{"record":{"id":"fe19fe95ac0e2b3a","repo":"JuliusBrussee/caveman","slug":"awscreds-unsupported-imds-endpoint-scheme-q","errorCode":null,"errorMessage":"awscreds: unsupported IMDS endpoint scheme %q","messagePattern":"awscreds: unsupported IMDS endpoint scheme %q","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"shared/platform/awscreds/awscreds.go","lineNumber":533,"sourceCode":"// checkIMDSEndpoint is checkContainerURI for AWS_EC2_METADATA_SERVICE_ENDPOINT.\n// That variable was taken verbatim and then dialled with p.link — the client\n// that deliberately ignores every proxy setting — so any host named there became\n// a proxy-bypassing outbound request with the IMDSv2 token attached.\nfunc checkIMDSEndpoint(raw string) error {\n\tu, err := url.Parse(raw)\n\tif err != nil || u.Host == \"\" {\n\t\treturn errors.New(\"awscreds: AWS_EC2_METADATA_SERVICE_ENDPOINT is not a valid URL\")\n\t}\n\tswitch u.Scheme {\n\tcase \"https\":\n\t\treturn nil\n\tcase \"http\":\n\t\tif plaintextHostAllowed(u.Hostname(), imdsHosts) {\n\t\t\treturn nil\n\t\t}\n\t\treturn fmt.Errorf(\"awscreds: refusing plaintext IMDS endpoint at host %q (allowed: loopback, 169.254.169.254, fd00:ec2::254)\", u.Hostname())\n\tdefault:\n\t\treturn fmt.Errorf(\"awscreds: unsupported IMDS endpoint scheme %q\", u.Scheme)\n\t}\n}\n\nfunc (p *Provider) fromIMDS(ctx context.Context) (*result, error) {\n\tif strings.EqualFold(p.env(\"AWS_EC2_METADATA_DISABLED\"), \"true\") {\n\t\treturn nil, nil\n\t}\n\tbase := p.env(\"AWS_EC2_METADATA_SERVICE_ENDPOINT\")\n\tif base == \"\" {\n\t\tbase = defaultIMDSBase\n\t}\n\tif err := checkIMDSEndpoint(base); err != nil {\n\t\treturn nil, err\n\t}\n\tbase = strings.TrimSuffix(base, \"/\")\n\n\t// IMDSv2 only: a v1 fallback would leave the proxy vulnerable to the SSRF\n\t// class the session token exists to close.","sourceCodeStart":515,"sourceCodeEnd":551,"githubUrl":"https://github.com/JuliusBrussee/caveman/blob/3ee70a102609e550bd2e68004bf5990a9341c851/shared/platform/awscreds/awscreds.go#L515-L551","documentation":"Error from checkIMDSEndpoint: AWS_EC2_METADATA_SERVICE_ENDPOINT parsed as a URL but its scheme is neither https nor plain http (and http is only allowed for allowlisted plaintext hosts). Because this endpoint is dialled by the proxy-ignoring link client, non-conforming schemes are refused before any IMDSv2 token is attached.","triggerScenarios":"AWS_EC2_METADATA_SERVICE_ENDPOINT contains an unsupported or missing scheme (e.g. 'metadata.internal' with no scheme, or socks5://...), so url.Parse yields a scheme falling into the default branch.","commonSituations":"Forgetting the http:// prefix when setting the endpoint env var; pasting a proxy or socket URI into the metadata endpoint variable; IMDSv2-only tooling emitting exotic schemes.","solutions":["Set the endpoint with an explicit scheme, e.g. http://169.254.169.254 or https://....","Use the canonical endpoint http://169.254.169.254/latest unless you have a simulator.","Unset AWS_EC2_METADATA_SERVICE_ENDPOINT to use the built-in default.","Check for stray whitespace/characters corrupting the URL scheme."],"exampleFix":"// before\nos.Setenv(\"AWS_EC2_METADATA_SERVICE_ENDPOINT\", \"169.254.169.254/latest\")\n// after\nos.Setenv(\"AWS_EC2_METADATA_SERVICE_ENDPOINT\", \"http://169.254.169.254/latest\")","handlingStrategy":"validation","validationCode":"if ep := os.Getenv(\"AWS_EC2_METADATA_SERVICE_ENDPOINT\"); ep != \"\" {\n    u, err := url.Parse(ep)\n    if err != nil || (u.Scheme != \"http\" && u.Scheme != \"https\") {\n        return fmt.Errorf(\"AWS_EC2_METADATA_SERVICE_ENDPOINT must include an http(s) scheme: %q\", ep)\n    }\n}","typeGuard":null,"tryCatchPattern":"if err != nil && strings.Contains(err.Error(), \"unsupported IMDS endpoint scheme\") {\n    log.Fatal(\"set AWS_EC2_METADATA_SERVICE_ENDPOINT to e.g. http://169.254.169.254\")\n}","preventionTips":["Always prefix the endpoint with http:// or https://","Trim whitespace from env values set programmatically","Validate at config load time, not at first credential fetch"],"tags":["aws","imds","url-scheme","env-config"],"backgroundTag":"invalid-url","analyzedSha":"3ee70a102609e550bd2e68004bf5990a9341c851","analyzedAt":"2026-09-20T15:53:39.229Z","contentChangedAt":"2026-09-20T15:53:39.229Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}