hashicorp/terraform · error
unmarshal Ecs sts token response err
Error message
unmarshal Ecs sts token response err : %s
What it means
Thrown by getAuthCredentialByEcsRoleName() when responses.Unmarshal() fails to parse the HTTP response from the ECS metadata service into a CommonResponse. This wraps the SDK's response unmarshaling logic. The error indicates the response body could not be processed by the Alibaba Cloud SDK's response parser.
Solutions
- Verify the response from 100.100.100.200 is well-formed — run 'curl http://100.100.100.200/latest/meta-data/ram/security-credentials/<role>' from the ECS instance.
- Check for any network proxies or security appliances intercepting metadata traffic.
- Ensure the ECS instance and its RAM role are properly configured.
- If the metadata service is malfunctioning, fall back to static credentials or STS tokens.
Defensive patterns
Strategy: try-catch
Validate before calling
// Pre-validate metadata service response format
func probeMetadataService(roleName string) error {
url := fmt.Sprintf("http://100.100.100.200/latest/meta-data/ram/security-credentials/%s", roleName)
resp, err := http.Get(url)
if err != nil {
return err
}
defer resp.Body.Close()
if resp.StatusCode != 200 {
return fmt.Errorf("metadata service returned HTTP %d", resp.StatusCode)
}
body, err := io.ReadAll(resp.Body)
if err != nil {
return err
}
var test interface{}
if err := json.Unmarshal(body, &test); err != nil {
return fmt.Errorf("metadata service returned non-JSON response: %w", err)
}
return nil
} Try / catch
// Handle metadata response unmarshal failure with credential fallback
resp, err := getAuthCredentialByEcsRoleName(roleName)
if err != nil && strings.Contains(err.Error(), "unmarshal Ecs sts token") {
log.Printf("[WARN] metadata service returned malformed response; falling back to static credentials")
// Fall back to ALICLOUD_ACCESS_KEY / ALICLOUD_SECRET_KEY env vars
} Prevention
- Verify the metadata service returns clean responses with 'curl' from the ECS instance.
- Check for network proxies that may intercept metadata traffic.
- Have a fallback credential strategy (static keys or STS) when ECS metadata is unreliable.
When it happens
Trigger: responses.Unmarshal(response, httpResponse, "") returns an error after the HTTP request to 100.100.100.200 succeeds. Triggers when the metadata service returns a response in an unexpected format — not valid HTTP, missing headers, or body encoding that the SDK parser cannot handle.
Common situations: Metadata service returning a non-standard response (e.g. HTML error page from a transparent proxy, or an empty body). A network appliance (corporate proxy, WAF) intercepting traffic to 100.100.100.200 and returning a non-conforming response. Corrupted network data. Metadata service returning an unexpected content-encoding.
Related errors
- refresh Ecs sts token err, json.Unmarshal fail
- build sts requests err
- get Ecs sts token err, httpStatus
- get Ecs sts token err
- refresh Ecs sts token err, Code is not Success
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/a9314101b1269f39.
Report an issue: GitHub.
Appendix: source
Thrown at internal/backend/remote-state/oss/backend.go:665
return
}
requestUrl := securityCredURL + ecsRoleName
httpRequest, err := http.NewRequest(requests.GET, requestUrl, strings.NewReader(""))
if err != nil {
err = fmt.Errorf("build sts requests err: %s", err.Error())
return
}
httpClient := &http.Client{}
httpResponse, err := httpClient.Do(httpRequest)
if err != nil {
err = fmt.Errorf("get Ecs sts token err : %s", err.Error())
return
}
response := responses.NewCommonResponse()
err = responses.Unmarshal(response, httpResponse, "")
if err != nil {
err = fmt.Errorf("unmarshal Ecs sts token response err : %s", err.Error())
return
}
if response.GetHttpStatus() != http.StatusOK {
err = fmt.Errorf("get Ecs sts token err, httpStatus: %d, message = %s", response.GetHttpStatus(), response.GetHttpContentString())
return
}
var data interface{}
err = json.Unmarshal(response.GetHttpContentBytes(), &data)
if err != nil {
err = fmt.Errorf("refresh Ecs sts token err, json.Unmarshal fail: %s", err.Error())
return
}
code, err := jmespath.Search("Code", data)
if err != nil {
err = fmt.Errorf("refresh Ecs sts token err, fail to get Code: %s", err.Error())
return
}View on GitHub (pinned to d32a084675)