JuliusBrussee/caveman · error

awscreds: build container credentials request

Error message

awscreds: build container credentials request: %w

What it means

fromContainer wraps an error returned by http.NewRequestWithContext when constructing the GET request for container credentials (ECS/EKS endpoint). The library throws this because the credentials URL passed validation but could not be parsed into an HTTP request, so no request can be made.

Solutions

  1. Print/inspect AWS_CONTAINER_CREDENTIALS_FULL_URI and RELATIVE_URI; make the full URI a valid absolute http(s) URL.
  2. URL-encode any special characters in the endpoint or path.
  3. Unset the container credential env vars if you are not actually running in ECS/EKS so another provider chain step is used.
  4. Check the wrapped %w cause for context canceled/deadline errors and fix the caller's timeout.

Example fix

// before
os.Setenv("AWS_CONTAINER_CREDENTIALS_FULL_URI", "169.254.170.2/v2/creds") // no scheme
// after
os.Setenv("AWS_CONTAINER_CREDENTIALS_FULL_URI", "http://169.254.170.2/v2/creds")
Defensive patterns

Strategy: validation

Validate before calling

u := os.Getenv("AWS_CONTAINER_CREDENTIALS_FULL_URI")
if u != "" {
    if _, err := url.Parse(u); err != nil || !strings.HasPrefix(u, "http") {
        return fmt.Errorf("invalid AWS_CONTAINER_CREDENTIALS_FULL_URI: %q", u)
    }
}

Try / catch

creds, err := provider.Credentials(ctx)
var urlErr *url.Error
if errors.As(err, &urlErr) { /* fix endpoint env var */ }

Prevention

When it happens

Trigger: fromContainer builds the endpoint from AWS_CONTAINER_CREDENTIALS_RELATIVE_URI / FULL_URI (or the default ECS base) and calls http.NewRequestWithContext; it fails when the resulting endpoint string is not a valid absolute URL (bad characters, missing scheme, malformed host) or the context is already canceled.

Common situations: Misconfigured AWS_CONTAINER_CREDENTIALS_FULL_URI containing spaces, unencoded characters, or no scheme; a relative URI env var that concatenates into an unparseable URL; running the app outside ECS/EKS with a hand-set full URI.

Understand the failure class

Background: "Invalid URL" errors: why new URL(), URI.parse, and reqwest::Url reject your string — missing scheme, whitespace, and bad path format — this error's family across 39 libraries.

Related errors


AI-assisted analysis of JuliusBrussee/caveman@3ee70a1026 (2026-09-20). Data as JSON: /api/errors/3071cfa3d33fdcf1. Report an issue: GitHub.

Appendix: source

Thrown at shared/platform/awscreds/awscreds.go:426

func (p *Provider) fromContainer(ctx context.Context) (*result, error) {
	endpoint := p.env("AWS_CONTAINER_CREDENTIALS_FULL_URI")
	if endpoint != "" {
		if err := checkContainerURI(endpoint); err != nil {
			return nil, err
		}
	} else {
		relative := p.env("AWS_CONTAINER_CREDENTIALS_RELATIVE_URI")
		if relative == "" {
			return nil, nil
		}
		if !strings.HasPrefix(relative, "/") {
			relative = "/" + relative
		}
		endpoint = strings.TrimSuffix(p.containerBase, "/") + relative
	}
	req, err := http.NewRequestWithContext(ctx, http.MethodGet, endpoint, nil)
	if err != nil {
		return nil, fmt.Errorf("awscreds: build container credentials request: %w", err)
	}
	auth, err := p.containerAuthToken()
	if err != nil {
		return nil, err
	}
	if auth != "" {
		req.Header.Set("Authorization", auth)
	}
	req.Header.Set("Accept", "application/json")
	body, err := p.doJSON(p.link, req, "container credentials")
	if err != nil {
		return nil, err
	}
	return credentialsFromJSON(body, "container")
}

func (p *Provider) containerAuthToken() (string, error) {
	if file := p.env("AWS_CONTAINER_AUTHORIZATION_TOKEN_FILE"); file != "" {

View on GitHub (pinned to 3ee70a1026)