# Error: Preview failed: unable to discover AWS AccessKeyID and/or SecretAccessKey

## TL;DR
Pulumi cannot find AWS credentials anywhere in the chain. Verify with `aws sts get-caller-identity`, then provide credentials via environment variables, the shared credentials file, or an SSO profile, and make sure `aws:region` is set in stack config.

## The error

```
error: Preview failed: unable to discover AWS AccessKeyID and/or SecretAccessKey - see https://pulumi.io/install/aws.html for details on configuration
```

## Fix it

1. Confirm the symptom is real: run `aws sts get-caller-identity` with the same environment Pulumi uses.
   - Success check: it returns your caller identity. If it fails, fix AWS CLI auth first.
2. If you keep keys in stack config, check `pulumi config` shows `aws:accessKey` and a secret `aws:secretKey`. If a dependency update changed how stack config is read, re-set them with `pulumi config set aws:accessKey [key]` and `pulumi config set --secret aws:secretKey [secret]`.
   - Success check: `pulumi config` lists both keys.
3. If you use profiles, set `aws:profile` in stack config and confirm the profile exists in `~/.aws/config`.
   - Success check: `aws --profile [profile] sts get-caller-identity` works.
4. Re-run `pulumi preview`.
   - Success check: the preview renders instead of failing at provider configuration.

## When to use this
You hit this at `pulumi preview` when AWS credentials that used to work stopped being picked up, often after a dependency or CLI update.

## When NOT to use this
Do not use this for SSO token expiry (`Failed to refresh cached SSO credentials`) or for region-only misconfiguration. This error is specifically about the access key pair being undiscoverable.

## Compatibility
Pulumi CLI 3.x, Pulumi AWS provider v6.x. Applies to TypeScript, Python, Go, and .NET programs alike.

## Variants
- `Error: invocation of aws:index/getCallerIdentity:getCallerIdentity returned an error: unable to discover AWS AccessKeyID and/or SecretAccessKey`
- `error: unable to discover AWS AccessKeyID and/or SecretAccessKey - see https://pulumi.io/install/aws.html for details on configuration` as a per-resource diagnostic

## Root cause
In the reported issue, `aws:accessKey`, `aws:region`, and `aws:secretKey` in `Pulumi.[stack].yaml` stopped being honored after a dependency update, so the provider fell back to the SDK chain, found nothing, and failed at preview time.

## Edge cases
- CI runners do not have your `~/.aws` directory. Provide credentials via environment or OIDC there.
- `aws:skipCredentialsValidation` does not help here; validation is not the problem, discovery is.
