Error: Preview failed: unable to discover AWS AccessKeyID and/or SecretAccessKey
Fixes Pulumi preview failing because the AWS provider cannot find an access key. For engineers whose stack config or environment changed and Pulumi stopped picking up AWS credentials, covering static keys, profiles, and the AWS SDK chain.
Error: Preview failed: unable to discover AWS AccessKeyID and/or SecretAccessKey
TL;DR
Pulumi cannot find AWS credentials anywhere in the chain. Verify with aws sts get-caller-identity, then provide credentials via environment variables, the shared credentials file, or an SSO profile, and make sure aws:region is set in stack config.
The error
error: Preview failed: unable to discover AWS AccessKeyID and/or SecretAccessKey - see https://pulumi.io/install/aws.html for details on configurationFix it
- Confirm the symptom is real: run
aws sts get-caller-identitywith the same environment Pulumi uses.
- Success check: it returns your caller identity. If it fails, fix AWS CLI auth first.
- If you keep keys in stack config, check
pulumi configshowsaws:accessKeyand a secretaws:secretKey. If a dependency update changed how stack config is read, re-set them withpulumi config set aws:accessKey [key]andpulumi config set --secret aws:secretKey [secret].
- Success check:
pulumi configlists both keys.
- If you use profiles, set
aws:profilein stack config and confirm the profile exists in~/.aws/config.
- Success check:
aws --profile [profile] sts get-caller-identityworks.
- Re-run
pulumi preview.
- Success check: the preview renders instead of failing at provider configuration.
When to use this
You hit this at pulumi preview when AWS credentials that used to work stopped being picked up, often after a dependency or CLI update.
When NOT to use this
Do not use this for SSO token expiry (Failed to refresh cached SSO credentials) or for region-only misconfiguration. This error is specifically about the access key pair being undiscoverable.
Compatibility
Pulumi CLI 3.x, Pulumi AWS provider v6.x. Applies to TypeScript, Python, Go, and .NET programs alike.
Variants
Error: invocation of aws:index/getCallerIdentity:getCallerIdentity returned an error: unable to discover AWS AccessKeyID and/or SecretAccessKeyerror: unable to discover AWS AccessKeyID and/or SecretAccessKey - see https://pulumi.io/install/aws.html for details on configurationas a per-resource diagnostic
Root cause
In the reported issue, aws:accessKey, aws:region, and aws:secretKey in Pulumi.[stack].yaml stopped being honored after a dependency update, so the provider fell back to the SDK chain, found nothing, and failed at preview time.
Edge cases
- CI runners do not have your
~/.awsdirectory. Provide credentials via environment or OIDC there. aws:skipCredentialsValidationdoes not help here; validation is not the problem, discovery is.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.