hashicorp/terraform · error

refresh Ecs sts token err, Code is not Success

Error message

refresh Ecs sts token err, Code is not Success

What it means

Thrown when refreshing an ECS STS token: the metadata service returned HTTP 200 and parseable JSON, the 'Code' field was extracted, but its value was not the string "Success". The role-assumption call was rejected by the metadata service for a semantic reason (auth, throttling, role state) even though transport succeeded.

Solutions

  1. In the Alibaba Cloud console, verify the ECS instance still has the expected RAM role attached.
  2. Check the RAM role's trust policy allows the ecs.aliyuncs.com service principal to assume it.
  3. Curl the metadata endpoint from the host and read the full body — the non-Success Code and Message will state the cause.
  4. Retry after a short wait; if Code indicates throttling (e.g. ServiceUnavailable), reduce concurrent credential-refreshing operations.
Defensive patterns

Strategy: retry

Validate before calling

// Pre-flight: fetch metadata and assert Code == "Success" before relying on it.
resp, err := metaClient.Get(roleURL)
if err != nil { return err }
var m map[string]interface{}
if err := json.Unmarshal(resp.Body, &m); err != nil { return err }
if c, _ := m["Code"].(string); c != "Success" {
    return fmt.Errorf("metadata Code=%q msg=%v", c, m["Message"])
}

Try / catch

// Retry on non-Success Code with backoff; surface the Code/Message to the operator.
var creds *stkCredentials
backoff := time.Second
for attempt := 0; attempt < 5; attempt++ {
    c, err := refreshEcsStsToken(role)
    if err == nil { creds = c; break }
    if strings.Contains(err.Error(), "Code is not Success") && attempt < 4 {
        time.Sleep(backoff); backoff *= 2; continue
    }
    return err
}

Prevention

When it happens

Trigger: The ECS RAM role metadata endpoint returns a body whose Code is e.g. "InvalidRamRole", "NoPermission", "ServiceUnavailable", or similar — any non-"Success" code. Common when the role is being deleted, the instance is detached from the role, or the metadata service is throttling.

Common situations: A RAM role was detached from the running ECS instance, or the role's trust policy no longer permits the ECS service to assume it. Also occurs during transient metadata-service issues or when the region's metadata endpoint is degraded.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/ee564105959d0577. Report an issue: GitHub.

Appendix: source

Thrown at internal/backend/remote-state/oss/backend.go:685

	}

	if response.GetHttpStatus() != http.StatusOK {
		err = fmt.Errorf("get Ecs sts token err, httpStatus: %d, message = %s", response.GetHttpStatus(), response.GetHttpContentString())
		return
	}
	var data interface{}
	err = json.Unmarshal(response.GetHttpContentBytes(), &data)
	if err != nil {
		err = fmt.Errorf("refresh Ecs sts token err, json.Unmarshal fail: %s", err.Error())
		return
	}
	code, err := jmespath.Search("Code", data)
	if err != nil {
		err = fmt.Errorf("refresh Ecs sts token err, fail to get Code: %s", err.Error())
		return
	}
	if code.(string) != "Success" {
		err = fmt.Errorf("refresh Ecs sts token err, Code is not Success")
		return
	}
	accessKeyId, err := jmespath.Search("AccessKeyId", data)
	if err != nil {
		err = fmt.Errorf("refresh Ecs sts token err, fail to get AccessKeyId: %s", err.Error())
		return
	}
	accessKeySecret, err := jmespath.Search("AccessKeySecret", data)
	if err != nil {
		err = fmt.Errorf("refresh Ecs sts token err, fail to get AccessKeySecret: %s", err.Error())
		return
	}
	securityToken, err := jmespath.Search("SecurityToken", data)
	if err != nil {
		err = fmt.Errorf("refresh Ecs sts token err, fail to get SecurityToken: %s", err.Error())
		return
	}

View on GitHub (pinned to d32a084675)