{"record":{"id":"bb7562fb09cdb1d7","repo":"grpc/grpc-go","slug":"grpc-the-credentials-require-transport-level-secu","errorCode":null,"errorMessage":"grpc: the credentials require transport level security (use grpc.WithTransportCredentials() to set)","messagePattern":"grpc: the credentials require transport level security \\(use grpc\\.WithTransportCredentials\\(\\) to set\\)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"clientconn.go","lineNumber":100,"sourceCode":"\tPickFirstBalancerName = pickfirst.Name\n)\n\n// The following errors are returned from Dial and DialContext\nvar (\n\t// errNoTransportSecurity indicates that there is no transport security\n\t// being set for ClientConn. Users should either set one or explicitly\n\t// call WithInsecure DialOption to disable security.\n\terrNoTransportSecurity = errors.New(\"grpc: no transport security set (use grpc.WithTransportCredentials(insecure.NewCredentials()) explicitly or set credentials)\")\n\t// errTransportCredsAndBundle indicates that creds bundle is used together\n\t// with other individual Transport Credentials.\n\terrTransportCredsAndBundle = errors.New(\"grpc: credentials.Bundle may not be used with individual TransportCredentials\")\n\t// errNoTransportCredsInBundle indicated that the configured creds bundle\n\t// returned a transport credentials which was nil.\n\terrNoTransportCredsInBundle = errors.New(\"grpc: credentials.Bundle must return non-nil transport credentials\")\n\t// errTransportCredentialsMissing indicates that users want to transmit\n\t// security information (e.g., OAuth2 token) which requires secure\n\t// connection on an insecure connection.\n\terrTransportCredentialsMissing = errors.New(\"grpc: the credentials require transport level security (use grpc.WithTransportCredentials() to set)\")\n)\n\nvar (\n\tdisconnectionsMetric = expstats.RegisterInt64Count(expstats.MetricDescriptor{\n\t\tName:           \"grpc.subchannel.disconnections\",\n\t\tDescription:    \"EXPERIMENTAL. Number of times the selected subchannel becomes disconnected.\",\n\t\tUnit:           \"{disconnection}\",\n\t\tLabels:         []string{\"grpc.target\"},\n\t\tOptionalLabels: []string{\"grpc.lb.backend_service\", \"grpc.lb.locality\", \"grpc.disconnect_error\"},\n\t\tDefault:        false,\n\t})\n\tconnectionAttemptsSucceededMetric = expstats.RegisterInt64Count(expstats.MetricDescriptor{\n\t\tName:           \"grpc.subchannel.connection_attempts_succeeded\",\n\t\tDescription:    \"EXPERIMENTAL. Number of successful connection attempts.\",\n\t\tUnit:           \"{attempt}\",\n\t\tLabels:         []string{\"grpc.target\"},\n\t\tOptionalLabels: []string{\"grpc.lb.backend_service\", \"grpc.lb.locality\"},\n\t\tDefault:        false,","sourceCodeStart":82,"sourceCodeEnd":118,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/clientconn.go#L82-L118","documentation":"Thrown by convertCustomConfig when json.Marshal fails to serialize the *structpb.Struct (the value of a TypedStruct) into a json.RawMessage. json.Marshal of a structpb.Struct can fail if the Struct contains invalid proto values that the Struct's JSON encoder cannot represent, such as a null value in an unexpected position or deeply nested structures exceeding encoder limits. This is a rare error because structpb.Struct is designed to be JSON-serializable.","triggerScenarios":"A TypedStruct's value field contains a *structpb.Struct with an internal inconsistency that causes encoding/json marshalling to fail — for instance, a ListValue containing a null Value in a context where the encoder rejects it, or a Struct field whose key contains invalid UTF-8. This is uncommon because proto validation usually catches these at construction time.","commonSituations":"A control plane that constructs structpb.Struct values programmatically with invalid nested values. A proto deserialization edge case where a malformed Struct passes proto validation but fails JSON marshalling. Extremely large or deeply nested Struct values hitting encoding limits.","solutions":["Inspect the inner error (%v) from json.Marshal to identify the specific field causing the serialization failure.","Validate the TypedStruct's Struct value before sending: ensure all keys are valid UTF-8 strings and all values are well-formed NullValue, NumberValue, StringValue, BoolValue, Struct, or ListValue.","If the Struct is generated programmatically on the control plane, add a round-trip json.Marshal test before sending the xDS resource."],"exampleFix":"// before: control plane builds a Struct with an invalid value\ns := &structpb.Struct{\n    Fields: map[string]*structpb.Value{\n        \"key\": {Kind: &structpb.Value_NumberValue{NumberValue: math.NaN()}},\n        // NaN is not valid JSON -> marshal error\n    },\n}\n\n// after: use a valid value\ns := &structpb.Struct{\n    Fields: map[string]*structpb.Value{\n        \"key\": structpb.NewStringValue(\"valid\"),\n    },\n}","handlingStrategy":"validation","validationCode":"// Pre-marshal the TypedStruct value to catch JSON encoding issues:\nfunc validateStructJSON(s *structpb.Struct) error {\n    if s == nil {\n        return nil\n    }\n    _, err := json.Marshal(s)\n    return err\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Round-trip test all TypedStruct values: json.Marshal -> json.Unmarshal -> assert equality.","Avoid NaN/Infinity in NumberValue fields (not valid JSON).","Ensure all Struct field keys are valid UTF-8 and values are well-formed proto Values."],"tags":["xds","rbac","grpc","audit","json","serialization"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}