hashicorp/terraform · error

build sts requests err

Error message

build sts requests err: %s

What it means

Thrown by getAuthCredentialByEcsRoleName() when http.NewRequest() fails to construct the HTTP GET request to the ECS instance metadata service for STS credentials. The target URL is 'http://100.100.100.200/latest/meta-data/ram/security-credentials/' + ecsRoleName. This is part of the Alibaba Cloud ECS RAM role credential resolution path.

Solutions

  1. Verify the ecs_role_name backend attribute contains only valid characters (alphanumeric, hyphens, underscores).
  2. URL-encode the role name if it may contain special characters before passing to the backend.
  3. Check that the value isn't accidentally empty or whitespace-only (though empty skips the function entirely).
Defensive patterns

Strategy: validation

Validate before calling

// Validate ECS role name for URL safety before use
func validateECSRoleName(roleName string) error {
    if roleName == "" {
        return fmt.Errorf("ecs_role_name is empty")
    }
    // RAM role names should be alphanumeric with hyphens/underscores
    validRoleName := regexp.MustCompile(`^[a-zA-Z0-9._-]+$`)
    if !validRoleName.MatchString(roleName) {
        return fmt.Errorf("ecs_role_name %q contains invalid characters for URL construction", roleName)
    }
    return nil
}

Prevention

When it happens

Trigger: http.NewRequest(requests.GET, requestUrl, strings.NewReader("")) returns an error. This can only fail if the requestUrl is malformed — e.g. containing invalid characters, control characters, or if ecsRoleName contains characters that break URL parsing (spaces, newlines). The securityCredURL base is a valid constant.

Common situations: ECS role name containing invalid URL characters (spaces, special symbols). Extremely rare in practice — most RAM role names are alphanumeric with hyphens/underscores. Could indicate a configuration injection issue where the role name comes from an untrusted source.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/f5392bb99f787b71. Report an issue: GitHub.

Appendix: source

Thrown at internal/backend/remote-state/oss/backend.go:652

	return providerConfig[ProfileKey], nil
}

var securityCredURL = "http://100.100.100.200/latest/meta-data/ram/security-credentials/"

// getAuthCredentialByEcsRoleName aims to access meta to get sts credential
// Actually, the job should be done by sdk, but currently not all resources and products support alibaba-cloud-sdk-go,
// and their go sdk does support ecs role name.
// This method is a temporary solution and it should be removed after all go sdk support ecs role name
// The related PR: https://github.com/terraform-providers/terraform-provider-alicloud/pull/731
func getAuthCredentialByEcsRoleName(ecsRoleName string) (accessKey, secretKey, token string, err error) {

	if ecsRoleName == "" {
		return
	}
	requestUrl := securityCredURL + ecsRoleName
	httpRequest, err := http.NewRequest(requests.GET, requestUrl, strings.NewReader(""))
	if err != nil {
		err = fmt.Errorf("build sts requests err: %s", err.Error())
		return
	}
	httpClient := &http.Client{}
	httpResponse, err := httpClient.Do(httpRequest)
	if err != nil {
		err = fmt.Errorf("get Ecs sts token err : %s", err.Error())
		return
	}

	response := responses.NewCommonResponse()
	err = responses.Unmarshal(response, httpResponse, "")
	if err != nil {
		err = fmt.Errorf("unmarshal Ecs sts token response err : %s", err.Error())
		return
	}

	if response.GetHttpStatus() != http.StatusOK {
		err = fmt.Errorf("get Ecs sts token err, httpStatus: %d, message = %s", response.GetHttpStatus(), response.GetHttpContentString())

View on GitHub (pinned to d32a084675)