remotion-dev/remotion · error · Error

Unsupported AWS Caller Identity as Assumed-Role ARN detected

Error message

Unsupported AWS Caller Identity as Assumed-Role ARN detected

What it means

When your STS caller identity is an assumed role, resolveCallerArnForSimulation() converts the STS ARN into the underlying IAM role ARN by matching the resource part against '/role-name/session-id'. If that trailing segment does not have the expected 'role-name/session-id' shape (typically a session id is missing), the ARN is considered unsupported and the error is thrown, aborting policy simulation.

Solutions

  1. Check the exact ARN with `aws sts get-caller-identity` - an assumed-role ARN must end in '/RoleName/SessionId'
  2. Re-authenticate through a standard path (aws sso login, aws sts assume-role from the CLI) so the session ARN is well-formed
  3. As a workaround, run the validation with IAM user credentials or a directly attached role
  4. Report the malformed ARN shape (account redacted) to Remotion so the parser can be extended

Example fix

# before - malformed assumed-role ARN from a custom broker
aws sts get-caller-identity
# "Arn": "arn:aws:sts::123456789012:assumed-role/RemotionRole"
npx remotion lambda policies validate  # throws

# after - assume the role with the AWS CLI (session id included)
aws sts assume-role --role-arn arn:aws:iam::123456789012:role/RemotionRole \
  --role-session-name validate
# export the returned keys, then:
npx remotion lambda policies validate
Defensive patterns

Strategy: try-catch

Validate before calling

// Verify the assumed-role session ARN carries a session id before validating
const AssumedRoleArn =
  /^arn:([^:]+):sts::(\d+):assumed-role\/([^/]+)\/(.+)$/;
const isStandardAssumedRoleArn = (arn: string): boolean =>
  AssumedRoleArn.test(arn);

Type guard

const isStandardAssumedRoleArn = (arn: string): boolean =>
  /^arn:([^:]+):sts::(\d+):assumed-role\/([^/]+)\/(.+)$/.test(arn);

Try / catch

try {
  execSync('npx remotion lambda policies validate', {stdio: 'inherit'});
} catch (err) {
  if (
    err instanceof Error &&
    /Unsupported AWS Caller Identity/i.test(String(err))
  ) {
    // re-authenticate with a standard `aws sts assume-role` session and retry
  }
  throw err;
}

Prevention

When it happens

Trigger: Running a Remotion Lambda IAM validation/simulation while authenticated via an assumed role whose STS ARN resource part is not '/RoleName/SessionId' - e.g. a truncated 'arn:aws:sts::123:assumed-role/MyRole' without the session segment, or a custom STS-compatible identity provider emitting non-standard ARNs (packages/lambda/src/api/iam-validation/resolve-caller-arn.ts:33-39).

Common situations: Custom credential processes or STS-compatible brokers (minikube-style STS shims, workplace identity bridges) that emit malformed assumed-role ARNs; mocked STS in tests; unusual automatic role sessions that omit the session name.

Related errors


AI-assisted analysis of remotion-dev/remotion@10db9de073 (2026-08-22). Data as JSON: /api/errors/918149cf42210cdf. Report an issue: GitHub.

Appendix: source

Thrown at packages/lambda/src/api/iam-validation/resolve-caller-arn.ts:36

	const callerPartition = components[1];
	if (callerPartition !== regionPartition) {
		throw new Error(
			`AWS Caller Identity partition ${callerPartition} does not match region ${region}, which uses partition ${regionPartition}.`,
		);
	}

	const service = components[2];
	const accountId = components[3];
	const resourceType = components[4];
	if (service === 'iam' && resourceType === 'user') {
		return callerIdentityArn;
	}

	if (service === 'sts' && resourceType === 'assumed-role') {
		const assumedRoleComponents = components[5].match(/^\/([^/]+)\/(.*)$/);
		if (!assumedRoleComponents) {
			throw new Error(
				'Unsupported AWS Caller Identity as Assumed-Role ARN detected',
			);
		}

		return `arn:${callerPartition}:iam::${accountId}:role/${assumedRoleComponents[1]}`;
	}

	throw new Error('Unsupported AWS Caller Identity ARN detected');
};

View on GitHub (pinned to 10db9de073)