hashicorp/terraform · error

there is no any available accesskey, secret and security…

Error message

there is no any available accesskey, secret and security token for Ecs role %s

What it means

Thrown after successfully extracting Code, AccessKeyId, AccessKeySecret, and SecurityToken via JMESPath without error: at least one of the three credential values was nil. The metadata service's Success response did not actually contain usable credentials.

Solutions

  1. Verify ecs_role_name in the backend config matches a RAM role attached to this ECS instance.
  2. In the Alibaba Cloud console, confirm the RAM role exists and grants the ECS service principal.
  3. Curl the metadata endpoint with the configured role name and confirm all three credential fields are populated.
  4. Retry shortly; if mid-rotation, the next refresh usually succeeds.
Defensive patterns

Strategy: validation

Validate before calling

// After all three JMESPath lookups return without error, assert none are nil.
if accessKeyId == nil || accessKeySecret == nil || securityToken == nil {
    return fmt.Errorf("role %s has no usable temporary credentials", ecsRoleName)
}

Type guard

func allCredentialsPresent(id, secret, token interface{}) bool {
    return id != nil && secret != nil && token != nil
}

Prevention

When it happens

Trigger: JMESPath searches returned nil (rather than erroring) for one or more of AccessKeyId / AccessKeySecret / SecurityToken — i.e., the fields exist as traversable structure but are absent. Typically the role has no temporary credentials to issue, or the role name does not match an attached role.

Common situations: The ecs_role_name configured points to a role that is not actually attached to the instance, the role was deleted, or the metadata service returned a Success envelope with empty credential fields during a rotation window.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/db51f8c5be8b81f1. Report an issue: GitHub.

Appendix: source

Thrown at internal/backend/remote-state/oss/backend.go:705

	}
	accessKeyId, err := jmespath.Search("AccessKeyId", data)
	if err != nil {
		err = fmt.Errorf("refresh Ecs sts token err, fail to get AccessKeyId: %s", err.Error())
		return
	}
	accessKeySecret, err := jmespath.Search("AccessKeySecret", data)
	if err != nil {
		err = fmt.Errorf("refresh Ecs sts token err, fail to get AccessKeySecret: %s", err.Error())
		return
	}
	securityToken, err := jmespath.Search("SecurityToken", data)
	if err != nil {
		err = fmt.Errorf("refresh Ecs sts token err, fail to get SecurityToken: %s", err.Error())
		return
	}

	if accessKeyId == nil || accessKeySecret == nil || securityToken == nil {
		err = fmt.Errorf("there is no any available accesskey, secret and security token for Ecs role %s", ecsRoleName)
		return
	}

	return accessKeyId.(string), accessKeySecret.(string), securityToken.(string), nil
}

func getHttpProxyUrl(rawUrl string) (*url.URL, error) {
	pc := httpproxy.FromEnvironment()
	u, err := url.Parse(rawUrl)
	if err != nil {
		return nil, err
	}
	return pc.ProxyFunc()(u)
}

View on GitHub (pinned to d32a084675)