hashicorp/terraform · error
describe oss endpoint using region: %#v got an error: %#v
Error message
describe oss endpoint using region: %#v got an error: %#v
What it means
Thrown by getOSSEndpointByRegion() when the DescribeEndpoints API call to the Alibaba Cloud Location Service fails. This call discovers the regional OSS endpoint by querying location-readonly.aliyuncs.com with ServiceCode='oss' and the region as Id. The error includes the region and the underlying SDK error.
Solutions
- Verify the region ID is a valid Alibaba Cloud OSS region.
- Grant the location:DescribeEndpoints permission to the RAM user/role.
- Check network access to 'location-readonly.aliyuncs.com' from your environment.
- Consider setting an explicit endpoint override in the backend config to bypass location discovery.
- Retry — the location service may have transient outages.
Defensive patterns
Strategy: retry
Validate before calling
// Pre-check location service reachability
func checkLocationServiceReachable() error {
conn, err := net.DialTimeout("tcp", "location-readonly.aliyuncs.com:443", 5*time.Second)
if err != nil {
return fmt.Errorf("cannot reach location service: %w", err)
}
conn.Close()
return nil
} Try / catch
// Retry DescribeEndpoints with fallback to manual endpoint construction
maxRetries := 3
var endpointsResponse *location.DescribeEndpointsResponse
for i := 0; i < maxRetries; i++ {
endpointsResponse, err = locationClient.DescribeEndpoints(args)
if err == nil {
break
}
time.Sleep(time.Duration(1<<i) * time.Second)
}
if err != nil {
// Fallback: construct endpoint manually for well-known regions
log.Printf("[WARN] DescribeEndpoints failed, using default endpoint pattern: %v", err)
} Prevention
- Ensure the RAM user/role has location:DescribeEndpoints permission.
- Use a valid Alibaba Cloud region identifier.
- Consider setting an explicit OSS endpoint to bypass location discovery entirely.
- Test connectivity to location-readonly.aliyuncs.com from your network.
When it happens
Trigger: locationClient.DescribeEndpoints(args) returns an error after the client was successfully initialized. Triggers include: region not supported by the location service, authentication failure (insufficient RAM permissions), network timeout, or the location service being temporarily unavailable.
Common situations: Using a new or rarely-used Alibaba Cloud region that the location service doesn't recognize. RAM user lacking permission to call location:DescribeEndpoints. Corporate firewall blocking access to location-readonly.aliyuncs.com. Transient location service outage. Region ID typo (e.g. 'cn-hangzhou' vs 'cn-hangzhou-west').
Related errors
- estimating object is exist got an error: %#v
- unable to initialize the location client: %#v
- bucket not exists
- error getting object: %#v
- Error retrieving state
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/5ada72864d11c620.
Report an issue: GitHub.
Appendix: source
Thrown at internal/backend/remote-state/oss/backend.go:458
return err
}
func (b *Backend) getOSSEndpointByRegion(access_key, secret_key, security_token, region string) (*location.DescribeEndpointsResponse, error) {
args := location.CreateDescribeEndpointsRequest()
args.ServiceCode = "oss"
args.Id = region
args.Domain = "location-readonly.aliyuncs.com"
locationClient, err := location.NewClientWithOptions(region, getSdkConfig(), credentials.NewStsTokenCredential(access_key, secret_key, security_token))
if err != nil {
return nil, fmt.Errorf("unable to initialize the location client: %#v", err)
}
locationClient.AppendUserAgent(TerraformUA, TerraformVersion)
endpointsResponse, err := locationClient.DescribeEndpoints(args)
if err != nil {
return nil, fmt.Errorf("describe oss endpoint using region: %#v got an error: %#v", region, err)
}
return endpointsResponse, nil
}
func getAssumeRoleAK(accessKey, secretKey, stsToken, region, roleArn, sessionName, policy, stsEndpoint string, sessionExpiration int) (string, string, string, error) {
request := sts.CreateAssumeRoleRequest()
request.RoleArn = roleArn
request.RoleSessionName = sessionName
request.DurationSeconds = requests.NewInteger(sessionExpiration)
request.Policy = policy
request.Scheme = "https"
var client *sts.Client
var err error
if stsToken == "" {
client, err = sts.NewClientWithAccessKey(region, accessKey, secretKey)
} else {
client, err = sts.NewClientWithStsToken(region, accessKey, secretKey, stsToken)View on GitHub (pinned to d32a084675)