JuliusBrussee/caveman · error
awscreds: build container credentials request
Error message
awscreds: build container credentials request: %w
What it means
fromContainer wraps an error returned by http.NewRequestWithContext when constructing the GET request for container credentials (ECS/EKS endpoint). The library throws this because the credentials URL passed validation but could not be parsed into an HTTP request, so no request can be made.
Solutions
- Print/inspect AWS_CONTAINER_CREDENTIALS_FULL_URI and RELATIVE_URI; make the full URI a valid absolute http(s) URL.
- URL-encode any special characters in the endpoint or path.
- Unset the container credential env vars if you are not actually running in ECS/EKS so another provider chain step is used.
- Check the wrapped %w cause for context canceled/deadline errors and fix the caller's timeout.
Example fix
// before
os.Setenv("AWS_CONTAINER_CREDENTIALS_FULL_URI", "169.254.170.2/v2/creds") // no scheme
// after
os.Setenv("AWS_CONTAINER_CREDENTIALS_FULL_URI", "http://169.254.170.2/v2/creds") Defensive patterns
Strategy: validation
Validate before calling
u := os.Getenv("AWS_CONTAINER_CREDENTIALS_FULL_URI")
if u != "" {
if _, err := url.Parse(u); err != nil || !strings.HasPrefix(u, "http") {
return fmt.Errorf("invalid AWS_CONTAINER_CREDENTIALS_FULL_URI: %q", u)
}
} Try / catch
creds, err := provider.Credentials(ctx)
var urlErr *url.Error
if errors.As(err, &urlErr) { /* fix endpoint env var */ } Prevention
- Validate AWS_CONTAINER_CREDENTIALS_* env vars at startup with url.Parse
- Only set FULL_URI when actually running inside ECS/EKS
- URL-encode any dynamic path segments
When it happens
Trigger: fromContainer builds the endpoint from AWS_CONTAINER_CREDENTIALS_RELATIVE_URI / FULL_URI (or the default ECS base) and calls http.NewRequestWithContext; it fails when the resulting endpoint string is not a valid absolute URL (bad characters, missing scheme, malformed host) or the context is already canceled.
Common situations: Misconfigured AWS_CONTAINER_CREDENTIALS_FULL_URI containing spaces, unencoded characters, or no scheme; a relative URI env var that concatenates into an unparseable URL; running the app outside ECS/EKS with a hand-set full URI.
Understand the failure class
Background: "Invalid URL" errors: why new URL(), URI.parse, and reqwest::Url reject your string — missing scheme, whitespace, and bad path format — this error's family across 39 libraries.
Related errors
- awscreds: unsupported container credentials scheme
- AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY must be set…
- awscreds: AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY must…
- awscreds: build imds token request
- awscreds: build request
AI-assisted analysis of JuliusBrussee/caveman@3ee70a1026 (2026-09-20).
Data as JSON: /api/errors/3071cfa3d33fdcf1.
Report an issue: GitHub.
Appendix: source
Thrown at shared/platform/awscreds/awscreds.go:426
func (p *Provider) fromContainer(ctx context.Context) (*result, error) {
endpoint := p.env("AWS_CONTAINER_CREDENTIALS_FULL_URI")
if endpoint != "" {
if err := checkContainerURI(endpoint); err != nil {
return nil, err
}
} else {
relative := p.env("AWS_CONTAINER_CREDENTIALS_RELATIVE_URI")
if relative == "" {
return nil, nil
}
if !strings.HasPrefix(relative, "/") {
relative = "/" + relative
}
endpoint = strings.TrimSuffix(p.containerBase, "/") + relative
}
req, err := http.NewRequestWithContext(ctx, http.MethodGet, endpoint, nil)
if err != nil {
return nil, fmt.Errorf("awscreds: build container credentials request: %w", err)
}
auth, err := p.containerAuthToken()
if err != nil {
return nil, err
}
if auth != "" {
req.Header.Set("Authorization", auth)
}
req.Header.Set("Accept", "application/json")
body, err := p.doJSON(p.link, req, "container credentials")
if err != nil {
return nil, err
}
return credentialsFromJSON(body, "container")
}
func (p *Provider) containerAuthToken() (string, error) {
if file := p.env("AWS_CONTAINER_AUTHORIZATION_TOKEN_FILE"); file != "" {View on GitHub (pinned to 3ee70a1026)