hashicorp/terraform · error
error describing table store
Error message
error describing table store %s: %#v
What it means
Thrown by remoteClient() when both ots_endpoint and ots_table are configured: the Tablestore (OTS) DescribeTable call failed. The backend pre-flight checks that the configured locking table exists and is reachable before using it for state locking.
Solutions
- Confirm ots_table matches an existing Tablestore table in the Alibaba Cloud console.
- Verify ots_endpoint is the correct regional endpoint for that table.
- Grant the credentials the Tablestore access (ots:DescribeTable, ots:GetRow, ots:PutRow, ots:DeleteRow) on the table.
- Check network egress from the runner to the OTS endpoint (security groups, NAT, proxies).
Defensive patterns
Strategy: validation
Validate before calling
// Before terraform runs, verify the OTS table exists and is describable.
desc, err := otsClient.DescribeTable(&tablestore.DescribeTableRequest{TableName: table})
if err != nil { return fmt.Errorf("pre-flight DescribeTable failed: %w", err) } Prevention
- Create the Tablestore lock table once during environment provisioning.
- Grant ots:DescribeTable, ots:GetRow, ots:PutRow, ots:DeleteRow to the deployer principal.
- Use the same region endpoint for OTS and OSS to reduce latency/permission mismatch.
When it happens
Trigger: Calling OTS DescribeTable for the configured table name and getting any error: table not found, authentication failure, endpoint unreachable, or permission denied on the tablestore:DescribeTable action.
Common situations: Mis-typed ots_table name, table not yet created, ots_endpoint pointing at the wrong region, RAM user/role lacking Tablestore permissions, or network/firewall blocking the OTS endpoint.
Related errors
- failed to retrieve lock info
- failed to store state MD5
- error deleting state
- Error unlocking Alibaba Cloud OSS state file: Lock ID
- failed to lock OSS state
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/0b69857801f002f0.
Report an issue: GitHub.
Appendix: source
Thrown at internal/backend/remote-state/oss/backend_state.go:49
return nil, errors.New("missing state name")
}
client := &RemoteClient{
ossClient: b.ossClient,
bucketName: b.bucketName,
stateFile: b.stateFile(name),
lockFile: b.lockFile(name),
serverSideEncryption: b.serverSideEncryption,
acl: b.acl,
otsTable: b.otsTable,
otsClient: b.otsClient,
}
if b.otsEndpoint != "" && b.otsTable != "" {
_, err := b.otsClient.DescribeTable(&tablestore.DescribeTableRequest{
TableName: b.otsTable,
})
if err != nil {
return client, fmt.Errorf("error describing table store %s: %#v", b.otsTable, err)
}
}
return client, nil
}
func (b *Backend) Workspaces() ([]string, tfdiags.Diagnostics) {
var diags tfdiags.Diagnostics
bucket, err := b.ossClient.Bucket(b.bucketName)
if err != nil {
return []string{""}, diags.Append(fmt.Errorf("error getting bucket: %#v", err))
}
var options []oss.Option
options = append(options, oss.Prefix(b.statePrefix+"/"), oss.MaxKeys(1000))
resp, err := bucket.ListObjects(options...)
if err != nil {View on GitHub (pinned to d32a084675)