hashicorp/terraform · error
unable to initialize the location client: %#v
Error message
unable to initialize the location client: %#v
What it means
Thrown by getOSSEndpointByRegion() when location.NewClientWithOptions() fails to create an Alibaba Cloud Location Service client. This client is used to discover the correct OSS endpoint for a given region. The error is formatted with %#v (Go syntax representation) of the underlying SDK error.
Solutions
- Verify the access_key, secret_key, and security_token (if using STS) are valid and not expired.
- Check that the region is a valid Alibaba Cloud region identifier (e.g. 'cn-hangzhou', 'us-east-1').
- Ensure network connectivity to 'location-readonly.aliyuncs.com'.
- If not using STS, verify static credentials are set via environment variables or the shared credentials file.
Defensive patterns
Strategy: try-catch
Validate before calling
// Pre-validate STS credentials before backend initialization
func validateSTSCredentials(accessKey, secretKey, securityToken string) error {
if accessKey == "" || secretKey == "" {
return fmt.Errorf("access_key and secret_key are required when using STS tokens")
}
if securityToken == "" {
return fmt.Errorf("security_token is required for STS credential mode")
}
return nil
} Try / catch
// Handle location client initialization failure with fallback
resp, err := b.getOSSEndpointByRegion(ak, sk, token, region)
if err != nil {
log.Printf("[WARN] location service failed, trying direct endpoint: %v", err)
// Fall back to constructing endpoint manually
endpoint = fmt.Sprintf("https://%s.oss-%s.aliyuncs.com", bucket, region)
} Prevention
- Verify STS tokens are fresh — tokens expire and must be rotated before backend init.
- Ensure the region string is a valid Alibaba Cloud region.
- Test location service connectivity from your environment before running Terraform.
When it happens
Trigger: location.NewClientWithOptions(region, getSdkConfig(), credentials.NewStsTokenCredential(access_key, secret_key, security_token)) returns an error. Common causes: invalid STS token credentials (nil access_key/secret_key/security_token), unsupported region string, or SDK configuration failure.
Common situations: Expired or invalid STS security token passed to the backend. Region string not recognized by the Alibaba Cloud SDK. Missing or invalid access_key/secret_key when not using STS. Network DNS resolution failure for the location service endpoint. Misconfigured endpoint override settings.
Related errors
- describe oss endpoint using region: %#v got an error: %#v
- get Ecs sts token err
- build sts requests err
- error retrieving state
- error uploading state
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/b6a845b696c3689a.
Report an issue: GitHub.
Appendix: source
Thrown at internal/backend/remote-state/oss/backend.go:452
if otsInstanceName == "" {
otsInstanceName = strings.Split(strings.TrimPrefix(strings.TrimPrefix(otsEndpoint, "https://"), "http://"), ".")[0]
}
b.otsClient = tablestore.NewClientWithConfig(otsEndpoint, otsInstanceName, accessKey, secretKey, securityToken, tablestore.NewDefaultTableStoreConfig())
}
b.otsTable = d.Get("tablestore_table").(string)
return err
}
func (b *Backend) getOSSEndpointByRegion(access_key, secret_key, security_token, region string) (*location.DescribeEndpointsResponse, error) {
args := location.CreateDescribeEndpointsRequest()
args.ServiceCode = "oss"
args.Id = region
args.Domain = "location-readonly.aliyuncs.com"
locationClient, err := location.NewClientWithOptions(region, getSdkConfig(), credentials.NewStsTokenCredential(access_key, secret_key, security_token))
if err != nil {
return nil, fmt.Errorf("unable to initialize the location client: %#v", err)
}
locationClient.AppendUserAgent(TerraformUA, TerraformVersion)
endpointsResponse, err := locationClient.DescribeEndpoints(args)
if err != nil {
return nil, fmt.Errorf("describe oss endpoint using region: %#v got an error: %#v", region, err)
}
return endpointsResponse, nil
}
func getAssumeRoleAK(accessKey, secretKey, stsToken, region, roleArn, sessionName, policy, stsEndpoint string, sessionExpiration int) (string, string, string, error) {
request := sts.CreateAssumeRoleRequest()
request.RoleArn = roleArn
request.RoleSessionName = sessionName
request.DurationSeconds = requests.NewInteger(sessionExpiration)
request.Policy = policy
request.Scheme = "https"
View on GitHub (pinned to d32a084675)