{"record":{"id":"e2d7ebfd7310b5d0","repo":"JuliusBrussee/caveman","slug":"awscreds-read-s-response-w","errorCode":null,"errorMessage":"awscreds: read %s response: %w","messagePattern":"awscreds: read (.+?) response: %w","errorType":"http","errorClass":null,"httpStatus":null,"severity":"error","filePath":"shared/platform/awscreds/awscreds.go","lineNumber":610,"sourceCode":"\treq, err := http.NewRequestWithContext(ctx, http.MethodGet, endpoint, nil)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"awscreds: build %s request: %w\", what, err)\n\t}\n\treq.Header.Set(\"X-aws-ec2-metadata-token\", token)\n\treturn p.doJSON(p.link, req, what)\n}\n\n// doJSON performs one attempt and returns the bounded body. A non-2xx response\n// is reported by status only: a metadata body holds credential material.\nfunc (p *Provider) doJSON(client *http.Client, req *http.Request, what string) ([]byte, error) {\n\tresp, err := client.Do(req)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"awscreds: %s request failed: %w\", what, err)\n\t}\n\tdefer resp.Body.Close()\n\tbody, err := io.ReadAll(io.LimitReader(resp.Body, maxBody))\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"awscreds: read %s response: %w\", what, err)\n\t}\n\tif resp.StatusCode < 200 || resp.StatusCode > 299 {\n\t\treturn nil, fmt.Errorf(\"awscreds: %s: http %d\", what, resp.StatusCode)\n\t}\n\treturn body, nil\n}\n\nfunc credentialsFromJSON(body []byte, source string) (*result, error) {\n\tvar parsed credentialJSON\n\tif err := json.Unmarshal(body, &parsed); err != nil {\n\t\treturn nil, fmt.Errorf(\"awscreds: %s returned an unparseable response\", source)\n\t}\n\tif parsed.Code != \"\" && !strings.EqualFold(parsed.Code, \"Success\") {\n\t\treturn nil, fmt.Errorf(\"awscreds: %s returned code %q\", source, parsed.Code)\n\t}\n\texpires, err := parseExpiry(parsed.Expiration)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"awscreds: %s credential expiry: %w\", source, err)","sourceCodeStart":592,"sourceCodeEnd":628,"githubUrl":"https://github.com/JuliusBrussee/caveman/blob/3ee70a102609e550bd2e68004bf5990a9341c851/shared/platform/awscreds/awscreds.go#L592-L628","documentation":"doJSON wraps an error from reading the response body (io.ReadAll over a maxBody-bounded LimitReader) for a container or IMDS request. The connection opened and the status was received, but the body could not be fully read — typically the connection dropped mid-response.","triggerScenarios":"The metadata server closes or resets the connection while the body is being read; network interruption mid-response; a proxy terminating the connection early; the peer sending a body larger than the reader tolerates in a way that breaks the connection.","commonSituations":"Flaky metadata service under instance overload; NAT or security appliance killing idle keep-alive connections mid-transfer; buggy local metadata simulator that half-closes responses.","solutions":["Retry the request — the metadata endpoints are idempotent GET/PUT and transient resets usually clear.","Check metadata service health on the host (curl -v the endpoint) to reproduce the mid-body drop.","Disable suspicious proxies/middleboxes between the process and the metadata address.","Inspect the wrapped cause (unexpected EOF, connection reset) to target the network fix."],"exampleFix":"// before\nbody, err := doJSON(client, req, \"imds credentials\")\nif err != nil { return nil, err } // single attempt\n// after\nbody, err := retry(3, func() ([]byte, error) {\n    return doJSON(client, req, \"imds credentials\")\n})","handlingStrategy":"retry","validationCode":null,"typeGuard":null,"tryCatchPattern":"body, err := doJSON(client, req, what)\nif err != nil {\n    if errors.Is(err, io.ErrUnexpectedEOF) || strings.Contains(err.Error(), \"connection reset\") {\n        // bounded retry with backoff; metadata endpoints are idempotent\n    }\n}","preventionTips":["Retry idempotent metadata GET/PUT up to 2-3 times with small backoff","Keep the default body size limit — don't bypass it","Monitor metadata service latency on busy instances","Avoid proxies between the workload and link-local metadata addresses"],"tags":["network","aws","imds","io","connection-reset"],"backgroundTag":"network-request-failed","analyzedSha":"3ee70a102609e550bd2e68004bf5990a9341c851","analyzedAt":"2026-09-20T15:53:39.229Z","contentChangedAt":"2026-09-20T15:53:39.229Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}