# Error: pulumi:providers:aws resource 'default' has a problem: No valid credential sources found

## TL;DR
The AWS provider found no credentials in any of its sources. Set up credentials the way your setup expects: environment variables, `~/.aws/credentials`, `aws sso login`, or Pulumi ESC dynamic credentials with AWS OIDC. Then re-run `pulumi preview`.

## The error

```
Diagnostics:
  pulumi:providers:aws (default):
    error: pulumi:providers:aws resource 'default' has a problem: No valid credential sources found.
    Please see https://www.pulumi.com/registry/packages/aws/installation-configuration/ for more information about providing credentials.
```

## Fix it

1. Check what is actually configured: `aws sts get-caller-identity`.
   - Success check: it prints your account and ARN. If it fails, the problem is your AWS setup, not Pulumi.
2. If you use static keys, export them: set `AWS_ACCESS_KEY_ID` and `AWS_SECRET_ACCESS_KEY` (and `AWS_SESSION_TOKEN` if you have one).
   - Success check: `aws sts get-caller-identity` now works.
3. If you use SSO, run `aws sso login` (add `--profile [profile]` if you use a named profile) and make sure the Pulumi stack config points at that profile via `aws:profile`.
   - Success check: the SSO token cache refreshes and Pulumi stops reporting the error.
4. For CI or teams, prefer Pulumi ESC with AWS OIDC dynamic credentials so short-lived credentials are minted per run instead of long-lived keys.
   - Success check: `pulumi preview` passes in a clean environment with no static keys present.

## When to use this
You hit this on `pulumi preview` or `pulumi up` with the AWS provider before any resource is created.

## When NOT to use this
Do not use this for `ExpiredToken` or `Failed to refresh cached SSO credentials`. Those mean credentials existed and went stale; this one means none were found at all.

## Compatibility
Pulumi CLI 3.x with the Pulumi AWS provider (v6.x). The credential chain behavior matches the underlying AWS SDK chain.

## Variants
- `error: pulumi:providers:aws resource 'default' has a problem: Missing region information`
- `error: pulumi:providers:aws resource 'default' has a problem: Invalid credentials configured.`
- `Error: NoCredentialProviders: no valid providers in chain`

## Root cause
The AWS provider walks the standard credential chain (environment, shared credentials file, SSO cache, container/EC2 metadata). In the reported case only a region was configured and no credential source existed, so provider configuration failed before any API call.

## Edge cases
- A region set without credentials produces this error, not a region error. Set both.
- In Docker or CI, the SSO token cache from your laptop is not present. Use OIDC or static keys there.
