remotion-dev/remotion · error · Error
Unsupported AWS Caller Identity as Assumed-Role ARN detected
Error message
Unsupported AWS Caller Identity as Assumed-Role ARN detected
What it means
When your STS caller identity is an assumed role, resolveCallerArnForSimulation() converts the STS ARN into the underlying IAM role ARN by matching the resource part against '/role-name/session-id'. If that trailing segment does not have the expected 'role-name/session-id' shape (typically a session id is missing), the ARN is considered unsupported and the error is thrown, aborting policy simulation.
Solutions
- Check the exact ARN with `aws sts get-caller-identity` - an assumed-role ARN must end in '/RoleName/SessionId'
- Re-authenticate through a standard path (aws sso login, aws sts assume-role from the CLI) so the session ARN is well-formed
- As a workaround, run the validation with IAM user credentials or a directly attached role
- Report the malformed ARN shape (account redacted) to Remotion so the parser can be extended
Example fix
# before - malformed assumed-role ARN from a custom broker aws sts get-caller-identity # "Arn": "arn:aws:sts::123456789012:assumed-role/RemotionRole" npx remotion lambda policies validate # throws # after - assume the role with the AWS CLI (session id included) aws sts assume-role --role-arn arn:aws:iam::123456789012:role/RemotionRole \ --role-session-name validate # export the returned keys, then: npx remotion lambda policies validate
Defensive patterns
Strategy: try-catch
Validate before calling
// Verify the assumed-role session ARN carries a session id before validating const AssumedRoleArn = /^arn:([^:]+):sts::(\d+):assumed-role\/([^/]+)\/(.+)$/; const isStandardAssumedRoleArn = (arn: string): boolean => AssumedRoleArn.test(arn);
Type guard
const isStandardAssumedRoleArn = (arn: string): boolean => /^arn:([^:]+):sts::(\d+):assumed-role\/([^/]+)\/(.+)$/.test(arn);
Try / catch
try {
execSync('npx remotion lambda policies validate', {stdio: 'inherit'});
} catch (err) {
if (
err instanceof Error &&
/Unsupported AWS Caller Identity/i.test(String(err))
) {
// re-authenticate with a standard `aws sts assume-role` session and retry
}
throw err;
} Prevention
- Assume roles through the standard AWS CLI/SDK so session ARNs keep the /role/session shape
- Check broker/custom STS output with aws sts get-caller-identity before using it with Remotion
- Update @remotion/lambda when new identity shapes are supported
When it happens
Trigger: Running a Remotion Lambda IAM validation/simulation while authenticated via an assumed role whose STS ARN resource part is not '/RoleName/SessionId' - e.g. a truncated 'arn:aws:sts::123:assumed-role/MyRole' without the session segment, or a custom STS-compatible identity provider emitting non-standard ARNs (packages/lambda/src/api/iam-validation/resolve-caller-arn.ts:33-39).
Common situations: Custom credential processes or STS-compatible brokers (minikube-style STS shims, workplace identity bridges) that emit malformed assumed-role ARNs; mocked STS in tests; unusual automatic role sessions that omit the session name.
Related errors
- Unknown AWS Caller Identity ARN detected
- AWS Caller Identity partition
- No valid AWS Caller Identity detected
- Failed to update Layers for function
- Unsupported AWS Caller Identity ARN detected
AI-assisted analysis of remotion-dev/remotion@10db9de073 (2026-08-22).
Data as JSON: /api/errors/918149cf42210cdf.
Report an issue: GitHub.
Appendix: source
Thrown at packages/lambda/src/api/iam-validation/resolve-caller-arn.ts:36
const callerPartition = components[1];
if (callerPartition !== regionPartition) {
throw new Error(
`AWS Caller Identity partition ${callerPartition} does not match region ${region}, which uses partition ${regionPartition}.`,
);
}
const service = components[2];
const accountId = components[3];
const resourceType = components[4];
if (service === 'iam' && resourceType === 'user') {
return callerIdentityArn;
}
if (service === 'sts' && resourceType === 'assumed-role') {
const assumedRoleComponents = components[5].match(/^\/([^/]+)\/(.*)$/);
if (!assumedRoleComponents) {
throw new Error(
'Unsupported AWS Caller Identity as Assumed-Role ARN detected',
);
}
return `arn:${callerPartition}:iam::${accountId}:role/${assumedRoleComponents[1]}`;
}
throw new Error('Unsupported AWS Caller Identity ARN detected');
};
View on GitHub (pinned to 10db9de073)