{"record":{"id":"81119ca14b7cd9b7","repo":"JuliusBrussee/caveman","slug":"awscreds-unsupported-container-credentials-scheme-q","errorCode":null,"errorMessage":"awscreds: unsupported container credentials scheme %q","messagePattern":"awscreds: unsupported container credentials scheme %q","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"shared/platform/awscreds/awscreds.go","lineNumber":511,"sourceCode":"// checkContainerURI applies the SDK rule for a caller-supplied credential\n// endpoint: TLS anywhere, plaintext only to loopback or the fixed ECS/EKS\n// credential addresses. Without it, AWS_CONTAINER_CREDENTIALS_FULL_URI is a\n// request to hand a task role's Authorization token to an arbitrary host.\nfunc checkContainerURI(raw string) error {\n\tu, err := url.Parse(raw)\n\tif err != nil {\n\t\treturn errors.New(\"awscreds: AWS_CONTAINER_CREDENTIALS_FULL_URI is not a valid URL\")\n\t}\n\tswitch u.Scheme {\n\tcase \"https\":\n\t\treturn nil\n\tcase \"http\":\n\t\tif plaintextHostAllowed(u.Hostname(), containerCredentialHosts) {\n\t\t\treturn nil\n\t\t}\n\t\treturn fmt.Errorf(\"awscreds: refusing plaintext container credentials endpoint at host %q (allowed: loopback, 169.254.170.2, 169.254.170.23, fd00:ec2::23)\", u.Hostname())\n\tdefault:\n\t\treturn fmt.Errorf(\"awscreds: unsupported container credentials scheme %q\", u.Scheme)\n\t}\n}\n\n// checkIMDSEndpoint is checkContainerURI for AWS_EC2_METADATA_SERVICE_ENDPOINT.\n// That variable was taken verbatim and then dialled with p.link — the client\n// that deliberately ignores every proxy setting — so any host named there became\n// a proxy-bypassing outbound request with the IMDSv2 token attached.\nfunc checkIMDSEndpoint(raw string) error {\n\tu, err := url.Parse(raw)\n\tif err != nil || u.Host == \"\" {\n\t\treturn errors.New(\"awscreds: AWS_EC2_METADATA_SERVICE_ENDPOINT is not a valid URL\")\n\t}\n\tswitch u.Scheme {\n\tcase \"https\":\n\t\treturn nil\n\tcase \"http\":\n\t\tif plaintextHostAllowed(u.Hostname(), imdsHosts) {\n\t\t\treturn nil","sourceCodeStart":493,"sourceCodeEnd":529,"githubUrl":"https://github.com/JuliusBrussee/caveman/blob/3ee70a102609e550bd2e68004bf5990a9341c851/shared/platform/awscreds/awscreds.go#L493-L529","documentation":"checkContainerURI rejects a container credentials endpoint whose URL scheme is neither https nor http. The library only knows how to speak HTTP(S) to the ECS/EKS credentials service and refuses anything else.","triggerScenarios":"AWS_CONTAINER_CREDENTIALS_FULL_URI set with a scheme like socks5, unix, ftp, or a malformed scheme (e.g. '169.254.170.2' parsed with an empty scheme reaching the default branch).","commonSituations":"Copying a proxy URL into the credentials URI variable; omitting the scheme entirely so url.Parse yields an empty scheme; custom link-local protocols unsupported by this provider.","solutions":["Prefix the URI with an explicit http:// or https:// scheme.","Use the standard ECS/EKS credentials endpoint format (http://169.254.170.2/v2/credentials).","If you need a unix socket or non-HTTP transport, front it with a small local HTTP proxy on loopback.","Unset the variable to fall back to the default container endpoint."],"exampleFix":"// before\nos.Setenv(\"AWS_CONTAINER_CREDENTIALS_FULL_URI\", \"169.254.170.2/v2/credentials\")\n// after\nos.Setenv(\"AWS_CONTAINER_CREDENTIALS_FULL_URI\", \"http://169.254.170.2/v2/credentials\")","handlingStrategy":"validation","validationCode":"u, err := url.Parse(fullURI)\nif err != nil || (u.Scheme != \"http\" && u.Scheme != \"https\") {\n    return fmt.Errorf(\"AWS_CONTAINER_CREDENTIALS_FULL_URI must be http(s), got %q\", fullURI)\n}","typeGuard":null,"tryCatchPattern":"if err != nil && strings.Contains(err.Error(), \"unsupported container credentials scheme\") {\n    log.Fatal(\"add an explicit http:// or https:// scheme to AWS_CONTAINER_CREDENTIALS_FULL_URI\")\n}","preventionTips":["Always include the scheme when setting credential URIs","Parse-check env vars in a config-validation step at boot","Don't paste proxy/socket URLs into the credentials URI variable"],"tags":["aws","credentials","url-scheme","env-config"],"backgroundTag":"invalid-url","analyzedSha":"3ee70a102609e550bd2e68004bf5990a9341c851","analyzedAt":"2026-09-20T15:53:39.229Z","contentChangedAt":"2026-09-20T15:53:39.229Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}