{"record":{"id":"d444323297aafa41","repo":"JuliusBrussee/caveman","slug":"awscreds-s-returned-an-unparseable-response","errorCode":null,"errorMessage":"awscreds: %s returned an unparseable response","messagePattern":"awscreds: (.+?) returned an unparseable response","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"shared/platform/awscreds/awscreds.go","lineNumber":621,"sourceCode":"\tresp, err := client.Do(req)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"awscreds: %s request failed: %w\", what, err)\n\t}\n\tdefer resp.Body.Close()\n\tbody, err := io.ReadAll(io.LimitReader(resp.Body, maxBody))\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"awscreds: read %s response: %w\", what, err)\n\t}\n\tif resp.StatusCode < 200 || resp.StatusCode > 299 {\n\t\treturn nil, fmt.Errorf(\"awscreds: %s: http %d\", what, resp.StatusCode)\n\t}\n\treturn body, nil\n}\n\nfunc credentialsFromJSON(body []byte, source string) (*result, error) {\n\tvar parsed credentialJSON\n\tif err := json.Unmarshal(body, &parsed); err != nil {\n\t\treturn nil, fmt.Errorf(\"awscreds: %s returned an unparseable response\", source)\n\t}\n\tif parsed.Code != \"\" && !strings.EqualFold(parsed.Code, \"Success\") {\n\t\treturn nil, fmt.Errorf(\"awscreds: %s returned code %q\", source, parsed.Code)\n\t}\n\texpires, err := parseExpiry(parsed.Expiration)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"awscreds: %s credential expiry: %w\", source, err)\n\t}\n\treturn &result{\n\t\tcreds: awssig.Credentials{\n\t\t\tAccessKeyID:     strings.TrimSpace(parsed.AccessKeyID),\n\t\t\tSecretAccessKey: strings.TrimSpace(parsed.SecretAccessKey),\n\t\t\tSessionToken:    strings.TrimSpace(parsed.Token),\n\t\t},\n\t\texpires: expires,\n\t\tsource:  source,\n\t}, nil\n}","sourceCodeStart":603,"sourceCodeEnd":639,"githubUrl":"https://github.com/JuliusBrussee/caveman/blob/3ee70a102609e550bd2e68004bf5990a9341c851/shared/platform/awscreds/awscreds.go#L603-L639","documentation":"credentialsFromJSON unmarshals the body returned by the ECS container metadata endpoint or EC2 IMDS into credentialJSON. If json.Unmarshal fails, the response was not the expected credential JSON object, and the error reports 'unparseable response' for the source (container or imds). The library throws this because continuing without validating the payload shape would produce zero-valued credentials.","triggerScenarios":"fromContainer or fromIMDS receives a 2xx body that is not valid JSON: an HTML error/login page from a proxy, a plain-text message, an empty body, or truncation at the maxBody limit.","commonSituations":"A corporate proxy or VPN captive portal intercepting requests to 169.254.169.254 and returning an HTML page with 200 OK; AWS_CONTAINER_CREDENTIALS_RELATIVE_URI pointing to a non-metadata HTTP service; custom AWS_EC2_METADATA_SERVICE_ENDPOINT pointing at the wrong server.","solutions":["Log/capture the raw body (temporarily) to see what the endpoint actually returned; an HTML page indicates interception by a proxy or wrong endpoint.","Verify AWS_CONTAINER_CREDENTIALS_RELATIVE_URI points to the ECS agent's credentials path and that the ecs agent is running.","If AWS_EC2_METADATA_SERVICE_ENDPOINT is overridden, reset it to http://169.254.169.254 and retry.","Ensure no proxy env vars (HTTP_PROXY) route metadata traffic; use NO_PROXY=169.254.169.254."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"func looksLikeJSONBody(b []byte) bool {\n    t := bytes.TrimSpace(b)\n    return len(t) > 0 && (t[0] == '{' || t[0] == '\"')\n}","typeGuard":null,"tryCatchPattern":"body, err := p.doJSON(client, req, \"imds credentials\")\nif err != nil {\n    return err\n}\nif !looksLikeJSONBody(body) {\n    return fmt.Errorf(\"metadata endpoint returned non-JSON (%d bytes); check proxy/NO_PROXY\", len(body))\n}","preventionTips":["Set NO_PROXY=169.254.169.254 and exclude the metadata host from HTTP_PROXY.","Point AWS_CONTAINER_CREDENTIALS_RELATIVE_URI only at the ECS agent path.","Do not override AWS_EC2_METADATA_SERVICE_ENDPOINT unless testing a real IMDS-compatible service."],"tags":["aws","json","metadata-service","credentials"],"backgroundTag":"json-unmarshal-failed","analyzedSha":"3ee70a102609e550bd2e68004bf5990a9341c851","analyzedAt":"2026-09-20T15:53:39.229Z","contentChangedAt":"2026-09-20T15:53:39.229Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}