hashicorp/terraform · error

unmarshal Ecs sts token response err

Error message

unmarshal Ecs sts token response err : %s

What it means

Thrown by getAuthCredentialByEcsRoleName() when responses.Unmarshal() fails to parse the HTTP response from the ECS metadata service into a CommonResponse. This wraps the SDK's response unmarshaling logic. The error indicates the response body could not be processed by the Alibaba Cloud SDK's response parser.

Solutions

  1. Verify the response from 100.100.100.200 is well-formed — run 'curl http://100.100.100.200/latest/meta-data/ram/security-credentials/<role>' from the ECS instance.
  2. Check for any network proxies or security appliances intercepting metadata traffic.
  3. Ensure the ECS instance and its RAM role are properly configured.
  4. If the metadata service is malfunctioning, fall back to static credentials or STS tokens.
Defensive patterns

Strategy: try-catch

Validate before calling

// Pre-validate metadata service response format
func probeMetadataService(roleName string) error {
    url := fmt.Sprintf("http://100.100.100.200/latest/meta-data/ram/security-credentials/%s", roleName)
    resp, err := http.Get(url)
    if err != nil {
        return err
    }
    defer resp.Body.Close()
    if resp.StatusCode != 200 {
        return fmt.Errorf("metadata service returned HTTP %d", resp.StatusCode)
    }
    body, err := io.ReadAll(resp.Body)
    if err != nil {
        return err
    }
    var test interface{}
    if err := json.Unmarshal(body, &test); err != nil {
        return fmt.Errorf("metadata service returned non-JSON response: %w", err)
    }
    return nil
}

Try / catch

// Handle metadata response unmarshal failure with credential fallback
resp, err := getAuthCredentialByEcsRoleName(roleName)
if err != nil && strings.Contains(err.Error(), "unmarshal Ecs sts token") {
    log.Printf("[WARN] metadata service returned malformed response; falling back to static credentials")
    // Fall back to ALICLOUD_ACCESS_KEY / ALICLOUD_SECRET_KEY env vars
}

Prevention

When it happens

Trigger: responses.Unmarshal(response, httpResponse, "") returns an error after the HTTP request to 100.100.100.200 succeeds. Triggers when the metadata service returns a response in an unexpected format — not valid HTTP, missing headers, or body encoding that the SDK parser cannot handle.

Common situations: Metadata service returning a non-standard response (e.g. HTML error page from a transparent proxy, or an empty body). A network appliance (corporate proxy, WAF) intercepting traffic to 100.100.100.200 and returning a non-conforming response. Corrupted network data. Metadata service returning an unexpected content-encoding.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/a9314101b1269f39. Report an issue: GitHub.

Appendix: source

Thrown at internal/backend/remote-state/oss/backend.go:665

		return
	}
	requestUrl := securityCredURL + ecsRoleName
	httpRequest, err := http.NewRequest(requests.GET, requestUrl, strings.NewReader(""))
	if err != nil {
		err = fmt.Errorf("build sts requests err: %s", err.Error())
		return
	}
	httpClient := &http.Client{}
	httpResponse, err := httpClient.Do(httpRequest)
	if err != nil {
		err = fmt.Errorf("get Ecs sts token err : %s", err.Error())
		return
	}

	response := responses.NewCommonResponse()
	err = responses.Unmarshal(response, httpResponse, "")
	if err != nil {
		err = fmt.Errorf("unmarshal Ecs sts token response err : %s", err.Error())
		return
	}

	if response.GetHttpStatus() != http.StatusOK {
		err = fmt.Errorf("get Ecs sts token err, httpStatus: %d, message = %s", response.GetHttpStatus(), response.GetHttpContentString())
		return
	}
	var data interface{}
	err = json.Unmarshal(response.GetHttpContentBytes(), &data)
	if err != nil {
		err = fmt.Errorf("refresh Ecs sts token err, json.Unmarshal fail: %s", err.Error())
		return
	}
	code, err := jmespath.Search("Code", data)
	if err != nil {
		err = fmt.Errorf("refresh Ecs sts token err, fail to get Code: %s", err.Error())
		return
	}

View on GitHub (pinned to d32a084675)