hashicorp/terraform · error
get Ecs sts token err
Error message
get Ecs sts token err : %s
What it means
Thrown by getAuthCredentialByEcsRoleName() when the HTTP client fails to reach the ECS instance metadata service at http://100.100.100.200. This IP is the link-local address for Alibaba Cloud's instance metadata service (similar to AWS 169.254.169.254). The error indicates the request could not be completed.
Solutions
- Do not configure ecs_role_name unless running on an Alibaba Cloud ECS instance with a RAM role attached.
- If on ECS, ensure security groups allow outbound traffic to 100.100.100.200.
- For containerized environments, use host networking or ensure the metadata IP is routable.
- Switch to static credentials (access_key/secret_key) or STS tokens when not on ECS.
Example fix
// before — running outside ECS with ecs_role_name
terraform {
backend "oss" {
ecs_role_name = "my-ram-role"
// no access_key / secret_key provided
}
}
// after — use static credentials when not on ECS
terraform {
backend "oss" {
access_key = "AKIAXXXXXXXX"
secret_key = "your-secret-key"
}
} Defensive patterns
Strategy: validation
Validate before calling
// Validate that ECS metadata service is reachable before using ecs_role_name
func checkECSMetadataService() error {
conn, err := net.DialTimeout("tcp", "100.100.100.200:80", 3*time.Second)
if err != nil {
return fmt.Errorf("ECS metadata service unreachable — you are likely not on an Alibaba Cloud ECS instance: %w", err)
}
conn.Close()
return nil
}
// Call this before relying on ecs_role_name authentication:
if err := checkECSMetadataService(); err != nil {
log.Fatal("ecs_role_name requires running on Alibaba Cloud ECS; use access_key/secret_key instead")
} Prevention
- Only use ecs_role_name when running Terraform/OpenTofu on an Alibaba Cloud ECS instance.
- For local, CI/CD, or cross-cloud environments, use static credentials or STS tokens instead.
- In containers, ensure the pod can route to 100.100.100.200 (use host networking if needed).
- Check security group rules allow outbound to the metadata service IP.
When it happens
Trigger: httpClient.Do(httpRequest) returns an error. The request targets http://100.100.100.200/latest/meta-data/ram/security-credentials/<role>. Fails when: the machine is not an Alibaba Cloud ECS instance, the metadata service is unreachable (network/firewall), DNS/routing issue, or connection timeout.
Common situations: Running Terraform/OpenTofu outside of Alibaba Cloud ECS (local machine, on-premises, AWS/GCP) with ecs_role_name configured. Running inside a container without host network access to the metadata IP. Security group or iptables rules blocking access to 100.100.100.200. Network namespace isolation in Kubernetes pods.
Related errors
- build sts requests err
- refresh Ecs sts token err, json.Unmarshal fail
- get Ecs sts token err, httpStatus
- unable to initialize the location client: %#v
- unmarshal Ecs sts token response err
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/88e6c3c9c8a4c47e.
Report an issue: GitHub.
Appendix: source
Thrown at internal/backend/remote-state/oss/backend.go:658
// Actually, the job should be done by sdk, but currently not all resources and products support alibaba-cloud-sdk-go,
// and their go sdk does support ecs role name.
// This method is a temporary solution and it should be removed after all go sdk support ecs role name
// The related PR: https://github.com/terraform-providers/terraform-provider-alicloud/pull/731
func getAuthCredentialByEcsRoleName(ecsRoleName string) (accessKey, secretKey, token string, err error) {
if ecsRoleName == "" {
return
}
requestUrl := securityCredURL + ecsRoleName
httpRequest, err := http.NewRequest(requests.GET, requestUrl, strings.NewReader(""))
if err != nil {
err = fmt.Errorf("build sts requests err: %s", err.Error())
return
}
httpClient := &http.Client{}
httpResponse, err := httpClient.Do(httpRequest)
if err != nil {
err = fmt.Errorf("get Ecs sts token err : %s", err.Error())
return
}
response := responses.NewCommonResponse()
err = responses.Unmarshal(response, httpResponse, "")
if err != nil {
err = fmt.Errorf("unmarshal Ecs sts token response err : %s", err.Error())
return
}
if response.GetHttpStatus() != http.StatusOK {
err = fmt.Errorf("get Ecs sts token err, httpStatus: %d, message = %s", response.GetHttpStatus(), response.GetHttpContentString())
return
}
var data interface{}
err = json.Unmarshal(response.GetHttpContentBytes(), &data)
if err != nil {
err = fmt.Errorf("refresh Ecs sts token err, json.Unmarshal fail: %s", err.Error())View on GitHub (pinned to d32a084675)