Error: no valid credential sources for Terraform AWS Provider found
Fixes the AWS provider's "no valid credential sources for Terraform AWS Provider found" error: missing or expired credentials, wrong profile, or wrong region env. Use when plan/apply fails before any API call. Verify with aws sts get-caller-identity; not for 403 permission errors (those are IAM policy, not missing creds).
TL;DR
The AWS provider found no credentials at all: no env vars, no shared config profile, no instance metadata. This fails before any API call. Set up one credential source (env vars or AWS_PROFILE), verify with aws sts get-caller-identity, then re-run.
The error
Error: error configuring Terraform AWS Provider: no valid credential sources for Terraform AWS Provider found.Steps to fix
Check what the provider can see:
aws sts get-caller-identity- Expected: if this fails, credentials are missing or expired outside Terraform too.
Provide one source. Environment variables:
export AWS_ACCESS_KEY_ID="..." export AWS_SECRET_ACCESS_KEY [your value] export AWS_DEFAULT_REGION="us-east-1"or a named profile:
export AWS_PROFILE="production".- Expected:
aws sts get-caller-identitynow succeeds.
- Expected:
Re-run
terraform planin the same shell (env vars do not cross shells).- Expected: provider configures and planning starts.
When to use this
terraform plan/applyfails immediately withno valid credential sources, usually on a new machine, in CI without OIDC/role setup, or after keys were rotated.
When NOT to use this
403/AccessDeniederrors mean credentials exist but lack permission: that is an IAM policy problem, not this one. SSOaws sso loginexpiry also presents differently.
Compatibility
- AWS provider all versions; the credential chain order (env, shared config, EC2 metadata, ECS) is stable.
Root cause
The AWS SDK checks a fixed chain of credential sources. In CI or fresh shells, none of them is populated: no env vars exported, no ~/.aws/credentials profile, no instance role. Terraform surfaces the SDK's "nothing found" as a provider configuration error.
Edge cases
AWS_PROFILEpointing at an SSO profile needs a freshaws sso login; the profile existing is not enough.- In CI, prefer OIDC-to-IAM-role over long-lived keys; the error is identical when the OIDC trust is misconfigured.
AWS_DEFAULT_REGIONvsAWS_REGION: the provider reads both, but some tools only set one; set the region explicitly in the provider block to be safe.