{"record":{"id":"918149cf42210cdf","repo":"remotion-dev/remotion","slug":"unsupported-aws-caller-identity-as-assumed-role-ar","errorCode":null,"errorMessage":"Unsupported AWS Caller Identity as Assumed-Role ARN detected","messagePattern":"Unsupported AWS Caller Identity as Assumed-Role ARN detected","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/lambda/src/api/iam-validation/resolve-caller-arn.ts","lineNumber":36,"sourceCode":"\n\tconst callerPartition = components[1];\n\tif (callerPartition !== regionPartition) {\n\t\tthrow new Error(\n\t\t\t`AWS Caller Identity partition ${callerPartition} does not match region ${region}, which uses partition ${regionPartition}.`,\n\t\t);\n\t}\n\n\tconst service = components[2];\n\tconst accountId = components[3];\n\tconst resourceType = components[4];\n\tif (service === 'iam' && resourceType === 'user') {\n\t\treturn callerIdentityArn;\n\t}\n\n\tif (service === 'sts' && resourceType === 'assumed-role') {\n\t\tconst assumedRoleComponents = components[5].match(/^\\/([^/]+)\\/(.*)$/);\n\t\tif (!assumedRoleComponents) {\n\t\t\tthrow new Error(\n\t\t\t\t'Unsupported AWS Caller Identity as Assumed-Role ARN detected',\n\t\t\t);\n\t\t}\n\n\t\treturn `arn:${callerPartition}:iam::${accountId}:role/${assumedRoleComponents[1]}`;\n\t}\n\n\tthrow new Error('Unsupported AWS Caller Identity ARN detected');\n};\n","sourceCodeStart":18,"sourceCodeEnd":46,"githubUrl":"https://github.com/remotion-dev/remotion/blob/10db9de07356446fb0edb3c3ae211369b693d18b/packages/lambda/src/api/iam-validation/resolve-caller-arn.ts#L18-L46","documentation":"When your STS caller identity is an assumed role, resolveCallerArnForSimulation() converts the STS ARN into the underlying IAM role ARN by matching the resource part against '/role-name/session-id'. If that trailing segment does not have the expected 'role-name/session-id' shape (typically a session id is missing), the ARN is considered unsupported and the error is thrown, aborting policy simulation.","triggerScenarios":"Running a Remotion Lambda IAM validation/simulation while authenticated via an assumed role whose STS ARN resource part is not '/RoleName/SessionId' - e.g. a truncated 'arn:aws:sts::123:assumed-role/MyRole' without the session segment, or a custom STS-compatible identity provider emitting non-standard ARNs (packages/lambda/src/api/iam-validation/resolve-caller-arn.ts:33-39).","commonSituations":"Custom credential processes or STS-compatible brokers (minikube-style STS shims, workplace identity bridges) that emit malformed assumed-role ARNs; mocked STS in tests; unusual automatic role sessions that omit the session name.","solutions":["Check the exact ARN with `aws sts get-caller-identity` - an assumed-role ARN must end in '/RoleName/SessionId'","Re-authenticate through a standard path (aws sso login, aws sts assume-role from the CLI) so the session ARN is well-formed","As a workaround, run the validation with IAM user credentials or a directly attached role","Report the malformed ARN shape (account redacted) to Remotion so the parser can be extended"],"exampleFix":"# before - malformed assumed-role ARN from a custom broker\naws sts get-caller-identity\n# \"Arn\": \"arn:aws:sts::123456789012:assumed-role/RemotionRole\"\nnpx remotion lambda policies validate  # throws\n\n# after - assume the role with the AWS CLI (session id included)\naws sts assume-role --role-arn arn:aws:iam::123456789012:role/RemotionRole \\\n  --role-session-name validate\n# export the returned keys, then:\nnpx remotion lambda policies validate","handlingStrategy":"try-catch","validationCode":"// Verify the assumed-role session ARN carries a session id before validating\nconst AssumedRoleArn =\n  /^arn:([^:]+):sts::(\\d+):assumed-role\\/([^/]+)\\/(.+)$/;\nconst isStandardAssumedRoleArn = (arn: string): boolean =>\n  AssumedRoleArn.test(arn);","typeGuard":"const isStandardAssumedRoleArn = (arn: string): boolean =>\n  /^arn:([^:]+):sts::(\\d+):assumed-role\\/([^/]+)\\/(.+)$/.test(arn);","tryCatchPattern":"try {\n  execSync('npx remotion lambda policies validate', {stdio: 'inherit'});\n} catch (err) {\n  if (\n    err instanceof Error &&\n    /Unsupported AWS Caller Identity/i.test(String(err))\n  ) {\n    // re-authenticate with a standard `aws sts assume-role` session and retry\n  }\n  throw err;\n}","preventionTips":["Assume roles through the standard AWS CLI/SDK so session ARNs keep the /role/session shape","Check broker/custom STS output with aws sts get-caller-identity before using it with Remotion","Update @remotion/lambda when new identity shapes are supported"],"tags":["aws","sts","assumed-role","arn","iam-validation","remotion","lambda"],"backgroundTag":"aws-arn-parse-failed","analyzedSha":"10db9de07356446fb0edb3c3ae211369b693d18b","analyzedAt":"2026-08-22T21:45:17.748Z","contentChangedAt":"2026-08-22T21:45:17.748Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}