Error: pulumi:providers:aws resource 'default' has a problem: Failed to refresh cached SSO credentials
Fixes the Pulumi AWS provider failing when cached AWS SSO credentials expire. For engineers using AWS SSO whose previously working stack starts failing at preview, the fix is re-authenticating with the AWS CLI.
Error: pulumi:providers:aws resource 'default' has a problem: Failed to refresh cached SSO credentials
TL;DR
Your cached AWS SSO token expired. Run aws sso login (with --profile [profile] if you use one), then re-run pulumi preview. For CI or long-lived setups, move to Pulumi ESC with AWS OIDC dynamic credentials.
The error
Diagnostics:
pulumi:providers:aws (default):
error: pulumi:providers:aws resource 'default' has a problem: Failed to refresh cached SSO credentials.
Please refresh SSO login.Fix it
- Re-authenticate:
aws sso login(oraws sso login --profile [profile]).
- Success check: the browser flow completes and the CLI reports a successful login.
- Verify the refresh worked:
aws sts get-caller-identity --profile [profile].
- Success check: it prints your identity instead of an SSO error.
- Re-run
pulumi previeworpulumi up.
- Success check: the provider configures and the operation proceeds.
- If this keeps recurring in automation, replace SSO-cache auth with Pulumi ESC dynamic credentials via AWS OIDC.
- Success check: unattended runs stop failing on SSO expiry.
When to use this
You hit this on a stack that used to work with AWS SSO, and the only thing that changed is time passing.
When NOT to use this
Do not use this for No valid credential sources found (nothing configured) or ExpiredToken on manually exported session keys (refresh those keys instead).
Compatibility
Pulumi CLI 3.x, Pulumi AWS provider v6.x, AWS CLI v2 with SSO configured.
Variants
error: pulumi:providers:aws resource 'provider' has a problem: Failed to refresh cached SSO credentials.Unable to locate credentials(bare; check how the project authenticates before guessing)
Root cause
AWS SSO tokens are short-lived. The provider reads the SSO token cache written by aws sso login; once it expires, refresh fails and provider configuration errors out. Pulumi cannot trigger the interactive SSO flow itself.
Edge cases
- Multiple profiles: make sure you log in to the profile your stack actually uses (
aws:profilein stack config). - In containers or CI there is no browser for the SSO flow. Use OIDC or static credentials there.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.