf(\"there is no any available accesskey, secret and security token for Ecs role %s\", ecsRoleName)\n\t\treturn\n\t}\n","sourceCodeStart":672,"sourceCodeEnd":708,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/oss/backend.go#L672-L708","documentation":"Thrown while refreshing an ECS STS token after 'Code' was \"Success\": a JMESPath search for 'AccessKeyId' errored. Although the response was a Success object, the JMESPath traversal of the AccessKeyId path raised an error (not nil) — typically because the data shape changed between the Code lookup and the credential lookup, or the field is nested differently than expected.","triggerScenarios":"The metadata JSON contains 'Code':'Success' but the structure around the credential fields is unexpected (e.g., credentials nested under an extra key, or the field is absent and JMESPath cannot resolve the path on the given structure).","commonSituations":"A new metadata-service version returns credentials nested under a 'Credentials' or 'SecurityToken' object while Code stays at top level; SDK/backend version mismatch; or a partial/truncated response body.","solutions":["Inspect the full metadata response body to see where AccessKeyId lives.","Align the Alibaba Cloud SDK / backend version with the metadata-service contract in your region.","Re-attach the RAM role to force a fresh, complete credential document.","If a proxy is in play, disable it for the 100.100.100.200 endpoint to avoid truncated responses."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// After metadata Success, verify AccessKeyId resolves as a non-nil string.\navid, ok := data.(map[string]interface{})[\"AccessKeyId\"].(string)\nif !ok || avid == \"\" {\n    return fmt.Errorf(\"metadata missing AccessKeyId\")\n}","typeGuard":"func hasAccessKeyId(v interface{}) bool {\n    m, ok := v.(map[string]interface{}); if !ok { return false }\n    s, ok := m[\"AccessKeyId\"].(string); return ok && s != \"\"\n}","tryCatchPattern":null,"preventionTips":["Lock SDK/backend versions to ones tested against your metadata service.","Log the raw metadata body in a debug build to catch structural drift early.","Re-attach the RAM role when credential fields are intermittently missing."],"tags":["alibaba-cloud","ecs","sts","jmespath","iam","credentials"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}