VectleSkillsError: Preview failed: unable to discover AWS AccessKeyID and/or SecretAccessKey

Error: Preview failed: unable to discover AWS AccessKeyID and/or SecretAccessKey

Export

Fixes Pulumi preview failing because the AWS provider cannot find an access key. For engineers whose stack config or environment changed and Pulumi stopped picking up AWS credentials, covering static keys, profiles, and the AWS SDK chain.

Error: Preview failed: unable to discover AWS AccessKeyID and/or SecretAccessKey

TL;DR

Pulumi cannot find AWS credentials anywhere in the chain. Verify with aws sts get-caller-identity, then provide credentials via environment variables, the shared credentials file, or an SSO profile, and make sure aws:region is set in stack config.

The error

error: Preview failed: unable to discover AWS AccessKeyID and/or SecretAccessKey - see https://pulumi.io/install/aws.html for details on configuration

Fix it

  1. Confirm the symptom is real: run aws sts get-caller-identity with the same environment Pulumi uses.
  • Success check: it returns your caller identity. If it fails, fix AWS CLI auth first.
  1. If you keep keys in stack config, check pulumi config shows aws:accessKey and a secret aws:secretKey. If a dependency update changed how stack config is read, re-set them with pulumi config set aws:accessKey [key] and pulumi config set --secret aws:secretKey [secret].
  • Success check: pulumi config lists both keys.
  1. If you use profiles, set aws:profile in stack config and confirm the profile exists in ~/.aws/config.
  • Success check: aws --profile [profile] sts get-caller-identity works.
  1. Re-run pulumi preview.
  • Success check: the preview renders instead of failing at provider configuration.

When to use this

You hit this at pulumi preview when AWS credentials that used to work stopped being picked up, often after a dependency or CLI update.

When NOT to use this

Do not use this for SSO token expiry (Failed to refresh cached SSO credentials) or for region-only misconfiguration. This error is specifically about the access key pair being undiscoverable.

Compatibility

Pulumi CLI 3.x, Pulumi AWS provider v6.x. Applies to TypeScript, Python, Go, and .NET programs alike.

Variants

  • Error: invocation of aws:index/getCallerIdentity:getCallerIdentity returned an error: unable to discover AWS AccessKeyID and/or SecretAccessKey
  • error: unable to discover AWS AccessKeyID and/or SecretAccessKey - see https://pulumi.io/install/aws.html for details on configuration as a per-resource diagnostic

Root cause

In the reported issue, aws:accessKey, aws:region, and aws:secretKey in Pulumi.[stack].yaml stopped being honored after a dependency update, so the provider fell back to the SDK chain, found nothing, and failed at preview time.

Edge cases

  • CI runners do not have your ~/.aws directory. Provide credentials via environment or OIDC there.
  • aws:skipCredentialsValidation does not help here; validation is not the problem, discovery is.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=Error%3A+Preview+failed%3A+unable+to+discover+AWS+AccessKeyID+and%2For+SecretAccessKey&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.