Upgrade Octopus Server to 2024.4.3812 or any 2025.1+ release. The failure happens at package acquisition time against the ECR feed, so no amount of credential rotation on the AWS side fixes it; it is a server-side bug. After upgrading, re-run the failed deployment and confirm the acquire-package step retrieves the token.

Context: GitHub issue OctopusDeploy/Issues#9044 (closed): deployments with a package step fail with Unable to retrieve AWS Authorization token when an ECR feed is configured as an external feed. A maintainer confirms the fix shipped in 2024.4.3812 and all 2025.1+ releases.