{"record":{"id":"3071cfa3d33fdcf1","repo":"JuliusBrussee/caveman","slug":"awscreds-build-container-credentials-request-w","errorCode":null,"errorMessage":"awscreds: build container credentials request: %w","messagePattern":"awscreds: build container credentials request: %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"shared/platform/awscreds/awscreds.go","lineNumber":426,"sourceCode":"func (p *Provider) fromContainer(ctx context.Context) (*result, error) {\n\tendpoint := p.env(\"AWS_CONTAINER_CREDENTIALS_FULL_URI\")\n\tif endpoint != \"\" {\n\t\tif err := checkContainerURI(endpoint); err != nil {\n\t\t\treturn nil, err\n\t\t}\n\t} else {\n\t\trelative := p.env(\"AWS_CONTAINER_CREDENTIALS_RELATIVE_URI\")\n\t\tif relative == \"\" {\n\t\t\treturn nil, nil\n\t\t}\n\t\tif !strings.HasPrefix(relative, \"/\") {\n\t\t\trelative = \"/\" + relative\n\t\t}\n\t\tendpoint = strings.TrimSuffix(p.containerBase, \"/\") + relative\n\t}\n\treq, err := http.NewRequestWithContext(ctx, http.MethodGet, endpoint, nil)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"awscreds: build container credentials request: %w\", err)\n\t}\n\tauth, err := p.containerAuthToken()\n\tif err != nil {\n\t\treturn nil, err\n\t}\n\tif auth != \"\" {\n\t\treq.Header.Set(\"Authorization\", auth)\n\t}\n\treq.Header.Set(\"Accept\", \"application/json\")\n\tbody, err := p.doJSON(p.link, req, \"container credentials\")\n\tif err != nil {\n\t\treturn nil, err\n\t}\n\treturn credentialsFromJSON(body, \"container\")\n}\n\nfunc (p *Provider) containerAuthToken() (string, error) {\n\tif file := p.env(\"AWS_CONTAINER_AUTHORIZATION_TOKEN_FILE\"); file != \"\" {","sourceCodeStart":408,"sourceCodeEnd":444,"githubUrl":"https://github.com/JuliusBrussee/caveman/blob/3ee70a102609e550bd2e68004bf5990a9341c851/shared/platform/awscreds/awscreds.go#L408-L444","documentation":"fromContainer wraps an error returned by http.NewRequestWithContext when constructing the GET request for container credentials (ECS/EKS endpoint). The library throws this because the credentials URL passed validation but could not be parsed into an HTTP request, so no request can be made.","triggerScenarios":"fromContainer builds the endpoint from AWS_CONTAINER_CREDENTIALS_RELATIVE_URI / FULL_URI (or the default ECS base) and calls http.NewRequestWithContext; it fails when the resulting endpoint string is not a valid absolute URL (bad characters, missing scheme, malformed host) or the context is already canceled.","commonSituations":"Misconfigured AWS_CONTAINER_CREDENTIALS_FULL_URI containing spaces, unencoded characters, or no scheme; a relative URI env var that concatenates into an unparseable URL; running the app outside ECS/EKS with a hand-set full URI.","solutions":["Print/inspect AWS_CONTAINER_CREDENTIALS_FULL_URI and RELATIVE_URI; make the full URI a valid absolute http(s) URL.","URL-encode any special characters in the endpoint or path.","Unset the container credential env vars if you are not actually running in ECS/EKS so another provider chain step is used.","Check the wrapped %w cause for context canceled/deadline errors and fix the caller's timeout."],"exampleFix":"// before\nos.Setenv(\"AWS_CONTAINER_CREDENTIALS_FULL_URI\", \"169.254.170.2/v2/creds\") // no scheme\n// after\nos.Setenv(\"AWS_CONTAINER_CREDENTIALS_FULL_URI\", \"http://169.254.170.2/v2/creds\")","handlingStrategy":"validation","validationCode":"u := os.Getenv(\"AWS_CONTAINER_CREDENTIALS_FULL_URI\")\nif u != \"\" {\n    if _, err := url.Parse(u); err != nil || !strings.HasPrefix(u, \"http\") {\n        return fmt.Errorf(\"invalid AWS_CONTAINER_CREDENTIALS_FULL_URI: %q\", u)\n    }\n}","typeGuard":null,"tryCatchPattern":"creds, err := provider.Credentials(ctx)\nvar urlErr *url.Error\nif errors.As(err, &urlErr) { /* fix endpoint env var */ }","preventionTips":["Validate AWS_CONTAINER_CREDENTIALS_* env vars at startup with url.Parse","Only set FULL_URI when actually running inside ECS/EKS","URL-encode any dynamic path segments"],"tags":["aws","credentials","http-client","env-config"],"backgroundTag":"invalid-url-format","analyzedSha":"3ee70a102609e550bd2e68004bf5990a9341c851","analyzedAt":"2026-09-20T15:53:39.229Z","contentChangedAt":"2026-09-20T15:53:39.229Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}