Error: invocation of aws:index/getCallerIdentity:getCallerIdentity returned an error: unable to discover AWS AccessKeyID
Fixes Pulumi failing on AWS profiles that use role assumption with an MFA device. For engineers using aws:profile with a role_arn and mfa_serial whose preview fails at getCallerIdentity, with workarounds for the MFA gap.
Error: invocation of aws:index/getCallerIdentity:getCallerIdentity returned an error: unable to discover AWS AccessKeyID
TL;DR
Pulumi's AWS provider does not handle IAM roles that require an MFA device the way the AWS CLI does. If your profile chains to a role with mfa_serial, authenticate first with the AWS CLI (aws sts assume-role with your MFA code), export the temporary credentials, and point Pulumi at them.
The error
Error: invocation of aws:index/getCallerIdentity:getCallerIdentity returned an error: unable to discover AWS AccessKeyID and/or SecretAccessKey - see https://pulumi.io/install/aws.html for details on configurationFix it
- Confirm your profile needs MFA: check
~/.aws/configformfa_serialunder the profile you set asaws:profile.
- Success check: you see the MFA serial and a
role_arnwithsource_profile.
- Assume the role manually with an MFA code:
aws sts assume-role --role-arn [role arn] --role-session-name pulumi --serial-number [mfa arn] --token-code [code] --profile [source profile].
- Success check: the command returns temporary
AccessKeyId,SecretAccessKey, andSessionToken.
- Export the three values as
AWS_ACCESS_KEY_ID,AWS_SECRET_ACCESS_KEY, andAWS_SESSION_TOKEN, then runpulumi previewwithoutaws:profileset.
- Success check: the
getCallerIdentityinvocation succeeds and the preview renders.
- For a durable setup, switch to Pulumi ESC with AWS OIDC dynamic credentials instead of MFA-chained profiles.
- Success check: clean-shell
pulumi upworks with no static credentials.
When to use this
You hit this with aws:profile pointing at a profile that assumes a role through an MFA device, where aws --profile [name] ec2 describe-instances works (it prompts for MFA) but Pulumi fails.
When NOT to use this
Do not use this for plain missing credentials or expired SSO tokens. This is specifically the MFA role-assumption gap.
Compatibility
Pulumi CLI 3.x, Pulumi AWS provider v6.x. The behavior difference vs the AWS CLI is long-standing.
Variants
error: unable to discover AWS AccessKeyID and/or SecretAccessKeyon a profile withrole_arnbut no MFA- Pulumi hanging when the session token from a manual assume-role expires (re-export fresh credentials)
Root cause
The AWS CLI prompts for an MFA code when a profile chains to an MFA-protected role. Pulumi's provider never prompts, so credential discovery silently finds nothing and the getCallerIdentity data source invocation fails.
Edge cases
- Temporary credentials expire. When the session token expires Pulumi can hang rather than error clearly; re-export fresh ones.
aws:skipCredentialsValidationdoes not bypass this; the failure happens during credential discovery, not validation.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.