{"record":{"id":"864719af3e133fd8","repo":"JuliusBrussee/caveman","slug":"awscreds-no-aws-credentials-found-env-web-identity-container","errorCode":null,"errorMessage":"awscreds: no AWS credentials found (env, web identity, container, IMDS)","messagePattern":"awscreds: no AWS credentials found \\(env, web identity, container, IMDS\\)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"shared/platform/awscreds/awscreds.go","lineNumber":274,"sourceCode":"}\n\nfunc (p *Provider) fetch(ctx context.Context) (*result, error) {\n\tfor _, source := range []func(context.Context) (*result, error){\n\t\tp.fromEnv, p.fromWebIdentity, p.fromContainer, p.fromIMDS,\n\t} {\n\t\tres, err := source(ctx)\n\t\tif err != nil {\n\t\t\treturn nil, err\n\t\t}\n\t\tif res == nil {\n\t\t\tcontinue\n\t\t}\n\t\tif !res.creds.Valid() {\n\t\t\treturn nil, fmt.Errorf(\"awscreds: %s returned incomplete credentials\", res.source)\n\t\t}\n\t\treturn res, nil\n\t}\n\treturn nil, errors.New(\"awscreds: no AWS credentials found (env, web identity, container, IMDS)\")\n}\n\nfunc (p *Provider) env(name string) string { return strings.TrimSpace(p.getenv(name)) }\n\n// fromEnv reads static keys. A half-configured pair is an error, not a skip:\n// the operator clearly meant to sign as these keys, and falling through would\n// silently sign as whatever ambient role the host carries — a different\n// principal, bill, and CloudTrail identity — with no disclosure. A lone\n// AWS_SESSION_TOKEN is not a pair and does not trigger this.\nfunc (p *Provider) fromEnv(context.Context) (*result, error) {\n\taccess, secret := p.env(\"AWS_ACCESS_KEY_ID\"), p.env(\"AWS_SECRET_ACCESS_KEY\")\n\tif access == \"\" && secret == \"\" {\n\t\treturn nil, nil\n\t}\n\tif access == \"\" || secret == \"\" {\n\t\treturn nil, errors.New(\"awscreds: AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY must both be set\")\n\t}\n\treturn &result{","sourceCodeStart":256,"sourceCodeEnd":292,"githubUrl":"https://github.com/JuliusBrussee/caveman/blob/3ee70a102609e550bd2e68004bf5990a9341c851/shared/platform/awscreds/awscreds.go#L256-L292","documentation":"The awscreds Provider walks a chain of credential sources — static env vars, web identity (IRSA/STS), container credentials (ECS/EKS endpoint), and EC2 IMDS. This terminal error means every source returned nothing usable, so no AWS credentials exist in the process and SigV4 signing cannot proceed.","triggerScenarios":"Calling Credentials() in an environment with no env keys, no web identity token file, no AWS_CONTAINER_CREDENTIALS_RELATIVE/FULL_URI, and no reachable IMDS — e.g. local dev or a container without any role attached.","commonSituations":"Running the proxy locally outside AWS with no keys exported; Kubernetes pod missing an IRSA annotation; ECS task without a task role; CI runners with no AWS env; firewall blocking 169.254.169.254.","solutions":["Export AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY (and AWS_SESSION_TOKEN for temporary keys) in the proxy process","Attach an IAM role: instance profile, ECS task role, or Kubernetes service account with IRSA","Verify the metadata service is reachable if relying on IMDS (no AWS_EC2_METADATA_DISABLED, no blocked link-local traffic)","If using Bedrock, consider a Bedrock bearer API key instead of SigV4"],"exampleFix":"// before (empty env)\n$ env | grep AWS_   # nothing\n// after\nexport AWS_ACCESS_KEY_ID=AKIA...\nexport AWS_SECRET_ACCESS_KEY=...\n","handlingStrategy":"validation","validationCode":"func hasAnyAWSCreds() bool {\n\tif os.Getenv(\"AWS_ACCESS_KEY_ID\") != \"\" && os.Getenv(\"AWS_SECRET_ACCESS_KEY\") != \"\" { return true }\n\tif os.Getenv(\"AWS_WEB_IDENTITY_TOKEN_FILE\") != \"\" { return true }\n\tif os.Getenv(\"AWS_CONTAINER_CREDENTIALS_RELATIVE_URI\") != \"\" || os.Getenv(\"AWS_CONTAINER_CREDENTIALS_FULL_URI\") != \"\" { return true }\n\treturn os.Getenv(\"AWS_EC2_METADATA_DISABLED\") != \"true\"\n}\n","typeGuard":null,"tryCatchPattern":"creds, err := provider.Credentials(ctx)\nif err != nil {\n\tif strings.Contains(err.Error(), \"no AWS credentials found\") {\n\t\t// fall back to bearer API key or abort with setup guidance\n\t}\n\treturn err\n}\n","preventionTips":["Attach an IAM role (instance profile, task role, IRSA) in every deployment","Export static keys for local dev","Confirm IMDS reachability and that AWS_EC2_METADATA_DISABLED is not set when relying on it"],"tags":["aws","credentials","env","imds"],"backgroundTag":"missing-credentials","analyzedSha":"3ee70a102609e550bd2e68004bf5990a9341c851","analyzedAt":"2026-09-20T15:53:39.229Z","contentChangedAt":"2026-09-20T15:53:39.229Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}