{"record":{"id":"bf984cf18c56a371","repo":"grpc/grpc-go","slug":"security-configuration-on-the-server-side-does-not","errorCode":null,"errorMessage":"security configuration on the server-side does not contain identity certificate provider instance name","messagePattern":"security configuration on the server-side does not contain identity certificate provider instance name","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/xds/xdsclient/xdsresource/unmarshal_cds.go","lineNumber":414,"sourceCode":"\n\t// For now, if we can't get a valid security config from the new fields, we\n\t// fallback to the old deprecated fields.\n\t// TODO: Drop support for deprecated fields. NACK if err != nil here.\n\tsc, err1 := securityConfigFromCommonTLSContextUsingNewFields(common, server)\n\tif sc == nil || sc.Equal(&SecurityConfig{}) {\n\t\tvar err error\n\t\tsc, err = securityConfigFromCommonTLSContextWithDeprecatedFields(common, server)\n\t\tif err != nil {\n\t\t\t// Retain the validation error from using the new fields.\n\t\t\treturn nil, errors.Join(err1, fmt.Errorf(\"failed to parse config using deprecated fields: %v\", err))\n\t\t}\n\t}\n\tif sc != nil {\n\t\t// sc == nil is a valid case where the control plane has not sent us any\n\t\t// security configuration. xDS creds will use fallback creds.\n\t\tif server {\n\t\t\tif sc.IdentityInstanceName == \"\" {\n\t\t\t\treturn nil, errors.New(\"security configuration on the server-side does not contain identity certificate provider instance name\")\n\t\t\t}\n\t\t} else {\n\t\t\tif !sc.UseSystemRootCerts && sc.RootInstanceName == \"\" {\n\t\t\t\treturn nil, errors.New(\"security configuration on the client-side does not contain root certificate provider instance name\")\n\t\t\t}\n\t\t}\n\t}\n\treturn sc, nil\n}\n\nfunc securityConfigFromCommonTLSContextWithDeprecatedFields(common *v3tlspb.CommonTlsContext, server bool) (*SecurityConfig, error) {\n\t// The `CommonTlsContext` contains a\n\t// `tls_certificate_certificate_provider_instance` field of type\n\t// `CertificateProviderInstance`, which contains the provider instance name\n\t// and the certificate name to fetch identity certs.\n\tsc := &SecurityConfig{}\n\tif identity := common.GetTlsCertificateCertificateProviderInstance(); identity != nil {\n\t\tsc.IdentityInstanceName = identity.GetInstanceName()","sourceCodeStart":396,"sourceCodeEnd":432,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/xds/xdsclient/xdsresource/unmarshal_cds.go#L396-L432","documentation":"Thrown by securityConfigFromCommonTLSContext when a server-side (listener inbound) TLS configuration was received from the control plane, but the resulting SecurityConfig has an empty IdentityInstanceName. The grpc-go xDS client requires an identity certificate provider instance name to fetch the server's own cert chain; without it, mTLS handshakes cannot present a cert. The error is returned while unmarshaling a Cluster (CDS) security config, after both the new (tls_certificate_provider_instance) and deprecated field paths failed to populate it.","triggerScenarios":"A CDS response contains an UpstreamTlsContext/CommonTlsContext for a server (server=true path invoked during inbound listener handling, or a cluster reused server-side) where neither tls_certificate_certificate_provider_instance (deprecated) nor the new tls_context.common_tls_context.tls_certificate_provider_instance has a non-empty instance_name. The control plane sent a partial TLS config.","commonSituations":"Misconfigured Istio/Envoy/xDS control plane that sets a TLS context but omits the certificate provider instance. Migration from deprecated SDS fields to the new envoy.transport_sockets.tls fields where the new field's instance_name was left blank. Bootstrap file (cert_provider_instances in the xds bootstrap) referencing a provider name that does not match what the control plane emits.","solutions":["Inspect the CDS resource from the control plane and confirm the CommonTlsContext includes a tls_certificate_provider_instance or the deprecated tls_certificate_certificate_provider_instance with a non-empty instance_name.","Verify the xDS bootstrap file's certificate_providers section defines the provider instance name that the control plane is referencing.","If using Istio, confirm the DestinationRule/PeerAuthentication actually provisions an SDS identity cert and the workload's SDS socket exposes that name.","Regenerate/redeploy the bootstrap or control-plane config so the identity provider instance name is non-empty for server-side listeners."],"exampleFix":"// before: control plane emits CommonTlsContext with no identity provider\n//   tls_context: { common_tls_context: {} }\n//\n// after: include an identity certificate provider instance name\n//   tls_context: {\n//     common_tls_context: {\n//       tls_certificate_provider_instance: { instance_name: \"default\" }\n//     }\n//   }","handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":"This error originates from xDS resource unmarshaling driven by the control plane; callers cannot pre-validate remote proto bytes. Handle it by inspecting the error returned from xdsclient resource callbacks (NewWatch / WatchCluster) and logging the resource name + version so the operator can correct the control-plane config. Do not retry unchanged; the resource will keep failing until reconfigured.","preventionTips":["In CI, run the control-plane's CDS resources through a policy check that requires tls_certificate_provider_instance.instance_name to be non-empty for any server-side TLS context.","Keep a documented mapping of bootstrap certificate_providers names to control-plane instance_name values.","Unit-test your control-plane emitter against grpc-go's expected schema before deploy."],"tags":["xds","tls","cds","mtls","security-config","control-plane"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}