hashicorp/terraform · error

unable to initialize the location client: %#v

Error message

unable to initialize the location client: %#v

What it means

Thrown by getOSSEndpointByRegion() when location.NewClientWithOptions() fails to create an Alibaba Cloud Location Service client. This client is used to discover the correct OSS endpoint for a given region. The error is formatted with %#v (Go syntax representation) of the underlying SDK error.

Solutions

  1. Verify the access_key, secret_key, and security_token (if using STS) are valid and not expired.
  2. Check that the region is a valid Alibaba Cloud region identifier (e.g. 'cn-hangzhou', 'us-east-1').
  3. Ensure network connectivity to 'location-readonly.aliyuncs.com'.
  4. If not using STS, verify static credentials are set via environment variables or the shared credentials file.
Defensive patterns

Strategy: try-catch

Validate before calling

// Pre-validate STS credentials before backend initialization
func validateSTSCredentials(accessKey, secretKey, securityToken string) error {
    if accessKey == "" || secretKey == "" {
        return fmt.Errorf("access_key and secret_key are required when using STS tokens")
    }
    if securityToken == "" {
        return fmt.Errorf("security_token is required for STS credential mode")
    }
    return nil
}

Try / catch

// Handle location client initialization failure with fallback
resp, err := b.getOSSEndpointByRegion(ak, sk, token, region)
if err != nil {
    log.Printf("[WARN] location service failed, trying direct endpoint: %v", err)
    // Fall back to constructing endpoint manually
    endpoint = fmt.Sprintf("https://%s.oss-%s.aliyuncs.com", bucket, region)
}

Prevention

When it happens

Trigger: location.NewClientWithOptions(region, getSdkConfig(), credentials.NewStsTokenCredential(access_key, secret_key, security_token)) returns an error. Common causes: invalid STS token credentials (nil access_key/secret_key/security_token), unsupported region string, or SDK configuration failure.

Common situations: Expired or invalid STS security token passed to the backend. Region string not recognized by the Alibaba Cloud SDK. Missing or invalid access_key/secret_key when not using STS. Network DNS resolution failure for the location service endpoint. Misconfigured endpoint override settings.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/b6a845b696c3689a. Report an issue: GitHub.

Appendix: source

Thrown at internal/backend/remote-state/oss/backend.go:452

		if otsInstanceName == "" {
			otsInstanceName = strings.Split(strings.TrimPrefix(strings.TrimPrefix(otsEndpoint, "https://"), "http://"), ".")[0]
		}
		b.otsClient = tablestore.NewClientWithConfig(otsEndpoint, otsInstanceName, accessKey, secretKey, securityToken, tablestore.NewDefaultTableStoreConfig())
	}
	b.otsTable = d.Get("tablestore_table").(string)

	return err
}

func (b *Backend) getOSSEndpointByRegion(access_key, secret_key, security_token, region string) (*location.DescribeEndpointsResponse, error) {
	args := location.CreateDescribeEndpointsRequest()
	args.ServiceCode = "oss"
	args.Id = region
	args.Domain = "location-readonly.aliyuncs.com"

	locationClient, err := location.NewClientWithOptions(region, getSdkConfig(), credentials.NewStsTokenCredential(access_key, secret_key, security_token))
	if err != nil {
		return nil, fmt.Errorf("unable to initialize the location client: %#v", err)

	}
	locationClient.AppendUserAgent(TerraformUA, TerraformVersion)
	endpointsResponse, err := locationClient.DescribeEndpoints(args)
	if err != nil {
		return nil, fmt.Errorf("describe oss endpoint using region: %#v got an error: %#v", region, err)
	}
	return endpointsResponse, nil
}

func getAssumeRoleAK(accessKey, secretKey, stsToken, region, roleArn, sessionName, policy, stsEndpoint string, sessionExpiration int) (string, string, string, error) {
	request := sts.CreateAssumeRoleRequest()
	request.RoleArn = roleArn
	request.RoleSessionName = sessionName
	request.DurationSeconds = requests.NewInteger(sessionExpiration)
	request.Policy = policy
	request.Scheme = "https"

View on GitHub (pinned to d32a084675)