remotion-dev/remotion · error · Error

Unknown AWS Caller Identity ARN detected

Error message

Unknown AWS Caller Identity ARN detected

What it means

During Remotion Lambda's IAM policy simulation (e.g. `npx remotion lambda policies validate`), resolveCallerArnForSimulation() parses the ARN returned by STS GetCallerIdentity with the regex ^arn:([^:]+):([^:]+)::(\d+):([^/]+)(.*)$. If the ARN does not match - malformed, truncated, or an identity shape the parser does not know - this error is thrown and validation stops.

Solutions

  1. Inspect what your credentials actually report: `aws sts get-caller-identity` - compare the Arn shape against arn:PARTITION:SERVICE::ACCOUNT:RESOURCE
  2. Update @remotion/lambda to the latest version (ARN parsing gets extended over time)
  3. Run the command with plain IAM user or standard assumed-role credentials (long-lived keys or a normal CLI profile) as a workaround
  4. If the ARN looks valid, report it (account redacted) as a Remotion issue so the regex can be extended

Example fix

# before - exotic identity fails to parse
aws sts get-caller-identity
# "Arn": "arn:aws:sts::123456789012:assumed-role/dev"
npx remotion lambda policies validate

# after - use a standard session
aws sso login --profile standard-role  # or assume a normal role
npx remotion lambda policies validate
Defensive patterns

Strategy: type-guard

Validate before calling

// Before running validation, confirm your caller identity ARN is parseable
import {STClient, GetCallerIdentityCommand} from '@aws-sdk/client-sts';

const KnownCallerArn = /^arn:([^:]+):([^:]+)::(\d+):([^/]+)(.*)$/;
const isKnownCallerArn = (arn: string): boolean => KnownCallerArn.test(arn);

const identity = await sts.send(new GetCallerIdentityCommand({}));
if (!isKnownCallerArn(identity.Arn ?? '')) {
  // switch credentials / profile before running `lambda policies validate`
}

Type guard

const isParseableCallerArn = (arn: string): boolean =>
  /^arn:([^:]+):([^:]+)::(\d+):([^/]+)(.*)$/.test(arn);

Try / catch

try {
  execSync('npx remotion lambda policies validate', {stdio: 'inherit'});
} catch (err) {
  if (err instanceof Error && /Caller Identity ARN/i.test(String(err))) {
    console.error('Run `aws sts get-caller-identity` and inspect the Arn shape');
  }
  throw err;
}

Prevention

When it happens

Trigger: Running an IAM validation/simulation command when the STS caller identity ARN does not fit the expected 'arn:partition:service::account:resource' shape (note the empty field between the service and account). Any identity ARN with extra path segments before the account, or a non-IAM/STS service, fails to parse.

Common situations: Non-standard STS endpoints or credential processes returning unusual ARNs; AWS SSO/everyday credentials surfacing identity types the parser predates; hand-mocked STS responses in CI; older @remotion/lambda versions against newer AWS identity formats.

Related errors


AI-assisted analysis of remotion-dev/remotion@10db9de073 (2026-08-22). Data as JSON: /api/errors/d4b645905e8331b0. Report an issue: GitHub.

Appendix: source

Thrown at packages/lambda/src/api/iam-validation/resolve-caller-arn.ts:16

import type {AwsPartition, AwsRegion} from '@remotion/lambda-client';

export const resolveCallerArnForSimulation = ({
	callerIdentityArn,
	region,
	regionPartition,
}: {
	callerIdentityArn: string;
	region: AwsRegion;
	regionPartition: AwsPartition;
}): string => {
	const components = callerIdentityArn.match(
		/^arn:([^:]+):([^:]+)::(\d+):([^/]+)(.*)$/,
	);
	if (!components) {
		throw new Error('Unknown AWS Caller Identity ARN detected');
	}

	const callerPartition = components[1];
	if (callerPartition !== regionPartition) {
		throw new Error(
			`AWS Caller Identity partition ${callerPartition} does not match region ${region}, which uses partition ${regionPartition}.`,
		);
	}

	const service = components[2];
	const accountId = components[3];
	const resourceType = components[4];
	if (service === 'iam' && resourceType === 'user') {
		return callerIdentityArn;
	}

	if (service === 'sts' && resourceType === 'assumed-role') {
		const assumedRoleComponents = components[5].match(/^\/([^/]+)\/(.*)$/);

View on GitHub (pinned to 10db9de073)