hashicorp/terraform · error
there is no any available accesskey, secret and security…
Error message
there is no any available accesskey, secret and security token for Ecs role %s
What it means
Thrown after successfully extracting Code, AccessKeyId, AccessKeySecret, and SecurityToken via JMESPath without error: at least one of the three credential values was nil. The metadata service's Success response did not actually contain usable credentials.
Solutions
- Verify ecs_role_name in the backend config matches a RAM role attached to this ECS instance.
- In the Alibaba Cloud console, confirm the RAM role exists and grants the ECS service principal.
- Curl the metadata endpoint with the configured role name and confirm all three credential fields are populated.
- Retry shortly; if mid-rotation, the next refresh usually succeeds.
Defensive patterns
Strategy: validation
Validate before calling
// After all three JMESPath lookups return without error, assert none are nil.
if accessKeyId == nil || accessKeySecret == nil || securityToken == nil {
return fmt.Errorf("role %s has no usable temporary credentials", ecsRoleName)
} Type guard
func allCredentialsPresent(id, secret, token interface{}) bool {
return id != nil && secret != nil && token != nil
} Prevention
- Validate ecs_role_name against the RAM role actually attached to the instance.
- Alert on ECS RAM role detachment.
- Pre-flight probe the metadata endpoint for a fully populated credential document.
When it happens
Trigger: JMESPath searches returned nil (rather than erroring) for one or more of AccessKeyId / AccessKeySecret / SecurityToken — i.e., the fields exist as traversable structure but are absent. Typically the role has no temporary credentials to issue, or the role name does not match an attached role.
Common situations: The ecs_role_name configured points to a role that is not actually attached to the instance, the role was deleted, or the metadata service returned a Success envelope with empty credential fields during a rotation window.
Related errors
- refresh Ecs sts token err, Code is not Success
- refresh Ecs sts token err, fail to get AccessKeyId
- refresh Ecs sts token err, fail to get AccessKeySecret
- refresh Ecs sts token err, fail to get SecurityToken
- refresh Ecs sts token err, fail to get Code
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/db51f8c5be8b81f1.
Report an issue: GitHub.
Appendix: source
Thrown at internal/backend/remote-state/oss/backend.go:705
}
accessKeyId, err := jmespath.Search("AccessKeyId", data)
if err != nil {
err = fmt.Errorf("refresh Ecs sts token err, fail to get AccessKeyId: %s", err.Error())
return
}
accessKeySecret, err := jmespath.Search("AccessKeySecret", data)
if err != nil {
err = fmt.Errorf("refresh Ecs sts token err, fail to get AccessKeySecret: %s", err.Error())
return
}
securityToken, err := jmespath.Search("SecurityToken", data)
if err != nil {
err = fmt.Errorf("refresh Ecs sts token err, fail to get SecurityToken: %s", err.Error())
return
}
if accessKeyId == nil || accessKeySecret == nil || securityToken == nil {
err = fmt.Errorf("there is no any available accesskey, secret and security token for Ecs role %s", ecsRoleName)
return
}
return accessKeyId.(string), accessKeySecret.(string), securityToken.(string), nil
}
func getHttpProxyUrl(rawUrl string) (*url.URL, error) {
pc := httpproxy.FromEnvironment()
u, err := url.Parse(rawUrl)
if err != nil {
return nil, err
}
return pc.ProxyFunc()(u)
}
View on GitHub (pinned to d32a084675)