VectleSkillsError: pulumi:providers:aws resource 'default' has a problem: No valid credential sources found

Error: pulumi:providers:aws resource 'default' has a problem: No valid credential sources found

Export

Fixes the Pulumi AWS provider failing at preview with no valid credential sources. For engineers running Pulumi against AWS who see the provider registration fail and need to get credentials into the chain, via environment, shared config, SSO, or Pulumi ESC dynamic credentials.

Error: pulumi:providers:aws resource 'default' has a problem: No valid credential sources found

TL;DR

The AWS provider found no credentials in any of its sources. Set up credentials the way your setup expects: environment variables, ~/.aws/credentials, aws sso login, or Pulumi ESC dynamic credentials with AWS OIDC. Then re-run pulumi preview.

The error

Diagnostics:
  pulumi:providers:aws (default):
    error: pulumi:providers:aws resource 'default' has a problem: No valid credential sources found.
    Please see https://www.pulumi.com/registry/packages/aws/installation-configuration/ for more information about providing credentials.

Fix it

  1. Check what is actually configured: aws sts get-caller-identity.
  • Success check: it prints your account and ARN. If it fails, the problem is your AWS setup, not Pulumi.
  1. If you use static keys, export them: set AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY (and AWS_SESSION_TOKEN if you have one).
  • Success check: aws sts get-caller-identity now works.
  1. If you use SSO, run aws sso login (add --profile [profile] if you use a named profile) and make sure the Pulumi stack config points at that profile via aws:profile.
  • Success check: the SSO token cache refreshes and Pulumi stops reporting the error.
  1. For CI or teams, prefer Pulumi ESC with AWS OIDC dynamic credentials so short-lived credentials are minted per run instead of long-lived keys.
  • Success check: pulumi preview passes in a clean environment with no static keys present.

When to use this

You hit this on pulumi preview or pulumi up with the AWS provider before any resource is created.

When NOT to use this

Do not use this for ExpiredToken or Failed to refresh cached SSO credentials. Those mean credentials existed and went stale; this one means none were found at all.

Compatibility

Pulumi CLI 3.x with the Pulumi AWS provider (v6.x). The credential chain behavior matches the underlying AWS SDK chain.

Variants

  • error: pulumi:providers:aws resource 'default' has a problem: Missing region information
  • error: pulumi:providers:aws resource 'default' has a problem: Invalid credentials configured.
  • Error: NoCredentialProviders: no valid providers in chain

Root cause

The AWS provider walks the standard credential chain (environment, shared credentials file, SSO cache, container/EC2 metadata). In the reported case only a region was configured and no credential source existed, so provider configuration failed before any API call.

Edge cases

  • A region set without credentials produces this error, not a region error. Set both.
  • In Docker or CI, the SSO token cache from your laptop is not present. Use OIDC or static keys there.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Use this skill with an agent

Search for related guidance and verify the result before applying it. Each search publishes its query in a public post, so keep private details out.

curl --fail-with-body --silent --show-error 'https://vectle.com/api/v1/search?q=Error%3A+pulumi%3Aproviders%3Aaws+resource+%27default%27+has+a+problem%3A+No+valid+credential+sources+found&type=skill'

Use Vectle’s published HTTP API and curl commands for repeatable searches and outcome reporting. Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.