{"record":{"id":"e903c542bf8471df","repo":"hashicorp/terraform","slug":"refresh-ecs-sts-token-err-json-unmarshal-fail-s","errorCode":null,"errorMessage":"refresh Ecs sts token err, json.Unmarshal fail: %s","messagePattern":"refresh Ecs sts token err, json\\.Unmarshal fail: (.+?)","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/oss/backend.go","lineNumber":676,"sourceCode":"\t\terr = fmt.Errorf(\"get Ecs sts token err : %s\", err.Error())\n\t\treturn\n\t}\n\n\tresponse := responses.NewCommonResponse()\n\terr = responses.Unmarshal(response, httpResponse, \"\")\n\tif err != nil {\n\t\terr = fmt.Errorf(\"unmarshal Ecs sts token response err : %s\", err.Error())\n\t\treturn\n\t}\n\n\tif response.GetHttpStatus() != http.StatusOK {\n\t\terr = fmt.Errorf(\"get Ecs sts token err, httpStatus: %d, message = %s\", response.GetHttpStatus(), response.GetHttpContentString())\n\t\treturn\n\t}\n\tvar data interface{}\n\terr = json.Unmarshal(response.GetHttpContentBytes(), &data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, json.Unmarshal fail: %s\", err.Error())\n\t\treturn\n\t}\n\tcode, err := jmespath.Search(\"Code\", data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, fail to get Code: %s\", err.Error())\n\t\treturn\n\t}\n\tif code.(string) != \"Success\" {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, Code is not Success\")\n\t\treturn\n\t}\n\taccessKeyId, err := jmespath.Search(\"AccessKeyId\", data)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"refresh Ecs sts token err, fail to get AccessKeyId: %s\", err.Error())\n\t\treturn\n\t}\n\taccessKeySecret, err := jmespath.Search(\"AccessKeySecret\", data)\n\tif err != nil {","sourceCodeStart":658,"sourceCodeEnd":694,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/oss/backend.go#L658-L694","documentation":"Thrown by getAuthCredentialByEcsRoleName() when json.Unmarshal() fails to parse the metadata service response body as JSON. The metadata service is expected to return a JSON object containing AccessKeyId, AccessKeySecret, SecurityToken, and Code fields. This error indicates the body was not valid JSON.","triggerScenarios":"json.Unmarshal(response.GetHttpContentBytes(), &data) fails. The metadata service returned a 200 OK response but the body is not parseable JSON — e.g. HTML, plain text error, empty string, or malformed JSON with syntax errors.","commonSituations":"Metadata service returning a cached or proxy-injected HTML page instead of JSON. Response body truncated due to network issues. An intermediary (e.g. iptables redirect, transparent proxy) replacing the response. Alibaba Cloud metadata service returning a non-JSON error format for edge cases. Encoding issues (BOM, gzip without decompression).","solutions":["Inspect the raw response body — run 'curl -v http://100.100.100.200/latest/meta-data/ram/security-credentials/<role>' from the ECS instance.","Check for proxies, DNS spoofing, or iptables rules redirecting metadata traffic.","Verify the ECS instance metadata service is functioning correctly by querying other metadata paths.","Fall back to static credentials or STS tokens if the metadata service is consistently returning non-JSON responses."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":"// Validate metadata service returns valid JSON before parsing\nfunc fetchAndValidateMetadataJSON(roleName string) (map[string]interface{}, error) {\n    url := fmt.Sprintf(\"http://100.100.100.200/latest/meta-data/ram/security-credentials/%s\", roleName)\n    resp, err := http.Get(url)\n    if err != nil {\n        return nil, err\n    }\n    defer resp.Body.Close()\n    body, err := io.ReadAll(resp.Body)\n    if err != nil {\n        return nil, err\n    }\n    var data map[string]interface{}\n    if err := json.Unmarshal(body, &data); err != nil {\n        return nil, fmt.Errorf(\"metadata service returned non-JSON body (%d bytes): %w; raw: %s\", len(body), err, string(body))\n    }\n    return data, nil\n}","typeGuard":null,"tryCatchPattern":"// Wrap credential refresh with JSON parse error handling and fallback\ncred, err := getAuthCredentialByEcsRoleName(roleName)\nif err != nil && strings.Contains(err.Error(), \"json.Unmarshal fail\") {\n    // Metadata service returned non-JSON — fall back to environment credentials\n    ak := os.Getenv(\"ALICLOUD_ACCESS_KEY\")\n    sk := os.Getenv(\"ALICLOUD_SECRET_KEY\")\n    if ak != \"\" && sk != \"\" {\n        cred = fmt.Sprintf(\"%s:%s\", ak, sk) // use env credentials\n    }\n}","preventionTips":["Test the metadata service response format with 'curl' from the ECS instance.","Ensure no proxy or network appliance intercepts metadata traffic.","Configure environment-variable-based credentials (ALICLOUD_ACCESS_KEY, ALICLOUD_SECRET_KEY) as a fallback.","Monitor for metadata service format changes after Alibaba Cloud platform updates."],"tags":["oss","ecs","metadata-service","json","parsing","authentication"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}