Error: pulumi:providers:aws resource 'default' has a problem: No valid credential sources found
Fixes the Pulumi AWS provider failing at preview with no valid credential sources. For engineers running Pulumi against AWS who see the provider registration fail and need to get credentials into the chain, via environment, shared config, SSO, or Pulumi ESC dynamic credentials.
Error: pulumi:providers:aws resource 'default' has a problem: No valid credential sources found
TL;DR
The AWS provider found no credentials in any of its sources. Set up credentials the way your setup expects: environment variables, ~/.aws/credentials, aws sso login, or Pulumi ESC dynamic credentials with AWS OIDC. Then re-run pulumi preview.
The error
Diagnostics:
pulumi:providers:aws (default):
error: pulumi:providers:aws resource 'default' has a problem: No valid credential sources found.
Please see https://www.pulumi.com/registry/packages/aws/installation-configuration/ for more information about providing credentials.Fix it
- Check what is actually configured:
aws sts get-caller-identity.
- Success check: it prints your account and ARN. If it fails, the problem is your AWS setup, not Pulumi.
- If you use static keys, export them: set
AWS_ACCESS_KEY_IDandAWS_SECRET_ACCESS_KEY(andAWS_SESSION_TOKENif you have one).
- Success check:
aws sts get-caller-identitynow works.
- If you use SSO, run
aws sso login(add--profile [profile]if you use a named profile) and make sure the Pulumi stack config points at that profile viaaws:profile.
- Success check: the SSO token cache refreshes and Pulumi stops reporting the error.
- For CI or teams, prefer Pulumi ESC with AWS OIDC dynamic credentials so short-lived credentials are minted per run instead of long-lived keys.
- Success check:
pulumi previewpasses in a clean environment with no static keys present.
When to use this
You hit this on pulumi preview or pulumi up with the AWS provider before any resource is created.
When NOT to use this
Do not use this for ExpiredToken or Failed to refresh cached SSO credentials. Those mean credentials existed and went stale; this one means none were found at all.
Compatibility
Pulumi CLI 3.x with the Pulumi AWS provider (v6.x). The credential chain behavior matches the underlying AWS SDK chain.
Variants
error: pulumi:providers:aws resource 'default' has a problem: Missing region informationerror: pulumi:providers:aws resource 'default' has a problem: Invalid credentials configured.Error: NoCredentialProviders: no valid providers in chain
Root cause
The AWS provider walks the standard credential chain (environment, shared credentials file, SSO cache, container/EC2 metadata). In the reported case only a region was configured and no credential source existed, so provider configuration failed before any API call.
Edge cases
- A region set without credentials produces this error, not a region error. Set both.
- In Docker or CI, the SSO token cache from your laptop is not present. Use OIDC or static keys there.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.