{"record":{"id":"3800e7eb0554835b","repo":"grpc/grpc-go","slug":"extproc-failed-to-parse-grpc-service-v","errorCode":null,"errorMessage":"extproc: failed to parse grpc_service %v","messagePattern":"extproc: failed to parse grpc_service (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/xds/httpfilter/extproc/ext_proc.go","lineNumber":130,"sourceCode":"\t\treturn nil, fmt.Errorf(\"extproc: error parsing config %v: unknown type %T, want *anypb.Any\", cfg, cfg)\n\t}\n\tmsg := new(v3procfilterpb.ExternalProcessor)\n\tif err := m.UnmarshalTo(msg); err != nil {\n\t\treturn nil, fmt.Errorf(\"extproc: failed to unmarshal config %v: %v\", cfg, err)\n\t}\n\tif msg.GetProcessingMode() == nil {\n\t\treturn nil, fmt.Errorf(\"extproc: missing processing_mode in config %v\", cfg)\n\t}\n\tif err := validateBodyProcessingMode(msg.GetProcessingMode()); err != nil {\n\t\treturn nil, err\n\t}\n\n\tif msg.GetGrpcService() == nil {\n\t\treturn nil, fmt.Errorf(\"extproc: empty grpc_service provided in config %v\", cfg)\n\t}\n\tserver, err := iextproc.ParseGRPCServiceConfig(msg.GetGrpcService())\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"extproc: failed to parse grpc_service %v\", err)\n\t}\n\n\tmutationRules, err := httpfilter.HeaderMutationRulesFromProto(msg.GetMutationRules())\n\tif err != nil {\n\t\treturn nil, err\n\t}\n\n\tvar allowedHeaders, disallowedHeaders []matcher.StringMatcher\n\tif allowed := msg.GetForwardRules().GetAllowedHeaders(); allowed != nil {\n\t\tallowedHeaders, err = httpfilter.ConvertStringMatchers(allowed.GetPatterns())\n\t\tif err != nil {\n\t\t\treturn nil, err\n\t\t}\n\t}\n\n\tif disallowed := msg.GetForwardRules().GetDisallowedHeaders(); disallowed != nil {\n\t\tdisallowedHeaders, err = httpfilter.ConvertStringMatchers(disallowed.GetPatterns())\n\t\tif err != nil {","sourceCodeStart":112,"sourceCodeEnd":148,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/xds/httpfilter/extproc/ext_proc.go#L112-L148","documentation":"Returned by ParseFilterConfig when iextproc.ParseGRPCServiceConfig fails to turn the grpc_service proto into a usable xdsresource.GRPCServiceConfig. The inner error (wrapped as %v) typically indicates a missing/unsupported credential type, missing target, or an unrecognized grpc_service variant. Hit at ext_proc.go:130.","triggerScenarios":"An ExternalProcessor.grpc_service is present but malformed: uses a credential type grpc-go does not support (e.g. some google_grpc channel args), has an empty target URI, or specifies an envoy_grpc cluster that cannot be resolved by the bootstrap.","commonSituations":"Control plane emits google_grpc with call_credentials grpc-go does not implement; target_uri is blank; a custom security plugin is configured but not registered; bootstrap lacks the cluster referenced by envoy_grpc.","solutions":["Read the wrapped %v error to identify the specific parse failure (credentials vs target vs plugin).","Ensure grpc_service uses a target URI and credential combination grpc-go's ext_proc supports (typically mTLS/insecure from the bootstrap).","If using envoy_grpc, confirm the cluster exists in the bootstrap cluster map.","Simplify the grpc_service to a known-working config (insecure + target) and re-add complexity incrementally."],"exampleFix":"# before\ngrpc_service:\n  google_grpc:\n    target_uri: \"\"\n    ssl_credentials: { google_default: {} }\n# after\ngrpc_service:\n  envoy_grpc:\n    cluster_name: ext-proc-cluster  # defined in bootstrap with mTLS","handlingStrategy":"validation","validationCode":"// pre-check the grpc_service is one grpc-go can parse\nif cfg.GetGrpcService() == nil { return fmt.Errorf(\"nil grpc_service\") }\nif cfg.GetGrpcService().GetEnvoyGrpc().GetClusterName() == \"\" &&\n   cfg.GetGrpcService().GetGoogleGrpc().GetTargetUri() == \"\" {\n  return fmt.Errorf(\"grpc_service missing target\")\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Use supported credential types (mTLS/insecure from bootstrap).","Ensure referenced envoy_grpc clusters exist in the bootstrap.","Simplify to insecure+target first, then add complexity.","Read the wrapped %v to localize the parse failure."],"tags":["grpc","xds","extproc","config","grpc-service"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}