{"record":{"id":"489a327eafe6ad54","repo":"grpc/grpc-go","slug":"grpc-no-transport-security-set-use-grpc-withtran","errorCode":null,"errorMessage":"grpc: no transport security set (use grpc.WithTransportCredentials(insecure.NewCredentials()) explicitly or set credentials)","messagePattern":"grpc: no transport security set \\(use grpc\\.WithTransportCredentials\\(insecure\\.NewCredentials\\(\\)\\) explicitly or set credentials\\)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"clientconn.go","lineNumber":90,"sourceCode":"\terrConnDrain = errors.New(\"grpc: the connection is drained\")\n\t// errConnClosing indicates that the connection is closing.\n\terrConnClosing = errors.New(\"grpc: the connection is closing\")\n\t// errConnIdling indicates the connection is being closed as the channel\n\t// is moving to an idle mode due to inactivity.\n\terrConnIdling = errors.New(\"grpc: the connection is closing due to channel idleness\")\n\t// invalidDefaultServiceConfigErrPrefix is used to prefix the json parsing error for the default\n\t// service config.\n\tinvalidDefaultServiceConfigErrPrefix = \"grpc: the provided default service config is invalid\"\n\t// PickFirstBalancerName is the name of the pick_first balancer.\n\tPickFirstBalancerName = pickfirst.Name\n)\n\n// The following errors are returned from Dial and DialContext\nvar (\n\t// errNoTransportSecurity indicates that there is no transport security\n\t// being set for ClientConn. Users should either set one or explicitly\n\t// call WithInsecure DialOption to disable security.\n\terrNoTransportSecurity = errors.New(\"grpc: no transport security set (use grpc.WithTransportCredentials(insecure.NewCredentials()) explicitly or set credentials)\")\n\t// errTransportCredsAndBundle indicates that creds bundle is used together\n\t// with other individual Transport Credentials.\n\terrTransportCredsAndBundle = errors.New(\"grpc: credentials.Bundle may not be used with individual TransportCredentials\")\n\t// errNoTransportCredsInBundle indicated that the configured creds bundle\n\t// returned a transport credentials which was nil.\n\terrNoTransportCredsInBundle = errors.New(\"grpc: credentials.Bundle must return non-nil transport credentials\")\n\t// errTransportCredentialsMissing indicates that users want to transmit\n\t// security information (e.g., OAuth2 token) which requires secure\n\t// connection on an insecure connection.\n\terrTransportCredentialsMissing = errors.New(\"grpc: the credentials require transport level security (use grpc.WithTransportCredentials() to set)\")\n)\n\nvar (\n\tdisconnectionsMetric = expstats.RegisterInt64Count(expstats.MetricDescriptor{\n\t\tName:           \"grpc.subchannel.disconnections\",\n\t\tDescription:    \"EXPERIMENTAL. Number of times the selected subchannel becomes disconnected.\",\n\t\tUnit:           \"{disconnection}\",\n\t\tLabels:         []string{\"grpc.target\"},","sourceCodeStart":72,"sourceCodeEnd":108,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/clientconn.go#L72-L108","documentation":"Thrown by buildLogger when the registered audit logger factory's ParseLoggerConfig method returns an error while parsing the custom config JSON. The factory (obtained via audit.GetLoggerBuilder) receives the raw JSON extracted from the TypedConfig and attempts to unmarshal it into its internal configuration struct. If the JSON does not match the expected schema, the parse fails.","triggerScenarios":"A registered custom audit logger's ParseLoggerConfig receives a JSON payload (from a TypedStruct or StdoutAuditLog config) whose structure does not match what the factory expects — missing required fields, wrong types, or malformed JSON. For the built-in stdout logger, the config is a StdoutAuditLog proto marshalled to JSON, so schema mismatches are unlikely; for custom loggers using TypedStruct, the Struct fields may not align with the factory's expectations.","commonSituations":"A custom audit logger registered via audit.RegisterLogger whose ParseLoggerConfig has strict schema requirements not met by the control-plane-provided config. A TypedStruct whose value fields are incorrectly typed (e.g., a number where a string is expected). Version mismatch between the control plane's idea of the logger config schema and the factory's parser.","solutions":["Inspect the inner error (%v) to see the exact parse failure, then adjust the config JSON to match the factory's expected schema.","If using a custom audit logger, ensure the control plane emits a TypedStruct whose fields exactly match what ParseLoggerConfig expects.","Register a ParseLoggerConfig that is lenient about extra or missing optional fields, or align the schemas between the control plane and the logger factory."],"exampleFix":"// before: custom logger factory expects {\"output_path\": \"...\"}\n// but control plane sends {\"path\": \"/var/log/audit.json\"}\n\n// after: align the field name in the control plane config\nconfig:\n  output_path: \"/var/log/audit.json\"","handlingStrategy":"try-catch","validationCode":"// Pre-validate the JSON config against the factory's expectations:\nfunc validateLoggerConfig(factory audit.LoggerBuilder, rawJSON json.RawMessage) error {\n    if factory == nil {\n        return fmt.Errorf(\"no factory\")\n    }\n    _, err := factory.ParseLoggerConfig(rawJSON)\n    return err\n}","typeGuard":null,"tryCatchPattern":"// Catch parse errors during engine construction and report with context:\nengine, err := rbac.NewChainEngine(policies, \"\")\nif err != nil && strings.Contains(err.Error(), \"custom config could not be parsed\") {\n    log.Printf(\"audit logger config parse failed; check JSON schema: %v\", err)\n    // fall back to no audit logging or retry with corrected config\n}","preventionTips":["Round-trip test every custom audit logger config: marshal -> factory.ParseLoggerConfig -> verify fields.","Document the exact JSON schema your custom logger factory expects and share it with control-plane authors.","Add JSON schema validation on the control plane before sending TypedStruct configs."],"tags":["xds","rbac","grpc","audit","config","json"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}