hashicorp/terraform · error
refresh Ecs sts token err, Code is not Success
Error message
refresh Ecs sts token err, Code is not Success
What it means
Thrown when refreshing an ECS STS token: the metadata service returned HTTP 200 and parseable JSON, the 'Code' field was extracted, but its value was not the string "Success". The role-assumption call was rejected by the metadata service for a semantic reason (auth, throttling, role state) even though transport succeeded.
Solutions
- In the Alibaba Cloud console, verify the ECS instance still has the expected RAM role attached.
- Check the RAM role's trust policy allows the ecs.aliyuncs.com service principal to assume it.
- Curl the metadata endpoint from the host and read the full body — the non-Success Code and Message will state the cause.
- Retry after a short wait; if Code indicates throttling (e.g. ServiceUnavailable), reduce concurrent credential-refreshing operations.
Defensive patterns
Strategy: retry
Validate before calling
// Pre-flight: fetch metadata and assert Code == "Success" before relying on it.
resp, err := metaClient.Get(roleURL)
if err != nil { return err }
var m map[string]interface{}
if err := json.Unmarshal(resp.Body, &m); err != nil { return err }
if c, _ := m["Code"].(string); c != "Success" {
return fmt.Errorf("metadata Code=%q msg=%v", c, m["Message"])
} Try / catch
// Retry on non-Success Code with backoff; surface the Code/Message to the operator.
var creds *stkCredentials
backoff := time.Second
for attempt := 0; attempt < 5; attempt++ {
c, err := refreshEcsStsToken(role)
if err == nil { creds = c; break }
if strings.Contains(err.Error(), "Code is not Success") && attempt < 4 {
time.Sleep(backoff); backoff *= 2; continue
}
return err
} Prevention
- Alert when ECS RAM role detachment occurs so metadata Code flips away from Success.
- Keep the RAM role's trust policy scoped to ecs.aliyuncs.com.
- Run credential-refresh probes on the ECS host before terraform runs.
When it happens
Trigger: The ECS RAM role metadata endpoint returns a body whose Code is e.g. "InvalidRamRole", "NoPermission", "ServiceUnavailable", or similar — any non-"Success" code. Common when the role is being deleted, the instance is detached from the role, or the metadata service is throttling.
Common situations: A RAM role was detached from the running ECS instance, or the role's trust policy no longer permits the ECS service to assume it. Also occurs during transient metadata-service issues or when the region's metadata endpoint is degraded.
Related errors
- refresh Ecs sts token err, fail to get Code
- there is no any available accesskey, secret and security…
- refresh Ecs sts token err, fail to get AccessKeyId
- refresh Ecs sts token err, fail to get AccessKeySecret
- refresh Ecs sts token err, fail to get SecurityToken
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/ee564105959d0577.
Report an issue: GitHub.
Appendix: source
Thrown at internal/backend/remote-state/oss/backend.go:685
}
if response.GetHttpStatus() != http.StatusOK {
err = fmt.Errorf("get Ecs sts token err, httpStatus: %d, message = %s", response.GetHttpStatus(), response.GetHttpContentString())
return
}
var data interface{}
err = json.Unmarshal(response.GetHttpContentBytes(), &data)
if err != nil {
err = fmt.Errorf("refresh Ecs sts token err, json.Unmarshal fail: %s", err.Error())
return
}
code, err := jmespath.Search("Code", data)
if err != nil {
err = fmt.Errorf("refresh Ecs sts token err, fail to get Code: %s", err.Error())
return
}
if code.(string) != "Success" {
err = fmt.Errorf("refresh Ecs sts token err, Code is not Success")
return
}
accessKeyId, err := jmespath.Search("AccessKeyId", data)
if err != nil {
err = fmt.Errorf("refresh Ecs sts token err, fail to get AccessKeyId: %s", err.Error())
return
}
accessKeySecret, err := jmespath.Search("AccessKeySecret", data)
if err != nil {
err = fmt.Errorf("refresh Ecs sts token err, fail to get AccessKeySecret: %s", err.Error())
return
}
securityToken, err := jmespath.Search("SecurityToken", data)
if err != nil {
err = fmt.Errorf("refresh Ecs sts token err, fail to get SecurityToken: %s", err.Error())
return
}
View on GitHub (pinned to d32a084675)