{"record":{"id":"e6158e3166fe73f8","repo":"JuliusBrussee/caveman","slug":"awscreds-read-container-authorization-token-file-w","errorCode":null,"errorMessage":"awscreds: read container authorization token file: %w","messagePattern":"awscreds: read container authorization token file: %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"shared/platform/awscreds/awscreds.go","lineNumber":447,"sourceCode":"\tif err != nil {\n\t\treturn nil, err\n\t}\n\tif auth != \"\" {\n\t\treq.Header.Set(\"Authorization\", auth)\n\t}\n\treq.Header.Set(\"Accept\", \"application/json\")\n\tbody, err := p.doJSON(p.link, req, \"container credentials\")\n\tif err != nil {\n\t\treturn nil, err\n\t}\n\treturn credentialsFromJSON(body, \"container\")\n}\n\nfunc (p *Provider) containerAuthToken() (string, error) {\n\tif file := p.env(\"AWS_CONTAINER_AUTHORIZATION_TOKEN_FILE\"); file != \"\" {\n\t\traw, err := os.ReadFile(file)\n\t\tif err != nil {\n\t\t\treturn \"\", fmt.Errorf(\"awscreds: read container authorization token file: %w\", err)\n\t\t}\n\t\treturn strings.TrimSpace(string(raw)), nil\n\t}\n\treturn p.env(\"AWS_CONTAINER_AUTHORIZATION_TOKEN\"), nil\n}\n\n// containerCredentialHosts is the fixed set of non-loopback addresses the AWS\n// SDKs will talk to in PLAINTEXT for container credentials: the ECS task-role\n// endpoint and EKS Pod Identity (v4 and v6). Accepting all of 169.254.0.0/16 and\n// fe80::/10 — every link-local address — instead meant any neighbouring\n// link-local listener could be handed the task role's Authorization token.\nvar containerCredentialHosts = []netip.Addr{\n\tnetip.MustParseAddr(\"169.254.170.2\"),  // ECS task role\n\tnetip.MustParseAddr(\"169.254.170.23\"), // EKS Pod Identity\n\tnetip.MustParseAddr(\"fd00:ec2::23\"),   // EKS Pod Identity over IPv6\n}\n\n// imdsHosts is the same idea for the instance metadata service.","sourceCodeStart":429,"sourceCodeEnd":465,"githubUrl":"https://github.com/JuliusBrussee/caveman/blob/3ee70a102609e550bd2e68004bf5990a9341c851/shared/platform/awscreds/awscreds.go#L429-L465","documentation":"containerAuthToken fails to read the file named by AWS_CONTAINER_AUTHORIZATION_TOKEN_FILE, which EKS Pod Identity / IRSA uses to carry the container authorization token. The library refuses to continue without the token rather than sending unauthenticated metadata requests.","triggerScenarios":"AWS_CONTAINER_AUTHORIZATION_TOKEN_FILE is set but os.ReadFile on the path fails: file missing, wrong path, no read permission, or the projected service-account token volume is not mounted.","commonSituations":"Pod running before the serviceaccount token volume is mounted; typo'd path; running the same code locally where the token file doesn't exist; container image drops read permissions on the mount.","solutions":["Verify the file exists at the exact path in AWS_CONTAINER_AUTHORIZATION_TOKEN_FILE (ls -l) inside the container.","Ensure the Kubernetes service-account token volume is mounted (EKS Pod Identity/IRSA admission injected it).","Fix read permissions or run as a user that can read the file.","Alternatively set AWS_CONTAINER_AUTHORIZATION_TOKEN directly if appropriate."],"exampleFix":"// before\ntokenFile := \"/var/run/secrets/pod-identity/tokn\" // typo\n// after\ntokenFile := \"/var/run/secrets/pod-identity/token\"","handlingStrategy":"validation","validationCode":"if f := os.Getenv(\"AWS_CONTAINER_AUTHORIZATION_TOKEN_FILE\"); f != \"\" {\n    if _, err := os.Stat(f); err != nil {\n        return fmt.Errorf(\"auth token file missing: %w\", err)\n    }\n}","typeGuard":null,"tryCatchPattern":"if err := creds.Load(ctx); err != nil {\n    if errors.Is(err, fs.ErrNotExist) { /* token volume not mounted; retry with backoff */ }\n}","preventionTips":["Wait for the projected service-account token volume before startup (init container or readiness gate)","Stat the token file in a readiness probe","Never hardcode token paths — read them from the env var"],"tags":["aws","credentials","filesystem","kubernetes"],"backgroundTag":"file-read-failed","analyzedSha":"3ee70a102609e550bd2e68004bf5990a9341c851","analyzedAt":"2026-09-20T15:53:39.229Z","contentChangedAt":"2026-09-20T15:53:39.229Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}