{"record":{"id":"4fdf98f88b6e91c0","repo":"grpc/grpc-go","slug":"client-side-auth-info-is-not-of-type-alts-authinfo","errorCode":null,"errorMessage":"client-side auth info is not of type alts.AuthInfo","messagePattern":"client-side auth info is not of type alts\\.AuthInfo","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"credentials/alts/alts.go","lineNumber":208,"sourceCode":"\topts.TargetServiceAccounts = g.accounts\n\topts.RPCVersions = &altspb.RpcProtocolVersions{\n\t\tMaxRpcVersion: maxRPCVersion,\n\t\tMinRpcVersion: minRPCVersion,\n\t}\n\topts.BoundAccessToken = g.boundAccessToken\n\tchs, err := handshaker.NewClientHandshaker(ctx, hsConn, rawConn, opts)\n\tif err != nil {\n\t\treturn nil, nil, err\n\t}\n\t// Close the handshaker since we have obtained a connection.\n\tdefer chs.Close()\n\tsecConn, authInfo, err := chs.ClientHandshake(ctx)\n\tif err != nil {\n\t\treturn nil, nil, err\n\t}\n\taltsAuthInfo, ok := authInfo.(AuthInfo)\n\tif !ok {\n\t\treturn nil, nil, errors.New(\"client-side auth info is not of type alts.AuthInfo\")\n\t}\n\tmatch, _ := checkRPCVersions(opts.RPCVersions, altsAuthInfo.PeerRPCVersions())\n\tif !match {\n\t\treturn nil, nil, fmt.Errorf(\"server-side RPC versions are not compatible with this client, local versions: %v, peer versions: %v\", opts.RPCVersions, altsAuthInfo.PeerRPCVersions())\n\t}\n\treturn secConn, authInfo, nil\n}\n\n// ServerHandshake implements the server side ALTS handshaker.\nfunc (g *altsTC) ServerHandshake(rawConn net.Conn) (_ net.Conn, _ credentials.AuthInfo, err error) {\n\tif !vmOnGCP {\n\t\treturn nil, nil, ErrUntrustedPlatform\n\t}\n\t// Connecting to ALTS handshaker service.\n\thsConn, err := service.Dial(g.hsAddress)\n\tif err != nil {\n\t\treturn nil, nil, err\n\t}","sourceCodeStart":190,"sourceCodeEnd":226,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/credentials/alts/alts.go#L190-L226","documentation":"Thrown by matchersFromPrincipals in its default switch case when a Principal proto's Identifier oneof is set to a variant that gRPC RBAC does not handle. The supported principal types are: AndIds, OrIds, Any, Authenticated, DirectRemoteIp, Header, UrlPath, Metadata, NotId, SourceIp, and RemoteIp. Any other variant triggers this error, failing the engine build.","triggerScenarios":"A control plane sends an RBAC policy whose principals include an identifier type not implemented by this version of grpc-go. For example, a newer Envoy proto adds a Principal identifier (like a JWT-claim-based principal or a TLS session ID principal) that the switch does not handle. The error propagates from newPolicyMatcher -> newEngine -> NewChainEngine, causing the xDS resource to be NACKed.","commonSituations":"Version skew: control plane runs a newer go-control-plane with additional Principal variants. A new Envoy RBAC principal extension deployed before grpc-go support. Custom proto extensions with non-standard principal identifiers.","solutions":["Upgrade grpc-go to a version whose matchersFromPrincipals enumerates the principal type the control plane sends.","Remove the unsupported principal identifier from the policy and use only supported types (and_ids, or_ids, any, authenticated, direct_remote_ip, header, url_path, metadata, not_id, source_ip, remote_ip).","Replace an unsupported identity check with an equivalent supported one — e.g., use authenticated with a principal_name string matcher instead of a custom claim-based principal."],"exampleFix":"// before: control plane uses an unsupported principal type\nprincipals:\n  - someNewIdentifier: {claim: \"sub\", value: \"admin\"}\n\n// after: use authenticated with principal_name matcher\nprincipals:\n  - authenticated:\n      principal_name:\n        exact: \"spiffe://example.org/admin\"","handlingStrategy":"validation","validationCode":"// Validate all principal types are supported before building the engine:\nfunc validatePrincipals(principals []*v3rbacpb.Principal) error {\n    for _, p := range principals {\n        switch p.GetIdentifier().(type) {\n        case *v3rbacpb.Principal_AndIds:\n            if err := validatePrincipals(p.GetAndIds().GetIds()); err != nil { return err }\n        case *v3rbacpb.Principal_OrIds:\n            if err := validatePrincipals(p.GetOrIds().GetIds()); err != nil { return err }\n        case *v3rbacpb.Principal_Any, *v3rbacpb.Principal_Authenticated_,\n             *v3rbacpb.Principal_DirectRemoteIp, *v3rbacpb.Principal_Header,\n             *v3rbacpb.Principal_UrlPath, *v3rbacpb.Principal_Metadata,\n             *v3rbacpb.Principal_NotId, *v3rbacpb.Principal_SourceIp,\n             *v3rbacpb.Principal_RemoteIp:\n            // supported\n        default:\n            return fmt.Errorf(\"unsupported principal type %T\", p.GetIdentifier())\n        }\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Keep grpc-go and go-control-plane versions aligned.","Audit RBAC policies for unsupported principal types before deploying to the data plane.","Use authenticated principal_name matchers instead of custom claim-based principals for identity checks."],"tags":["xds","rbac","grpc","principal","unsupported","version-skew"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}