{"record":{"id":"887d7bd8fb64890b","repo":"grpc/grpc-go","slug":"rls-csp-validation-error-from-rls-lb-policy-parsi","errorCode":null,"errorMessage":"rls_csp: validation error from rls lb policy parsing: %v","messagePattern":"rls_csp: validation error from rls lb policy parsing: (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/xds/clusterspecifier/rls/rls.go","lineNumber":91,"sourceCode":"\t\tChildPolicy: []map[string]json.RawMessage{\n\t\t\t{\n\t\t\t\t\"cds_experimental\": json.RawMessage(`{\"isDynamic\":true}`),\n\t\t\t},\n\t\t},\n\t\tChildPolicyConfigTargetFieldName: \"cluster\",\n\t}\n\n\trawJSON, err := json.Marshal(lbCfgJSON)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"rls_csp: error marshaling load balancing config %v: %v\", lbCfgJSON, err)\n\t}\n\n\trlsBB := balancer.Get(internal.RLSLoadBalancingPolicyName)\n\tif rlsBB == nil {\n\t\treturn nil, fmt.Errorf(\"RLS LB policy not registered\")\n\t}\n\tif _, err = rlsBB.(balancer.ConfigParser).ParseConfig(rawJSON); err != nil {\n\t\treturn nil, fmt.Errorf(\"rls_csp: validation error from rls lb policy parsing: %v\", err)\n\t}\n\n\treturn clusterspecifier.BalancerConfig{{internal.RLSLoadBalancingPolicyName: lbCfgJSON}}, nil\n}\n","sourceCodeStart":73,"sourceCodeEnd":96,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/xds/clusterspecifier/rls/rls.go#L73-L96","documentation":"The RLS LB policy's ConfigParser.ParseConfig rejected the constructed LB config JSON (rls.go:90-91). The route lookup config, child policy, or target field name in the JSON does not satisfy the RLS balancer's validation rules.","triggerScenarios":"rlsBB.(balancer.ConfigParser).ParseConfig(rawJSON) returns an error because the constructed JSON (containing routeLookupConfig, childPolicy, and childPolicyConfigTargetFieldName) has fields that fail the RLS LB policy's semantic validation.","commonSituations":"RouteLookupConfig has an invalid cache size (zero or negative), missing grpc_keybuilders, an invalid lookup service target, or an empty target field; xDS server sends a structurally valid but semantically invalid RouteLookupConfig; child policy 'cds_experimental' not registered.","solutions":["Review the wrapped error for the specific RLS LB policy validation failure message","Ensure RouteLookupConfig has valid cache_size_bytes (> 0), grpc_keybuilders, and lookup_service fields","Verify the child policy 'cds_experimental' is registered and configured correctly","Check that childPolicyConfigTargetFieldName matches the expected 'cluster' value"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Pre-validate RouteLookupConfig fields before relying on xDS parsing.\nrlc := rlcs.GetRouteLookupConfig()\nif rlc.GetCacheSizeBytes() == 0 {\n    return fmt.Errorf(\"RouteLookupConfig cache_size_bytes must be > 0\")\n}\nif len(rlc.GetGrpcKeybuilders()) == 0 {\n    return fmt.Errorf(\"RouteLookupConfig must include at least one grpc_keybuilder\")\n}","typeGuard":null,"tryCatchPattern":"_, err := plugin.ParseClusterSpecifierConfig(anyCfg)\nif err != nil && strings.Contains(err.Error(), \"validation error from rls lb policy parsing\") {\n    log.Printf(\"RLS LB config rejected: %v — check RouteLookupConfig fields\", err)\n}","preventionTips":["Validate RouteLookupConfig fields on the xDS server before deployment","Test RLS configs with a local gRPC client before production rollout","Review RLS LB policy documentation for required fields and their valid ranges","Ensure the cds_experimental child policy balancer is also registered"],"tags":["rls","xds","cluster-specifier","balancer","validation"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}