# Error: Error querying AMI: NoCredentialProviders: no valid providers in chain (Packer)

## TL;DR
Packer found no AWS credentials in any source. Provide them via environment variables, a profile, or `-var` flags for `aws_access_key`/`aws_secret_key`, then rebuild.

## The error

```
==> amazonebs: Prevalidating AMI Name...
==> amazonebs: Error querying AMI: NoCredentialProviders: no valid providers in chain
==> amazonebs: caused by: EnvAccessKeyNotFound: failed to find credentials in the environment.
==> amazonebs: SharedCredsLoad: failed to load profile, .
==> amazonebs: EC2RoleRequestError: no EC2 instance role found
```

## Fix it

1. Check the environment Packer runs in: `aws sts get-caller-identity`.
   - Success check: it works. If not, the problem is AWS auth, not Packer.
2. Provide credentials one of these ways: export `AWS_ACCESS_KEY_ID`/`AWS_SECRET_ACCESS_KEY`, set `aws_profile` in the template, or pass `-var 'aws_access_key [your value] -var 'aws_secret_key [your value]
   - Success check: `packer build` gets past AMI querying.
3. On EC2 build hosts, attach an instance profile with AMI permissions instead of static keys.
   - Success check: no credentials in the environment, yet the build works.
4. Re-run `packer build`.
   - Success check: `Prevalidating AMI Name` succeeds and the build proceeds.

## When to use this
You hit this at the start of an amazon-ebs build, before any instance launches.

## When NOT to use this
Do not use this for SSH failures later in the build or for `UnauthorizedOperation` on specific APIs. This is specifically the empty credential chain.

## Compatibility
Packer 1.x, amazon builders. The chain matches the AWS SDK.

## Variants
- `EnvAccessKeyNotFound`, `SharedCredsLoad: failed to load profile`, `EC2RoleRequestError` as the `caused by` lines
- The same failure on `amazon-instance`, `amazon-ebssurrogate`, and other EC2 builders

## Root cause
The AWS SDK chain (env, shared config, SSO, container/EC2 metadata) found nothing. Packer surfaces the aggregate `NoCredentialProviders` when the first AWS call (AMI lookup) runs.

## Edge cases
- A profile name set but the profile missing from `~/.aws/config` gives `SharedCredsLoad` specifically. Check the profile name.
- CI runners have no `~/.aws`. Use env vars or OIDC there.
