{"record":{"id":"0609eba5d13cbeed","repo":"grpc/grpc-go","slug":"gcpauthn-cache-config-cache-size-must-be-greater","errorCode":null,"errorMessage":"gcpauthn: cache_config.cache_size must be greater than zero","messagePattern":"gcpauthn: cache_config\\.cache_size must be greater than zero","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/xds/httpfilter/gcp_authn/gcp_authn_filter.go","lineNumber":75,"sourceCode":"\nfunc (builder) TypeURLs() []string {\n\treturn []string{\"type.googleapis.com/envoy.extensions.filters.http.gcp_authn.v3.GcpAuthnFilterConfig\"}\n}\n\nfunc (builder) ParseFilterConfig(cfg proto.Message) (httpfilter.FilterConfig, error) {\n\tm, ok := cfg.(*anypb.Any)\n\tif !ok {\n\t\treturn nil, fmt.Errorf(\"gcpauthn: invalid filter config type %T\", cfg)\n\t}\n\tmsg := &v3gcpauthnpb.GcpAuthnFilterConfig{}\n\tif err := m.UnmarshalTo(msg); err != nil {\n\t\treturn nil, fmt.Errorf(\"gcpauthn: failed to unmarshal filter config: %v\", err)\n\t}\n\n\tcacheSize := uint64(defaultCacheSize)\n\tif cacheSizeConfig := msg.GetCacheConfig().GetCacheSize(); cacheSizeConfig != nil {\n\t\tif cacheSize = cacheSizeConfig.GetValue(); cacheSize == 0 {\n\t\t\treturn nil, fmt.Errorf(\"gcpauthn: cache_config.cache_size must be greater than zero\")\n\t\t}\n\t}\n\n\treturn config{cacheSize: cacheSize}, nil\n}\n\n// ParseFilterConfigOverride parses the provided override configuration.\n//\n// Note that we don't support overrides for this filter configuration,\n// but still validate it as part of the normal resource validation.\nfunc (b builder) ParseFilterConfigOverride(cfg proto.Message) (httpfilter.FilterConfig, error) {\n\treturn b.ParseFilterConfig(cfg)\n}\n\nfunc (builder) IsTerminal() bool {\n\treturn false\n}\n","sourceCodeStart":57,"sourceCodeEnd":93,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/xds/httpfilter/gcp_authn/gcp_authn_filter.go#L57-L93","documentation":"ParseFilterConfig (gcp_authn_filter.go:74) validates that when cache_config.cache_size is explicitly set, it must be greater than zero. A value of zero is rejected because an LRU credentials cache of size zero cannot function.","triggerScenarios":"GcpAuthnFilterConfig.cache_config.cache_size is set to a wrapperspb.UInt64Value with value 0. If the field is left unset, the default of 10 applies and this error is not raised.","commonSituations":"Operator explicitly sets cache_size: 0 (misunderstanding it as 'unlimited' or 'disabled'); automation templating that defaults numeric fields to zero.","solutions":["Set cache_config.cache_size to a positive integer (e.g., 10 or higher).","If unsure, omit the cache_size field entirely so the default of 10 is used.","Audit Helm/YAML templates that coerce empty numeric inputs to 0."],"exampleFix":"// before\ncacheConfig: { cacheSize: { value: 0 } }\n\n// after\ncacheConfig: { cacheSize: { value: 10 } }","handlingStrategy":"validation","validationCode":"if cs := msg.GetCacheConfig().GetCacheSize(); cs != nil && cs.GetValue() == 0 {\n    return nil, errors.New(\"gcpauthn: cache_size must be > 0; fix the config before sending\")\n}","typeGuard":null,"tryCatchPattern":"if err != nil && strings.Contains(err.Error(), \"cache_size must be greater than zero\") {\n    // bump cache_size in the xDS config to a positive integer\n}","preventionTips":["Omit cache_size to use the default of 10 when unsure.","Audit templating that defaults numeric fields to zero."],"tags":["gcp-authn","config","validation","xds","grpc"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}