hashicorp/terraform · error
build sts requests err
Error message
build sts requests err: %s
What it means
Thrown by getAuthCredentialByEcsRoleName() when http.NewRequest() fails to construct the HTTP GET request to the ECS instance metadata service for STS credentials. The target URL is 'http://100.100.100.200/latest/meta-data/ram/security-credentials/' + ecsRoleName. This is part of the Alibaba Cloud ECS RAM role credential resolution path.
Solutions
- Verify the ecs_role_name backend attribute contains only valid characters (alphanumeric, hyphens, underscores).
- URL-encode the role name if it may contain special characters before passing to the backend.
- Check that the value isn't accidentally empty or whitespace-only (though empty skips the function entirely).
Defensive patterns
Strategy: validation
Validate before calling
// Validate ECS role name for URL safety before use
func validateECSRoleName(roleName string) error {
if roleName == "" {
return fmt.Errorf("ecs_role_name is empty")
}
// RAM role names should be alphanumeric with hyphens/underscores
validRoleName := regexp.MustCompile(`^[a-zA-Z0-9._-]+$`)
if !validRoleName.MatchString(roleName) {
return fmt.Errorf("ecs_role_name %q contains invalid characters for URL construction", roleName)
}
return nil
} Prevention
- Use only alphanumeric characters, hyphens, underscores, and dots in RAM role names.
- Validate the ecs_role_name backend attribute before running Terraform.
- Avoid spaces or special characters in Alibaba Cloud RAM role names.
When it happens
Trigger: http.NewRequest(requests.GET, requestUrl, strings.NewReader("")) returns an error. This can only fail if the requestUrl is malformed — e.g. containing invalid characters, control characters, or if ecsRoleName contains characters that break URL parsing (spaces, newlines). The securityCredURL base is a valid constant.
Common situations: ECS role name containing invalid URL characters (spaces, special symbols). Extremely rare in practice — most RAM role names are alphanumeric with hyphens/underscores. Could indicate a configuration injection issue where the role name comes from an untrusted source.
Related errors
- get Ecs sts token err
- refresh Ecs sts token err, json.Unmarshal fail
- get Ecs sts token err, httpStatus
- unmarshal Ecs sts token response err
- refresh Ecs sts token err, Code is not Success
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/f5392bb99f787b71.
Report an issue: GitHub.
Appendix: source
Thrown at internal/backend/remote-state/oss/backend.go:652
return providerConfig[ProfileKey], nil
}
var securityCredURL = "http://100.100.100.200/latest/meta-data/ram/security-credentials/"
// getAuthCredentialByEcsRoleName aims to access meta to get sts credential
// Actually, the job should be done by sdk, but currently not all resources and products support alibaba-cloud-sdk-go,
// and their go sdk does support ecs role name.
// This method is a temporary solution and it should be removed after all go sdk support ecs role name
// The related PR: https://github.com/terraform-providers/terraform-provider-alicloud/pull/731
func getAuthCredentialByEcsRoleName(ecsRoleName string) (accessKey, secretKey, token string, err error) {
if ecsRoleName == "" {
return
}
requestUrl := securityCredURL + ecsRoleName
httpRequest, err := http.NewRequest(requests.GET, requestUrl, strings.NewReader(""))
if err != nil {
err = fmt.Errorf("build sts requests err: %s", err.Error())
return
}
httpClient := &http.Client{}
httpResponse, err := httpClient.Do(httpRequest)
if err != nil {
err = fmt.Errorf("get Ecs sts token err : %s", err.Error())
return
}
response := responses.NewCommonResponse()
err = responses.Unmarshal(response, httpResponse, "")
if err != nil {
err = fmt.Errorf("unmarshal Ecs sts token response err : %s", err.Error())
return
}
if response.GetHttpStatus() != http.StatusOK {
err = fmt.Errorf("get Ecs sts token err, httpStatus: %d, message = %s", response.GetHttpStatus(), response.GetHttpContentString())View on GitHub (pinned to d32a084675)