TL;DR: boto3 looked in every credential source (env vars, shared credentials file, IAM role) and found nothing. Run `aws configure` or export AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY, then retry. If you are on EC2/Lambda/ECS, attach an IAM role instead.

```text
botocore.exceptions.NoCredentialsError: Unable to locate credentials
```

## Fix it

1. Check what boto3 sees: run `aws sts get-caller-identity`. Expected on success: your account ARN. If it errors, credentials are missing or broken.
2. Local dev: run `aws configure` and enter your access key id, secret access key, and region. Expected: ~/.aws/credentials now has a [default] profile.
3. Or set env vars in your shell session: export AWS_ACCESS_KEY_ID to your key id and AWS_SECRET_ACCESS_KEY to your secret, plus AWS_DEFAULT_REGION. Expected: the sts call succeeds.
4. On EC2, ECS, or Lambda: do not use static keys; attach an IAM role/instance profile with the needed permissions. Expected: boto3 picks up role credentials automatically.

## When this applies
- The error is exactly NoCredentialsError: Unable to locate credentials.
- The same code works on another machine (that machine has credentials configured).

## When it doesn't
- The error is InvalidClientTokenId or SignatureDoesNotMatch: credentials exist but are wrong; check the key values.
- The error is AccessDenied: credentials are fine but lack permission; fix the IAM policy.

## Compatibility
- boto3/botocore any version. AWS CLI v1/v2 for the aws configure step.

## Why it happens
boto3 resolves credentials through a chain: explicit args, env vars, shared credentials file, container credentials, instance metadata. NoCredentialsError means every link came up empty.

## Edge cases
- PartialCredentialsError (only one of the pair set) is a different error with a different fix: set both.
- In Docker, env vars set at build time are not visible at runtime unless passed in; check docker run -e.
- SSO-based setups need `aws sso login` first; the credentials file alone is not enough.
