hashicorp/terraform · error

describe oss endpoint using region: %#v got an error: %#v

Error message

describe oss endpoint using region: %#v got an error: %#v

What it means

Thrown by getOSSEndpointByRegion() when the DescribeEndpoints API call to the Alibaba Cloud Location Service fails. This call discovers the regional OSS endpoint by querying location-readonly.aliyuncs.com with ServiceCode='oss' and the region as Id. The error includes the region and the underlying SDK error.

Solutions

  1. Verify the region ID is a valid Alibaba Cloud OSS region.
  2. Grant the location:DescribeEndpoints permission to the RAM user/role.
  3. Check network access to 'location-readonly.aliyuncs.com' from your environment.
  4. Consider setting an explicit endpoint override in the backend config to bypass location discovery.
  5. Retry — the location service may have transient outages.
Defensive patterns

Strategy: retry

Validate before calling

// Pre-check location service reachability
func checkLocationServiceReachable() error {
    conn, err := net.DialTimeout("tcp", "location-readonly.aliyuncs.com:443", 5*time.Second)
    if err != nil {
        return fmt.Errorf("cannot reach location service: %w", err)
    }
    conn.Close()
    return nil
}

Try / catch

// Retry DescribeEndpoints with fallback to manual endpoint construction
maxRetries := 3
var endpointsResponse *location.DescribeEndpointsResponse
for i := 0; i < maxRetries; i++ {
    endpointsResponse, err = locationClient.DescribeEndpoints(args)
    if err == nil {
        break
    }
    time.Sleep(time.Duration(1<<i) * time.Second)
}
if err != nil {
    // Fallback: construct endpoint manually for well-known regions
    log.Printf("[WARN] DescribeEndpoints failed, using default endpoint pattern: %v", err)
}

Prevention

When it happens

Trigger: locationClient.DescribeEndpoints(args) returns an error after the client was successfully initialized. Triggers include: region not supported by the location service, authentication failure (insufficient RAM permissions), network timeout, or the location service being temporarily unavailable.

Common situations: Using a new or rarely-used Alibaba Cloud region that the location service doesn't recognize. RAM user lacking permission to call location:DescribeEndpoints. Corporate firewall blocking access to location-readonly.aliyuncs.com. Transient location service outage. Region ID typo (e.g. 'cn-hangzhou' vs 'cn-hangzhou-west').

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/5ada72864d11c620. Report an issue: GitHub.

Appendix: source

Thrown at internal/backend/remote-state/oss/backend.go:458

	return err
}

func (b *Backend) getOSSEndpointByRegion(access_key, secret_key, security_token, region string) (*location.DescribeEndpointsResponse, error) {
	args := location.CreateDescribeEndpointsRequest()
	args.ServiceCode = "oss"
	args.Id = region
	args.Domain = "location-readonly.aliyuncs.com"

	locationClient, err := location.NewClientWithOptions(region, getSdkConfig(), credentials.NewStsTokenCredential(access_key, secret_key, security_token))
	if err != nil {
		return nil, fmt.Errorf("unable to initialize the location client: %#v", err)

	}
	locationClient.AppendUserAgent(TerraformUA, TerraformVersion)
	endpointsResponse, err := locationClient.DescribeEndpoints(args)
	if err != nil {
		return nil, fmt.Errorf("describe oss endpoint using region: %#v got an error: %#v", region, err)
	}
	return endpointsResponse, nil
}

func getAssumeRoleAK(accessKey, secretKey, stsToken, region, roleArn, sessionName, policy, stsEndpoint string, sessionExpiration int) (string, string, string, error) {
	request := sts.CreateAssumeRoleRequest()
	request.RoleArn = roleArn
	request.RoleSessionName = sessionName
	request.DurationSeconds = requests.NewInteger(sessionExpiration)
	request.Policy = policy
	request.Scheme = "https"

	var client *sts.Client
	var err error
	if stsToken == "" {
		client, err = sts.NewClientWithAccessKey(region, accessKey, secretKey)
	} else {
		client, err = sts.NewClientWithStsToken(region, accessKey, secretKey, stsToken)

View on GitHub (pinned to d32a084675)