{"record":{"id":"61baa6b9c526261a","repo":"JuliusBrussee/caveman","slug":"awscreds-aws-container-credentials-full-uri-is-not-a-valid","errorCode":null,"errorMessage":"awscreds: AWS_CONTAINER_CREDENTIALS_FULL_URI is not a valid URL","messagePattern":"awscreds: AWS_CONTAINER_CREDENTIALS_FULL_URI is not a valid URL","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"shared/platform/awscreds/awscreds.go","lineNumber":500,"sourceCode":"\t\treturn true\n\t}\n\taddr = addr.Unmap()\n\tfor _, allowed := range allow {\n\t\tif addr == allowed {\n\t\t\treturn true\n\t\t}\n\t}\n\treturn false\n}\n\n// checkContainerURI applies the SDK rule for a caller-supplied credential\n// endpoint: TLS anywhere, plaintext only to loopback or the fixed ECS/EKS\n// credential addresses. Without it, AWS_CONTAINER_CREDENTIALS_FULL_URI is a\n// request to hand a task role's Authorization token to an arbitrary host.\nfunc checkContainerURI(raw string) error {\n\tu, err := url.Parse(raw)\n\tif err != nil {\n\t\treturn errors.New(\"awscreds: AWS_CONTAINER_CREDENTIALS_FULL_URI is not a valid URL\")\n\t}\n\tswitch u.Scheme {\n\tcase \"https\":\n\t\treturn nil\n\tcase \"http\":\n\t\tif plaintextHostAllowed(u.Hostname(), containerCredentialHosts) {\n\t\t\treturn nil\n\t\t}\n\t\treturn fmt.Errorf(\"awscreds: refusing plaintext container credentials endpoint at host %q (allowed: loopback, 169.254.170.2, 169.254.170.23, fd00:ec2::23)\", u.Hostname())\n\tdefault:\n\t\treturn fmt.Errorf(\"awscreds: unsupported container credentials scheme %q\", u.Scheme)\n\t}\n}\n\n// checkIMDSEndpoint is checkContainerURI for AWS_EC2_METADATA_SERVICE_ENDPOINT.\n// That variable was taken verbatim and then dialled with p.link — the client\n// that deliberately ignores every proxy setting — so any host named there became\n// a proxy-bypassing outbound request with the IMDSv2 token attached.","sourceCodeStart":482,"sourceCodeEnd":518,"githubUrl":"https://github.com/JuliusBrussee/caveman/blob/3ee70a102609e550bd2e68004bf5990a9341c851/shared/platform/awscreds/awscreds.go#L482-L518","documentation":"checkContainerURI validates AWS_CONTAINER_CREDENTIALS_FULL_URI before it is ever dialed: it must parse as a URL and be either https, or http pointed at loopback or the fixed ECS/EKS credential endpoints (169.254.170.2 / 169.254.170.23). This prevents handing a task role's Authorization token to an arbitrary attacker-controlled host. A value that does not parse as a URL yields this error.","triggerScenarios":"fromContainer runs and AWS_CONTAINER_CREDENTIALS_FULL_URI contains a string url.Parse rejects — control characters, stray spaces, or a malformed scheme like 'htp://...' or '%zz'.","commonSituations":"Typoed scheme in an ECS/EKS task definition env var, quoting bugs injecting whitespace into the env value, or copying an example endpoint with a trailing character.","solutions":["Fix AWS_CONTAINER_CREDENTIALS_FULL_URI to a syntactically valid absolute URL (e.g. http://169.254.170.2/v2/credentials or an https:// endpoint)","Check the task definition / env injection for quoting or whitespace issues corrupting the value","Prefer the relative variant AWS_CONTAINER_CREDENTIALS_RELATIVE_URI on ECS, which avoids full-URL validation entirely"],"exampleFix":"// before\nexport AWS_CONTAINER_CREDENTIALS_FULL_URI=\"http://169.254.170.2 /v2/credentials\"\n// after\nexport AWS_CONTAINER_CREDENTIALS_FULL_URI=\"http://169.254.170.2/v2/credentials\"\n","handlingStrategy":"validation","validationCode":"func containerURIIsSafe(raw string) bool {\n\tu, err := url.Parse(raw)\n\tif err != nil { return false }\n\tif u.Scheme == \"https\" { return true }\n\tif u.Scheme == \"http\" {\n\t\th := u.Hostname()\n\t\treturn h == \"169.254.170.2\" || h == \"169.254.170.23\" || h == \"localhost\" || strings.HasPrefix(h, \"127.\")\n\t}\n\treturn false\n}\n","typeGuard":null,"tryCatchPattern":"if err := awscreds.CheckContainerURI(os.Getenv(\"AWS_CONTAINER_CREDENTIALS_FULL_URI\")); err != nil {\n\t// fix env before starting the provider\n}\n","preventionTips":["Use AWS_CONTAINER_CREDENTIALS_RELATIVE_URI on ECS instead of the full URI","Copy endpoints exactly from task-definition metadata, no manual retyping","Beware shell quoting that injects spaces into env values"],"tags":["aws","ecs","eks","url-validation","security"],"backgroundTag":"invalid-url-format","analyzedSha":"3ee70a102609e550bd2e68004bf5990a9341c851","analyzedAt":"2026-09-20T15:53:39.229Z","contentChangedAt":"2026-09-20T15:53:39.229Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}