hashicorp/terraform · error

get Ecs sts token err, httpStatus

Error message

get Ecs sts token err, httpStatus: %d, message = %s

What it means

Thrown by getAuthCredentialByEcsRoleName() when the ECS metadata service responds with an HTTP status code other than 200 OK. The error includes the status code and the response body content for diagnostics. This indicates the metadata endpoint was reached but returned an error.

Solutions

  1. Verify the RAM role specified in ecs_role_name is actually attached to the ECS instance in the Alibaba Cloud console.
  2. Check that the ECS instance has a RAM role assigned — 'Instance Details > RAM Role' in the console.
  3. If rate-limited (429), reduce the frequency of Terraform operations or cache credentials.
  4. Retry transient 5xx errors — the metadata service may recover.
  5. Ensure the role name matches exactly (case-sensitive) as configured in RAM.
Defensive patterns

Strategy: validation

Validate before calling

// Validate RAM role attachment before relying on ECS metadata credentials
func validateRAMRoleAttached(roleName string) error {
    url := fmt.Sprintf("http://100.100.100.200/latest/meta-data/ram/security-credentials/%s", roleName)
    resp, err := http.Get(url)
    if err != nil {
        return fmt.Errorf("metadata service unreachable: %w", err)
    }
    defer resp.Body.Close()
    if resp.StatusCode == 404 {
        return fmt.Errorf("RAM role %q is not attached to this ECS instance (HTTP 404)", roleName)
    }
    if resp.StatusCode != 200 {
        return fmt.Errorf("metadata service returned HTTP %d for role %q", resp.StatusCode, roleName)
    }
    return nil
}

Prevention

When it happens

Trigger: response.GetHttpStatus() != http.StatusOK after successful response parsing. The metadata service at 100.100.100.200 returns 404 (role not found), 403 (instance doesn't have this RAM role), 500 (internal metadata service error), or 429 (rate limited).

Common situations: RAM role name doesn't match any role attached to the ECS instance (404). Instance has no RAM role attached at all. The role was recently detached but the backend config still references it. Metadata service rate-limited due to frequent credential refresh calls. Alibaba Cloud metadata service transient error (5xx).

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/8f1d20d0d987910d. Report an issue: GitHub.

Appendix: source

Thrown at internal/backend/remote-state/oss/backend.go:670

		err = fmt.Errorf("build sts requests err: %s", err.Error())
		return
	}
	httpClient := &http.Client{}
	httpResponse, err := httpClient.Do(httpRequest)
	if err != nil {
		err = fmt.Errorf("get Ecs sts token err : %s", err.Error())
		return
	}

	response := responses.NewCommonResponse()
	err = responses.Unmarshal(response, httpResponse, "")
	if err != nil {
		err = fmt.Errorf("unmarshal Ecs sts token response err : %s", err.Error())
		return
	}

	if response.GetHttpStatus() != http.StatusOK {
		err = fmt.Errorf("get Ecs sts token err, httpStatus: %d, message = %s", response.GetHttpStatus(), response.GetHttpContentString())
		return
	}
	var data interface{}
	err = json.Unmarshal(response.GetHttpContentBytes(), &data)
	if err != nil {
		err = fmt.Errorf("refresh Ecs sts token err, json.Unmarshal fail: %s", err.Error())
		return
	}
	code, err := jmespath.Search("Code", data)
	if err != nil {
		err = fmt.Errorf("refresh Ecs sts token err, fail to get Code: %s", err.Error())
		return
	}
	if code.(string) != "Success" {
		err = fmt.Errorf("refresh Ecs sts token err, Code is not Success")
		return
	}
	accessKeyId, err := jmespath.Search("AccessKeyId", data)

View on GitHub (pinned to d32a084675)