remotion-dev/remotion · error · Error
Unknown AWS Caller Identity ARN detected
Error message
Unknown AWS Caller Identity ARN detected
What it means
During Remotion Lambda's IAM policy simulation (e.g. `npx remotion lambda policies validate`), resolveCallerArnForSimulation() parses the ARN returned by STS GetCallerIdentity with the regex ^arn:([^:]+):([^:]+)::(\d+):([^/]+)(.*)$. If the ARN does not match - malformed, truncated, or an identity shape the parser does not know - this error is thrown and validation stops.
Solutions
- Inspect what your credentials actually report: `aws sts get-caller-identity` - compare the Arn shape against arn:PARTITION:SERVICE::ACCOUNT:RESOURCE
- Update @remotion/lambda to the latest version (ARN parsing gets extended over time)
- Run the command with plain IAM user or standard assumed-role credentials (long-lived keys or a normal CLI profile) as a workaround
- If the ARN looks valid, report it (account redacted) as a Remotion issue so the regex can be extended
Example fix
# before - exotic identity fails to parse aws sts get-caller-identity # "Arn": "arn:aws:sts::123456789012:assumed-role/dev" npx remotion lambda policies validate # after - use a standard session aws sso login --profile standard-role # or assume a normal role npx remotion lambda policies validate
Defensive patterns
Strategy: type-guard
Validate before calling
// Before running validation, confirm your caller identity ARN is parseable
import {STClient, GetCallerIdentityCommand} from '@aws-sdk/client-sts';
const KnownCallerArn = /^arn:([^:]+):([^:]+)::(\d+):([^/]+)(.*)$/;
const isKnownCallerArn = (arn: string): boolean => KnownCallerArn.test(arn);
const identity = await sts.send(new GetCallerIdentityCommand({}));
if (!isKnownCallerArn(identity.Arn ?? '')) {
// switch credentials / profile before running `lambda policies validate`
} Type guard
const isParseableCallerArn = (arn: string): boolean => /^arn:([^:]+):([^:]+)::(\d+):([^/]+)(.*)$/.test(arn);
Try / catch
try {
execSync('npx remotion lambda policies validate', {stdio: 'inherit'});
} catch (err) {
if (err instanceof Error && /Caller Identity ARN/i.test(String(err))) {
console.error('Run `aws sts get-caller-identity` and inspect the Arn shape');
}
throw err;
} Prevention
- Standardize on IAM user or standard assumed-role credentials for Remotion deploys
- Run aws sts get-caller-identity once per CI job to assert the identity shape
- Update @remotion/lambda before reporting ARN parsing issues
When it happens
Trigger: Running an IAM validation/simulation command when the STS caller identity ARN does not fit the expected 'arn:partition:service::account:resource' shape (note the empty field between the service and account). Any identity ARN with extra path segments before the account, or a non-IAM/STS service, fails to parse.
Common situations: Non-standard STS endpoints or credential processes returning unusual ARNs; AWS SSO/everyday credentials surfacing identity types the parser predates; hand-mocked STS responses in CI; older @remotion/lambda versions against newer AWS identity formats.
Related errors
- Unsupported AWS Caller Identity as Assumed-Role ARN detected
- AWS Caller Identity partition
- No valid AWS Caller Identity detected
- Failed to update Layers for function
- Unsupported AWS Caller Identity ARN detected
AI-assisted analysis of remotion-dev/remotion@10db9de073 (2026-08-22).
Data as JSON: /api/errors/d4b645905e8331b0.
Report an issue: GitHub.
Appendix: source
Thrown at packages/lambda/src/api/iam-validation/resolve-caller-arn.ts:16
import type {AwsPartition, AwsRegion} from '@remotion/lambda-client';
export const resolveCallerArnForSimulation = ({
callerIdentityArn,
region,
regionPartition,
}: {
callerIdentityArn: string;
region: AwsRegion;
regionPartition: AwsPartition;
}): string => {
const components = callerIdentityArn.match(
/^arn:([^:]+):([^:]+)::(\d+):([^/]+)(.*)$/,
);
if (!components) {
throw new Error('Unknown AWS Caller Identity ARN detected');
}
const callerPartition = components[1];
if (callerPartition !== regionPartition) {
throw new Error(
`AWS Caller Identity partition ${callerPartition} does not match region ${region}, which uses partition ${regionPartition}.`,
);
}
const service = components[2];
const accountId = components[3];
const resourceType = components[4];
if (service === 'iam' && resourceType === 'user') {
return callerIdentityArn;
}
if (service === 'sts' && resourceType === 'assumed-role') {
const assumedRoleComponents = components[5].match(/^\/([^/]+)\/(.*)$/);View on GitHub (pinned to 10db9de073)