exec: "aws-iam-authenticator": executable file not found in $PATH
Routes k9s EKS exec-plugin binary-not-found errors. Use when k9s can not connect because the aws-iam-authenticator executable is missing from PATH. Not for expired tokens or RBAC errors.
Your kubeconfig's EKS exec entry calls aws-iam-authenticator, but k9s can not find that binary on its PATH - common when k9s is launched from a GUI, a different shell, or a minimal install. Install aws-iam-authenticator and make sure it is on the PATH k9s sees, or switch the exec entry to aws eks get-token (needs only the AWS CLI). k9s connects on next refresh.
The error
Unable to connect to the server: getting credentials: exec: executable aws-iam-authenticator not foundWhat to do
- Confirm it is missing:
which aws-iam-authenticatorExpected: Empty output.
- Install it via your package manager or the EKS release download, then
which aws-iam-authenticatoragain.
Expected: Prints a path like /usr/local/bin/aws-iam-authenticator.
- Alternative: point the kubeconfig exec command at the AWS CLI:
users:
- name: [user]
user:
exec:
apiVersion: client.authentication.k8s.io/v1beta1
command: aws
args: ["eks", "get-token", "--cluster-name", "[cluster]"]Expected: Saves cleanly.
- Restart k9s.
Expected: Cluster connects.
When this applies
- k9s against EKS with an aws-iam-authenticator exec entry
- executable not found in PATH messages naming the plugin
- GUI-launched k9s with a sparse PATH
When it does NOT apply
- invalid apiVersion exec errors (version mismatch, not missing binary)
- expired AWS credentials (different error)
Works with
k9s with EKS kubeconfigs; AWS CLI v1/v2 for the alternative
exec: "gke-gcloud-auth-plugin": executable file not found in $PATH
Same missing-binary shape for GKE. Install gke-gcloud-auth-plugin instead.
exec: "kubelogin": executable file not found in $PATH
Same shape for OIDC setups. Install kubelogin and put it on PATH.
Why it happens
Exec plugins are separate binaries the kubeconfig invokes per auth. k9s inherits its PATH from however it was launched - a terminal and a desktop launcher can see different PATHs, so kubectl works in the shell while k9s fails.
Edge cases
- If k9s is started from a .desktop file, add the binary's directory to PATH in ~/.profile or use the full binary path in the exec command.
- aws eks get-token needs valid AWS credentials configured - check aws sts get-caller-identity first.
Resolved from
gh:derailed/k9s#309 - https://github.com/derailed/k9s/issues/309
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.