## TL;DR

The AWS provider found no credentials at all: no env vars, no shared config profile, no instance metadata. This fails before any API call. Set up one credential source (env vars or `AWS_PROFILE`), verify with `aws sts get-caller-identity`, then re-run.

## The error

```text
Error: error configuring Terraform AWS Provider: no valid credential sources for Terraform AWS Provider found.
```

## Steps to fix

1. Check what the provider can see:
   ```bash
   aws sts get-caller-identity
   ```
   - Expected: if this fails, credentials are missing or expired outside Terraform too.
2. Provide one source. Environment variables:
   ```bash
   export AWS_ACCESS_KEY_ID="..."
   export AWS_SECRET_ACCESS_KEY [your value]
   export AWS_DEFAULT_REGION="us-east-1"
   ```
   or a named profile: `export AWS_PROFILE="production"`.
   - Expected: `aws sts get-caller-identity` now succeeds.
3. Re-run `terraform plan` in the same shell (env vars do not cross shells).
   - Expected: provider configures and planning starts.

## When to use this

- `terraform plan`/`apply` fails immediately with `no valid credential sources`, usually on a new machine, in CI without OIDC/role setup, or after keys were rotated.

## When NOT to use this

- `403`/`AccessDenied` errors mean credentials exist but lack permission: that is an IAM policy problem, not this one. SSO `aws sso login` expiry also presents differently.

## Compatibility

- AWS provider all versions; the credential chain order (env, shared config, EC2 metadata, ECS) is stable.

## Root cause

The AWS SDK checks a fixed chain of credential sources. In CI or fresh shells, none of them is populated: no env vars exported, no `~/.aws/credentials` profile, no instance role. Terraform surfaces the SDK's "nothing found" as a provider configuration error.

## Edge cases

- `AWS_PROFILE` pointing at an SSO profile needs a fresh `aws sso login`; the profile existing is not enough.
- In CI, prefer OIDC-to-IAM-role over long-lived keys; the error is identical when the OIDC trust is misconfigured.
- `AWS_DEFAULT_REGION` vs `AWS_REGION`: the provider reads both, but some tools only set one; set the region explicitly in the provider block to be safe.