{"record":{"id":"d9b264bfc88bd86d","repo":"remotion-dev/remotion","slug":"unsupported-aws-caller-identity-arn-detected","errorCode":null,"errorMessage":"Unsupported AWS Caller Identity ARN detected","messagePattern":"Unsupported AWS Caller Identity ARN detected","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/lambda/src/api/iam-validation/resolve-caller-arn.ts","lineNumber":44,"sourceCode":"\tconst service = components[2];\n\tconst accountId = components[3];\n\tconst resourceType = components[4];\n\tif (service === 'iam' && resourceType === 'user') {\n\t\treturn callerIdentityArn;\n\t}\n\n\tif (service === 'sts' && resourceType === 'assumed-role') {\n\t\tconst assumedRoleComponents = components[5].match(/^\\/([^/]+)\\/(.*)$/);\n\t\tif (!assumedRoleComponents) {\n\t\t\tthrow new Error(\n\t\t\t\t'Unsupported AWS Caller Identity as Assumed-Role ARN detected',\n\t\t\t);\n\t\t}\n\n\t\treturn `arn:${callerPartition}:iam::${accountId}:role/${assumedRoleComponents[1]}`;\n\t}\n\n\tthrow new Error('Unsupported AWS Caller Identity ARN detected');\n};\n","sourceCodeStart":26,"sourceCodeEnd":46,"githubUrl":"https://github.com/remotion-dev/remotion/blob/10db9de07356446fb0edb3c3ae211369b693d18b/packages/lambda/src/api/iam-validation/resolve-caller-arn.ts#L26-L46","documentation":"Thrown by resolveCallerArnForSimulation when simulating IAM permissions (e.g. `npx remotion lambda policies validate`). The function parses the AWS Caller Identity ARN and only supports `arn:<partition>:iam::<account>:user/<name>` and STS assumed-role ARNs `arn:<partition>:sts::<account>:assumed-role/<role>/<session>`, rewriting the latter to an IAM role ARN. Any other ARN shape (e.g. `sts:federated-user`, `sts` with a resource type other than `assumed-role`) cannot be mapped to a principal for policy simulation, so the library refuses it.","triggerScenarios":"Running `npx remotion lambda permissions validate` (or the validatePermissions API / simulate IAM flow) while authenticated with an STS identity that is not an assumed-role, such as `arn:aws:sts::123456789012:federated-user/bob` or an irregular role-session ARN that fails the `/role/session` split.","commonSituations":"Using SAML/OIDC federation or a web-identity session whose get-caller-identity output is a federated-user ARN; using a customSTS setup or an AWS SSO token broker that produces non-standard session ARNs; running the validation from a CI role that was assumed through a tool producing exotic session names with extra slashes.","solutions":["Run `aws sts get-caller-identity` and inspect the Arn field; if it is not an iam user or an sts assumed-role ARN, re-authenticate as one of those (e.g. `aws sts assume-role` and export the resulting credentials).","If you are federated, assume an IAM role inside the account first (`aws sts assume-role --role-arn ... --role-session-name remotion`) and run the validation with those temporary credentials.","As a workaround, skip the policy simulation and grant the documented Remotion Lambda permissions manually, or run the simulation from a regular IAM user."],"exampleFix":"# before: authenticated as federated-user\naws sts get-caller-identity\n# \"Arn\": \"arn:aws:sts::123456789012:federated-user/alice\"\nnpx remotion lambda policies validate --region us-east-1  # -> Unsupported AWS Caller Identity ARN detected\n\n# after: assume a role first\naws sts assume-role --role-arn arn:aws:iam::123456789012:role/remotion-validate --role-session-name validate\nexport AWS_ACCESS_KEY_ID=... AWS_SECRET_ACCESS_KEY=... AWS_SESSION_TOKEN=...\nnpx remotion lambda policies validate --region us-east-1","handlingStrategy":"try-catch","validationCode":"// Check the identity shape before running policy validation\nimport {STSClient, GetCallerIdentityCommand} from '@aws-sdk/client-sts';\nconst id = await new STSClient({}).send(new GetCallerIdentityCommand());\nconst arn = id.Arn ?? '';\nconst ok =\n  /^arn:[^:]+:iam::\\d{12}:user\\/.+/.test(arn) ||\n  /^arn:[^:]+:sts::\\d{12}:assumed-role\\/[^/]+\\/.+$/.test(arn);\nif (!ok) throw new Error(`Re-authenticate as IAM user or assumed role: ${arn}`);","typeGuard":"const isSupportedCallerArn = (arn: string): boolean =>\n  /^arn:[^:]+:iam::\\d{12}:user\\/[A-Za-z0-9+=,.@\\/_-]+$/.test(arn) ||\n  /^arn:[^:]+:sts::\\d{12}:assumed-role\\/[^/]+\\/.+$/.test(arn);","tryCatchPattern":"try {\n  await validatePermissions({...});\n} catch (e) {\n  if (e instanceof Error && /Caller Identity ARN/i.test(e.message)) {\n    // re-authenticate (assume-role) and retry, or skip simulation\n  } else throw e;\n}","preventionTips":["Run `aws sts get-caller-identity` before invoking permission validation scripts.","In CI, always run validation through an assumed IAM role, not a federated or root identity.","Keep a small preflight that asserts the ARN is a user or assumed-role shape."],"tags":["aws","iam","arn","sts","policy-validation"],"backgroundTag":"unsupported-caller-identity-arn","analyzedSha":"10db9de07356446fb0edb3c3ae211369b693d18b","analyzedAt":"2026-08-22T21:45:17.748Z","contentChangedAt":"2026-08-22T21:45:17.748Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}