hashicorp/terraform · error

get Ecs sts token err

Error message

get Ecs sts token err : %s

What it means

Thrown by getAuthCredentialByEcsRoleName() when the HTTP client fails to reach the ECS instance metadata service at http://100.100.100.200. This IP is the link-local address for Alibaba Cloud's instance metadata service (similar to AWS 169.254.169.254). The error indicates the request could not be completed.

Solutions

  1. Do not configure ecs_role_name unless running on an Alibaba Cloud ECS instance with a RAM role attached.
  2. If on ECS, ensure security groups allow outbound traffic to 100.100.100.200.
  3. For containerized environments, use host networking or ensure the metadata IP is routable.
  4. Switch to static credentials (access_key/secret_key) or STS tokens when not on ECS.

Example fix

// before — running outside ECS with ecs_role_name
terraform {
  backend "oss" {
    ecs_role_name = "my-ram-role"
    // no access_key / secret_key provided
  }
}
// after — use static credentials when not on ECS
terraform {
  backend "oss" {
    access_key = "AKIAXXXXXXXX"
    secret_key = "your-secret-key"
  }
}
Defensive patterns

Strategy: validation

Validate before calling

// Validate that ECS metadata service is reachable before using ecs_role_name
func checkECSMetadataService() error {
    conn, err := net.DialTimeout("tcp", "100.100.100.200:80", 3*time.Second)
    if err != nil {
        return fmt.Errorf("ECS metadata service unreachable — you are likely not on an Alibaba Cloud ECS instance: %w", err)
    }
    conn.Close()
    return nil
}

// Call this before relying on ecs_role_name authentication:
if err := checkECSMetadataService(); err != nil {
    log.Fatal("ecs_role_name requires running on Alibaba Cloud ECS; use access_key/secret_key instead")
}

Prevention

When it happens

Trigger: httpClient.Do(httpRequest) returns an error. The request targets http://100.100.100.200/latest/meta-data/ram/security-credentials/<role>. Fails when: the machine is not an Alibaba Cloud ECS instance, the metadata service is unreachable (network/firewall), DNS/routing issue, or connection timeout.

Common situations: Running Terraform/OpenTofu outside of Alibaba Cloud ECS (local machine, on-premises, AWS/GCP) with ecs_role_name configured. Running inside a container without host network access to the metadata IP. Security group or iptables rules blocking access to 100.100.100.200. Network namespace isolation in Kubernetes pods.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/88e6c3c9c8a4c47e. Report an issue: GitHub.

Appendix: source

Thrown at internal/backend/remote-state/oss/backend.go:658

// Actually, the job should be done by sdk, but currently not all resources and products support alibaba-cloud-sdk-go,
// and their go sdk does support ecs role name.
// This method is a temporary solution and it should be removed after all go sdk support ecs role name
// The related PR: https://github.com/terraform-providers/terraform-provider-alicloud/pull/731
func getAuthCredentialByEcsRoleName(ecsRoleName string) (accessKey, secretKey, token string, err error) {

	if ecsRoleName == "" {
		return
	}
	requestUrl := securityCredURL + ecsRoleName
	httpRequest, err := http.NewRequest(requests.GET, requestUrl, strings.NewReader(""))
	if err != nil {
		err = fmt.Errorf("build sts requests err: %s", err.Error())
		return
	}
	httpClient := &http.Client{}
	httpResponse, err := httpClient.Do(httpRequest)
	if err != nil {
		err = fmt.Errorf("get Ecs sts token err : %s", err.Error())
		return
	}

	response := responses.NewCommonResponse()
	err = responses.Unmarshal(response, httpResponse, "")
	if err != nil {
		err = fmt.Errorf("unmarshal Ecs sts token response err : %s", err.Error())
		return
	}

	if response.GetHttpStatus() != http.StatusOK {
		err = fmt.Errorf("get Ecs sts token err, httpStatus: %d, message = %s", response.GetHttpStatus(), response.GetHttpContentString())
		return
	}
	var data interface{}
	err = json.Unmarshal(response.GetHttpContentBytes(), &data)
	if err != nil {
		err = fmt.Errorf("refresh Ecs sts token err, json.Unmarshal fail: %s", err.Error())

View on GitHub (pinned to d32a084675)