{"record":{"id":"e8945ceb93e148aa","repo":"grpc/grpc-go","slug":"authority-q-not-found-in-the-config-for-resource","errorCode":null,"errorMessage":"authority %q not found in the config for resource %q","messagePattern":"authority %q not found in the config for resource %q","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/xds/clients/xdsclient/clientimpl_watchers.go","lineNumber":79,"sourceCode":"\t\tResourceWatcher: watcher,\n\t\tnodeID:          c.config.Node.ID,\n\t}\n\n\trType, ok := c.config.ResourceTypes[typeURL]\n\tif !ok {\n\t\tlogger.Warningf(\"ResourceType implementation for resource type url %q is not found\", rType.TypeURL)\n\t\tc.serializer.TrySchedule(func(context.Context) {\n\t\t\twatcher.ResourceError(fmt.Errorf(\"no ResourceType implementation found for typeURL %q\", rType.TypeURL), func() {})\n\t\t})\n\t\treturn func() {}\n\t}\n\n\tn := xdsresource.ParseName(resourceName)\n\ta := c.getAuthorityForResource(n)\n\tif a == nil {\n\t\tlogger.Warningf(\"Watch registered for name %q of type %q, authority %q is not found\", rType.TypeName, resourceName, n.Authority)\n\t\tc.serializer.TrySchedule(func(context.Context) {\n\t\t\twatcher.ResourceError(fmt.Errorf(\"authority %q not found in the config for resource %q\", n.Authority, resourceName), func() {})\n\t\t})\n\t\treturn func() {}\n\t}\n\t// The watchResource method on the authority is invoked with n.String()\n\t// instead of resourceName because n.String() canonicalizes the given name.\n\t// So, two resource names which don't differ in the query string, but only\n\t// differ in the order of context params will result in the same resource\n\t// being watched by the authority.\n\treturn a.watchResource(rType, n.String(), watcher)\n}\n\n// Gets the authority for the given resource name.\n//\n// See examples in this section of the gRFC:\n// https://github.com/grpc/proposal/blob/master/A47-xds-federation.md#bootstrap-config-changes\nfunc (c *XDSClient) getAuthorityForResource(name *xdsresource.Name) *authority {\n\t// For new-style resource names, always lookup the authorities map. If the\n\t// name does not specify an authority, we will end up looking for an entry","sourceCodeStart":61,"sourceCodeEnd":97,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/xds/clients/xdsclient/clientimpl_watchers.go#L61-L97","documentation":"Reported via the watcher when the parsed resource name carries an authority that is not present in Config.Authorities and is not the top-level authority (clientimpl_watchers.go:79). The client cannot route the watch to any authority, so it reports the error and returns a no-op cancel.","triggerScenarios":"WatchResource is called with a resource name like \"xdstp://my-authority/cosmetic\" but Config.Authorities has no entry for \"my-authority\" (and the name's scheme is the federation scheme, so the top-level authority is not used). Also triggered for old-style names whose authority is non-empty and absent from Authorities.","commonSituations":"Federated xDS (gRFC A47) is used but the authorities map in the bootstrap is incomplete; a typo in the authority token; resource name was constructed for a different environment; the top-level authority was expected but the name explicitly carries an authority that doesn't match.","solutions":["Add the authority to Config.Authorities (with its server config and credentials) before constructing the XDSClient.","Verify the resource name spelling - use xdsresource.ParseName to inspect scheme/authority/path.","If the resource should use the top-level authority, drop the authority from the name (for old-style) or set scheme to non-federation form.","Cross-check the bootstrap authorities section against the names being watched."],"exampleFix":"// before\ncfg := &xdsclient.Config{Authorities: map[string]*xdsclient.Authority{}}\nc, _ := xdsclient.New(cfg)\nc.WatchResource(typeURL, \"xdstp://prod-authority/listener/foo\", w) // error\n\n// after\ncfg := &xdsclient.Config{Authorities: map[string]*xdsclient.Authority{\n    \"prod-authority\": {Server: serverCfgForProd},\n}}\nc, _ := xdsclient.New(cfg)\nc.WatchResource(typeURL, \"xdstp://prod-authority/listener/foo\", w)","handlingStrategy":"validation","validationCode":"func validateAuthority(cfg *xdsclient.Config, resourceName string) error {\n    n := xdsresource.ParseName(resourceName)\n    if n.Scheme == xdsresource.FederationScheme {\n        if _, ok := cfg.Authorities[n.Authority]; !ok {\n            return fmt.Errorf(\"authority %q not configured\", n.Authority)\n        }\n    } else if n.Authority != \"\" {\n        if _, ok := cfg.Authorities[n.Authority]; !ok {\n            return fmt.Errorf(\"authority %q not configured\", n.Authority)\n        }\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":"// WatchResource returns a no-op cancel on this error; the watcher's ResourceError receives it.\n// Parse the resource name first to fail fast:\nif n := xdsresource.ParseName(resourceName); n.Authority != \"\" && !authorityConfigured(cfg, n.Authority) {\n    // add the authority or rewrite the name","preventionTips":["Keep the Config.Authorities map in sync with every authority token used in resource names.","Use xdsresource.ParseName to inspect names before watching.","Add an integration test that watches one resource per configured authority."],"tags":["xds","watcher","federation","authority","configuration"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}