aio-libs/aiohttp · warning · LookupError

No .netrc file found

Error message

No .netrc file found

What it means

_auth_header_from_netrc raises LookupError when the netrc_obj passed to it is None, meaning no .netrc file was found on the system. This function is called internally when aiohttp resolves proxy credentials from the netrc file for environment-configured proxies.

Solutions

  1. Create a ~/.netrc file with the appropriate machine entry and credentials
  2. Set the HOME environment variable to the correct home directory
  3. Provide proxy credentials explicitly via the proxy_auth parameter instead of relying on netrc
  4. Set trust_env=False if you do not want netrc-based proxy resolution

Example fix

# before
session = ClientSession(trust_env=True)
# relies on netrc but file does not exist

# after
# Option 1: provide credentials explicitly
from aiohttp import BasicAuth
auth = BasicAuth('proxyuser', 'proxypass')
session = ClientSession(trust_env=True)
await session.get(url, proxy='http://proxy:8080', proxy_auth=auth)
Defensive patterns

Strategy: fallback

Validate before calling

import os, netrc

def get_netrc_or_none():
    try:
        return netrc.netrc()
    except (FileNotFoundError, netrc.NetrcParseError):
        return None

netrc_obj = get_netrc_or_none()
if netrc_obj is None:
    logger.warning('No .netrc found; provide proxy_auth explicitly')

Try / catch

try:
    resp = await session.get(url, proxy=proxy_url)
except LookupError as e:
    if 'netrc' in str(e).lower():
        # Fall back to explicit proxy auth
        resp = await session.get(url, proxy=proxy_url, proxy_auth=BasicAuth('user', 'pass'))
    raise

Prevention

When it happens

Trigger: Setting trust_env=True on a ClientSession and configuring a proxy via environment variables (HTTP_PROXY/HTTPS_PROXY) while expecting netrc-based proxy authentication, but no ~/.netrc file exists on the system. Also triggered when HOME is unset so netrc.netrc cannot locate the file.

Common situations: CI/CD pipelines without a .netrc file but with proxy env vars set; containers missing HOME or the .netrc file; corporate proxy setups that rely on netrc credentials deployed per-user but the deployment was skipped.

Related errors


AI-assisted analysis of aio-libs/aiohttp@d041d4d0fd (2026-08-11). Data as JSON: /api/errors/9993a027e5f2c840. Report an issue: GitHub.

Appendix: source

Thrown at aiohttp/helpers.py:243

            client_logger.warning("Could not read .netrc file: %s", e)

    return None


@frozen_dataclass_decorator
class ProxyInfo:
    proxy: URL
    proxy_auth: str | None


def _auth_header_from_netrc(netrc_obj: netrc.netrc | None, host: str) -> str:
    """Return a ``Proxy-Authorization`` header value for ``host`` from netrc.

    :raises LookupError: if ``netrc_obj`` is :py:data:`None` or if no
            entry is found for the ``host``.
    """
    if netrc_obj is None:
        raise LookupError("No .netrc file found")
    auth_from_netrc = netrc_obj.authenticators(host)

    if auth_from_netrc is None:
        raise LookupError(f"No entry for {host!s} found in the `.netrc` file.")
    login, account, password = auth_from_netrc

    # TODO(PY311): username = login or account
    # Up to python 3.10, account could be None if not specified,
    # and login will be empty string if not specified. From 3.11,
    # login and account will be empty string if not specified.
    username = login if (login or account is None) else account

    # TODO(PY311): Remove this, as password will be empty string
    # if not specified
    if password is None:
        password = ""  # type: ignore[unreachable]

    return encode_basic_auth(username, password)

View on GitHub (pinned to d041d4d0fd)