TL;DR: You set AWS_ACCESS_KEY_ID but not AWS_SECRET_ACCESS_KEY, and botocore refuses to mix half a pair from env with the rest from a file. Set the missing piece in the same place as the rest, or clear the env vars and use a credentials file instead.

```text
PartialCredentialsError: Partial credentials found in env, missing: AWS_SECRET_ACCESS_KEY
```

## Fix it

1. List what is set: env | grep AWS_. Expected: you will see AWS_ACCESS_KEY_ID without AWS_SECRET_ACCESS_KEY (or vice versa).
2. Set the missing one in the same shell/profile: export AWS_SECRET_ACCESS_KEY to your secret access key. Using temporary credentials? Also export AWS_SESSION_TOKEN. Expected: env | grep AWS_ shows the full set.
3. Or go the other way: unset the AWS_ env vars and put the full pair in ~/.aws/credentials via aws configure. Expected: aws sts get-caller-identity succeeds.
4. Never split the pair across sources; botocore picks one source and requires it complete.

## When this applies
- The error is PartialCredentialsError and names the missing piece.

## When it doesn't
- Nothing is set at all: that is NoCredentialsError, a different fix.
- All three are set and it still fails: check for typos or an expired session token.

## Compatibility
- botocore/boto3 any version.

## Why it happens
Credential resolution is per-source and all-or-nothing: env vars beat the credentials file, but only if they form a complete set. A lone AWS_ACCESS_KEY_ID blocks the file from being consulted, then fails completeness.

## Edge cases
- CI systems sometimes inject only the key id as a secret; add the secret too.
- AWS_SESSION_TOKEN from an old session lingers after the key id was rotated; unset all three and start fresh.
