hashicorp/terraform · error

expected to be in the range ( - ), got

Error message

expected %s to be in the range (%d - %d), got %d

What it means

Thrown by the ValidateFunc for 'session_expiration' in the OSS backend when the integer value falls outside the allowed range of 900 to 3600 seconds (15 minutes to 1 hour). This mirrors Alibaba Cloud STS constraints on assumed-role session durations.

Solutions

  1. Set session_expiration to a value between 900 and 3600 (inclusive), e.g. 3600 for the maximum 1-hour session.
  2. If you expected minutes, multiply by 60 — 30 minutes = 1800 seconds.
  3. Omit the field entirely if the default STS duration is acceptable.

Example fix

// before (out of range)
session_expiration = 7200
// after (within 900-3600 range)
session_expiration = 3600
Defensive patterns

Strategy: validation

Validate before calling

// Validate session_expiration range before Terraform init
func validateSessionExpiration(seconds int) error {
    const min, max = 900, 3600
    if seconds < min || seconds > max {
        return fmt.Errorf("session_expiration must be between %d and %d seconds (got %d); note: values are in seconds, not minutes", min, max, seconds)
    }
    return nil
}

Prevention

When it happens

Trigger: ValidateFunc checks value < 900 or value > 3600. The user configures session_expiration in the OSS backend block to a value outside [900, 3600]. Common invalid values: 0, 60, 600 (if expecting minutes), 7200, or negative numbers.

Common situations: Developer confuses seconds with minutes (sets 60 expecting 1 hour). Developer sets a very long expiration (7200) not supported by Alibaba Cloud STS. Developer leaves a placeholder value of 0. Copy-paste from AWS STS configuration where different limits apply (AWS allows 900-43200).

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/272ff3c488041220. Report an issue: GitHub.

Appendix: source

Thrown at internal/backend/remote-state/oss/backend.go:79

				"policy": {
					Type:        schema.TypeString,
					Optional:    true,
					Description: "The permissions applied when assuming a role. You cannot use this policy to grant permissions which exceed those of the role that is being assumed.",
				},
				"session_expiration": {
					Type:        schema.TypeInt,
					Optional:    true,
					Description: "The time after which the established session for assuming role expires.",
					ValidateFunc: func(v interface{}, k string) ([]string, []error) {
						min := 900
						max := 3600
						value, ok := v.(int)
						if !ok {
							return nil, []error{fmt.Errorf("expected type of %s to be int", k)}
						}

						if value < min || value > max {
							return nil, []error{fmt.Errorf("expected %s to be in the range (%d - %d), got %d", k, min, max, v)}
						}

						return nil, nil
					},
				},
			},
		},
	}
}

// New creates a new backend for OSS remote state.
func New() backend.Backend {
	s := &schema.Backend{
		Schema: map[string]*schema.Schema{
			"access_key": {
				Type:        schema.TypeString,
				Optional:    true,
				Description: "Alibaba Cloud Access Key ID",

View on GitHub (pinned to d32a084675)