{"record":{"id":"09c16fa7f5f294ab","repo":"grpc/grpc-go","slug":"security-configuration-on-the-client-side-does-not","errorCode":null,"errorMessage":"security configuration on the client-side does not contain root certificate provider instance name","messagePattern":"security configuration on the client-side does not contain root certificate provider instance name","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/xds/xdsclient/xdsresource/unmarshal_cds.go","lineNumber":418,"sourceCode":"\tsc, err1 := securityConfigFromCommonTLSContextUsingNewFields(common, server)\n\tif sc == nil || sc.Equal(&SecurityConfig{}) {\n\t\tvar err error\n\t\tsc, err = securityConfigFromCommonTLSContextWithDeprecatedFields(common, server)\n\t\tif err != nil {\n\t\t\t// Retain the validation error from using the new fields.\n\t\t\treturn nil, errors.Join(err1, fmt.Errorf(\"failed to parse config using deprecated fields: %v\", err))\n\t\t}\n\t}\n\tif sc != nil {\n\t\t// sc == nil is a valid case where the control plane has not sent us any\n\t\t// security configuration. xDS creds will use fallback creds.\n\t\tif server {\n\t\t\tif sc.IdentityInstanceName == \"\" {\n\t\t\t\treturn nil, errors.New(\"security configuration on the server-side does not contain identity certificate provider instance name\")\n\t\t\t}\n\t\t} else {\n\t\t\tif !sc.UseSystemRootCerts && sc.RootInstanceName == \"\" {\n\t\t\t\treturn nil, errors.New(\"security configuration on the client-side does not contain root certificate provider instance name\")\n\t\t\t}\n\t\t}\n\t}\n\treturn sc, nil\n}\n\nfunc securityConfigFromCommonTLSContextWithDeprecatedFields(common *v3tlspb.CommonTlsContext, server bool) (*SecurityConfig, error) {\n\t// The `CommonTlsContext` contains a\n\t// `tls_certificate_certificate_provider_instance` field of type\n\t// `CertificateProviderInstance`, which contains the provider instance name\n\t// and the certificate name to fetch identity certs.\n\tsc := &SecurityConfig{}\n\tif identity := common.GetTlsCertificateCertificateProviderInstance(); identity != nil {\n\t\tsc.IdentityInstanceName = identity.GetInstanceName()\n\t\tsc.IdentityCertName = identity.GetCertificateName()\n\t}\n\n\t// The `CommonTlsContext` contains a `validation_context_type` field which","sourceCodeStart":400,"sourceCodeEnd":436,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/xds/xdsclient/xdsresource/unmarshal_cds.go#L400-L436","documentation":"Thrown by securityConfigFromCommonTLSContext on the client side when the parsed SecurityConfig neither uses system roots (UseSystemRootCerts==false) nor has a RootInstanceName. grpc-go needs either a root certificate provider instance name or system root certs to validate the server's certificate. The error surfaces while unmarshaling a CDS cluster's upstream TLS context after both new and deprecated field paths failed to supply a validation/ root context.","triggerScenarios":"A CDS UpstreamTlsContext is sent where combined_validation_context / validation_context / validation_context_sds_secret_config do not resolve to a non-empty certificate_provider_instance instance_name, and the system_root_certs field is not set. Equivalent deprecated fields (validation_context_certificate_provider_instance) are also empty.","commonSituations":"Control-plane config for a cluster enables TLS but omits the root/CA validation context. Bootstrap file lacks a root cert provider registration. Migration between SDS field names dropped the root provider name. Private CA setup where the operator forgot to attach the root cert bundle provider.","solutions":["Ensure the CDS UpstreamTlsContext provides a validation context with a non-empty certificate_provider_instance instance_name, or set system_root_certs=true to fall back to the OS trust store.","Check the deprecated combined_validation_context.default_validation_context path still populates the provider instance if the control plane uses deprecated fields.","Verify the xDS bootstrap certificate_providers map registers the root provider name the control plane references.","Confirm the control-plane-side CA/secret rotation pipeline still emits the root cert to SDS for that provider name."],"exampleFix":"// before: cluster has TLS but no validation context\n//   transport_socket: { name: \"tls\", typed_config: { common_tls_context: {} } }\n//\n// after: supply a root cert provider instance name\n//   transport_socket: {\n//     name: \"tls\",\n//     typed_config: {\n//       common_tls_context: {\n//         validation_context: {\n//           certificate_provider_instance: { instance_name: \"roots\" }\n//         }\n//       }\n//     }\n//   }","handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":"Handle in the xDS watcher callback (WatchCluster) by logging the cluster name and version; alert operations that the cluster's validation context is missing. No client-side retry will help until the control plane re-sends a valid config.","preventionTips":["Policy-check all CDS UpstreamTlsContext resources to ensure validation_context or system_root_certs is populated.","Maintain a bootstrap template that always registers a default root cert provider.","During migrations between SDS field names, run an integration test that asserts RootInstanceName is non-empty before promotion."],"tags":["xds","tls","cds","mtls","security-config","control-plane","validation-context"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}