hashicorp/terraform · error
expected to be in the range ( - ), got
Error message
expected %s to be in the range (%d - %d), got %d
What it means
Thrown by the ValidateFunc for 'session_expiration' in the OSS backend when the integer value falls outside the allowed range of 900 to 3600 seconds (15 minutes to 1 hour). This mirrors Alibaba Cloud STS constraints on assumed-role session durations.
Solutions
- Set session_expiration to a value between 900 and 3600 (inclusive), e.g. 3600 for the maximum 1-hour session.
- If you expected minutes, multiply by 60 — 30 minutes = 1800 seconds.
- Omit the field entirely if the default STS duration is acceptable.
Example fix
// before (out of range) session_expiration = 7200 // after (within 900-3600 range) session_expiration = 3600
Defensive patterns
Strategy: validation
Validate before calling
// Validate session_expiration range before Terraform init
func validateSessionExpiration(seconds int) error {
const min, max = 900, 3600
if seconds < min || seconds > max {
return fmt.Errorf("session_expiration must be between %d and %d seconds (got %d); note: values are in seconds, not minutes", min, max, seconds)
}
return nil
} Prevention
- Remember Alibaba Cloud STS session durations are in seconds, 900-3600 (15min to 1hr).
- Omit session_expiration if you don't need to customize it — the default STS duration is usually fine.
- Do not copy AWS STS values (which allow up to 43200 seconds) without adjusting for Alibaba Cloud's lower maximum.
When it happens
Trigger: ValidateFunc checks value < 900 or value > 3600. The user configures session_expiration in the OSS backend block to a value outside [900, 3600]. Common invalid values: 0, 60, 600 (if expecting minutes), 7200, or negative numbers.
Common situations: Developer confuses seconds with minutes (sets 60 expecting 1 hour). Developer sets a very long expiration (7200) not supported by Alibaba Cloud STS. Developer leaves a placeholder value of 0. Copy-paste from AWS STS configuration where different limits apply (AWS allows 900-43200).
Related errors
- expected type of to be int
- key can not start and end with '/'
- must be a valid ACL value , expected , or , got
- unable to initialize the location client: %#v
- workspace_key_prefix must not start with '/' or './'
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/272ff3c488041220.
Report an issue: GitHub.
Appendix: source
Thrown at internal/backend/remote-state/oss/backend.go:79
"policy": {
Type: schema.TypeString,
Optional: true,
Description: "The permissions applied when assuming a role. You cannot use this policy to grant permissions which exceed those of the role that is being assumed.",
},
"session_expiration": {
Type: schema.TypeInt,
Optional: true,
Description: "The time after which the established session for assuming role expires.",
ValidateFunc: func(v interface{}, k string) ([]string, []error) {
min := 900
max := 3600
value, ok := v.(int)
if !ok {
return nil, []error{fmt.Errorf("expected type of %s to be int", k)}
}
if value < min || value > max {
return nil, []error{fmt.Errorf("expected %s to be in the range (%d - %d), got %d", k, min, max, v)}
}
return nil, nil
},
},
},
},
}
}
// New creates a new backend for OSS remote state.
func New() backend.Backend {
s := &schema.Backend{
Schema: map[string]*schema.Schema{
"access_key": {
Type: schema.TypeString,
Optional: true,
Description: "Alibaba Cloud Access Key ID",View on GitHub (pinned to d32a084675)