{"record":{"id":"d4b645905e8331b0","repo":"remotion-dev/remotion","slug":"unknown-aws-caller-identity-arn-detected","errorCode":null,"errorMessage":"Unknown AWS Caller Identity ARN detected","messagePattern":"Unknown AWS Caller Identity ARN detected","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/lambda/src/api/iam-validation/resolve-caller-arn.ts","lineNumber":16,"sourceCode":"import type {AwsPartition, AwsRegion} from '@remotion/lambda-client';\n\nexport const resolveCallerArnForSimulation = ({\n\tcallerIdentityArn,\n\tregion,\n\tregionPartition,\n}: {\n\tcallerIdentityArn: string;\n\tregion: AwsRegion;\n\tregionPartition: AwsPartition;\n}): string => {\n\tconst components = callerIdentityArn.match(\n\t\t/^arn:([^:]+):([^:]+)::(\\d+):([^/]+)(.*)$/,\n\t);\n\tif (!components) {\n\t\tthrow new Error('Unknown AWS Caller Identity ARN detected');\n\t}\n\n\tconst callerPartition = components[1];\n\tif (callerPartition !== regionPartition) {\n\t\tthrow new Error(\n\t\t\t`AWS Caller Identity partition ${callerPartition} does not match region ${region}, which uses partition ${regionPartition}.`,\n\t\t);\n\t}\n\n\tconst service = components[2];\n\tconst accountId = components[3];\n\tconst resourceType = components[4];\n\tif (service === 'iam' && resourceType === 'user') {\n\t\treturn callerIdentityArn;\n\t}\n\n\tif (service === 'sts' && resourceType === 'assumed-role') {\n\t\tconst assumedRoleComponents = components[5].match(/^\\/([^/]+)\\/(.*)$/);","sourceCodeStart":1,"sourceCodeEnd":34,"githubUrl":"https://github.com/remotion-dev/remotion/blob/10db9de07356446fb0edb3c3ae211369b693d18b/packages/lambda/src/api/iam-validation/resolve-caller-arn.ts#L1-L34","documentation":"During Remotion Lambda's IAM policy simulation (e.g. `npx remotion lambda policies validate`), resolveCallerArnForSimulation() parses the ARN returned by STS GetCallerIdentity with the regex ^arn:([^:]+):([^:]+)::(\\d+):([^/]+)(.*)$. If the ARN does not match - malformed, truncated, or an identity shape the parser does not know - this error is thrown and validation stops.","triggerScenarios":"Running an IAM validation/simulation command when the STS caller identity ARN does not fit the expected 'arn:partition:service::account:resource' shape (note the empty field between the service and account). Any identity ARN with extra path segments before the account, or a non-IAM/STS service, fails to parse.","commonSituations":"Non-standard STS endpoints or credential processes returning unusual ARNs; AWS SSO/everyday credentials surfacing identity types the parser predates; hand-mocked STS responses in CI; older @remotion/lambda versions against newer AWS identity formats.","solutions":["Inspect what your credentials actually report: `aws sts get-caller-identity` - compare the Arn shape against arn:PARTITION:SERVICE::ACCOUNT:RESOURCE","Update @remotion/lambda to the latest version (ARN parsing gets extended over time)","Run the command with plain IAM user or standard assumed-role credentials (long-lived keys or a normal CLI profile) as a workaround","If the ARN looks valid, report it (account redacted) as a Remotion issue so the regex can be extended"],"exampleFix":"# before - exotic identity fails to parse\naws sts get-caller-identity\n# \"Arn\": \"arn:aws:sts::123456789012:assumed-role/dev\"\nnpx remotion lambda policies validate\n\n# after - use a standard session\naws sso login --profile standard-role  # or assume a normal role\nnpx remotion lambda policies validate","handlingStrategy":"type-guard","validationCode":"// Before running validation, confirm your caller identity ARN is parseable\nimport {STClient, GetCallerIdentityCommand} from '@aws-sdk/client-sts';\n\nconst KnownCallerArn = /^arn:([^:]+):([^:]+)::(\\d+):([^/]+)(.*)$/;\nconst isKnownCallerArn = (arn: string): boolean => KnownCallerArn.test(arn);\n\nconst identity = await sts.send(new GetCallerIdentityCommand({}));\nif (!isKnownCallerArn(identity.Arn ?? '')) {\n  // switch credentials / profile before running `lambda policies validate`\n}","typeGuard":"const isParseableCallerArn = (arn: string): boolean =>\n  /^arn:([^:]+):([^:]+)::(\\d+):([^/]+)(.*)$/.test(arn);","tryCatchPattern":"try {\n  execSync('npx remotion lambda policies validate', {stdio: 'inherit'});\n} catch (err) {\n  if (err instanceof Error && /Caller Identity ARN/i.test(String(err))) {\n    console.error('Run `aws sts get-caller-identity` and inspect the Arn shape');\n  }\n  throw err;\n}","preventionTips":["Standardize on IAM user or standard assumed-role credentials for Remotion deploys","Run aws sts get-caller-identity once per CI job to assert the identity shape","Update @remotion/lambda before reporting ARN parsing issues"],"tags":["aws","sts","arn","iam-validation","remotion","lambda"],"backgroundTag":"aws-arn-parse-failed","analyzedSha":"10db9de07356446fb0edb3c3ae211369b693d18b","analyzedAt":"2026-08-22T21:45:17.748Z","contentChangedAt":"2026-08-22T21:45:17.748Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}