{"record":{"id":"faa843dd9d8c82c5","repo":"grpc/grpc-go","slug":"failed-to-build-credentials-bundle-from-bootstrap","errorCode":null,"errorMessage":"failed to build credentials bundle from bootstrap for %q: %v","messagePattern":"failed to build credentials bundle from bootstrap for %q: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/xds/bootstrap/bootstrap.go","lineNumber":368,"sourceCode":"\tserver := serverConfigJSON{}\n\tif err := json.Unmarshal(data, &server); err != nil {\n\t\treturn fmt.Errorf(\"xds: failed to JSON unmarshal server configuration during bootstrap: %v, config:\\n%s\", err, string(data))\n\t}\n\n\tsc.serverURI = server.ServerURI\n\tsc.channelCreds = server.ChannelCreds\n\tsc.callCredsConfigs = server.CallCredsConfigs\n\tsc.serverFeatures = server.ServerFeatures\n\n\tfor _, cc := range server.ChannelCreds {\n\t\t// We stop at the first credential type that we support.\n\t\tc := bootstrap.GetChannelCredentials(cc.Type)\n\t\tif c == nil {\n\t\t\tcontinue\n\t\t}\n\t\tbundle, cancel, err := c.Build(cc.Config)\n\t\tif err != nil {\n\t\t\treturn fmt.Errorf(\"failed to build credentials bundle from bootstrap for %q: %v\", cc.Type, err)\n\t\t}\n\t\tsc.selectedChannelCreds = cc\n\t\tsc.credsDialOption = grpc.WithCredentialsBundle(bundle)\n\t\tif d, ok := bundle.(extraDialOptions); ok {\n\t\t\tsc.extraDialOptions = d.DialOptions()\n\t\t}\n\t\tsc.cleanups = append(sc.cleanups, cancel)\n\t\tbreak\n\t}\n\n\tif envconfig.XDSBootstrapCallCredsEnabled {\n\t\t// Process call credentials - unlike channel creds, we use ALL supported\n\t\t// types. Also, call credentials are optional as per gRFC A97.\n\t\tfor _, cfg := range server.CallCredsConfigs {\n\t\t\tc := bootstrap.GetCallCredentials(cfg.Type)\n\t\t\tif c == nil {\n\t\t\t\t// Skip unsupported call credential types (don't fail bootstrap).\n\t\t\t\tcontinue","sourceCodeStart":350,"sourceCodeEnd":386,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/xds/bootstrap/bootstrap.go#L350-L386","documentation":"Returned when the first supported channel credentials type's Build() call fails during bootstrap server config parsing. The credential type name (e.g. 'tlscreds_mtls' or 'google_default') is printed along with the underlying build error.","triggerScenarios":"Triggered at bootstrap.go:368 when c.Build(cc.Config) errors for a registered channel credential plugin. Example: the tlscreds NewBundle fails because certificate_file or ca_certificate_file paths are unreadable.","commonSituations":"TLS/mTLS channel creds reference certificate, key, or CA files that do not exist or have wrong permissions; cert provider plugin returns invalid args; SPIFFE trust bundle map file path invalid.","solutions":["Read the underlying %v: it states which file or config value is invalid.","Verify every file path (certificate_file, private_key_file, ca_certificate_file) exists and is readable by the process.","Check file permissions and, in containers, that the secret/mount is present.","Validate the credential plugin config block against the plugin's documented schema."],"exampleFix":"// before (cert file missing)\n\"channel_creds\":[{\"type\":\"tlscreds_mtls\",\"config\":{\"certificate_file\":\"/etc/certs/client.crt\",\"private_key_file\":\"/etc/certs/client.key\"}}]\n// where /etc/certs/client.key is absent -> error 386\n\n// after: ensure the files exist and are mounted\n$ ls /etc/certs/client.crt /etc/certs/client.key","handlingStrategy":"validation","validationCode":"// Pre-flight check that credential files referenced by channel_creds exist.\nfunc checkCredFiles(cfg map[string]string) error {\n    for field, path := range cfg {\n        if path == \"\" {\n            continue\n        }\n        if _, err := os.Stat(path); err != nil {\n            return fmt.Errorf(\"%s: %w\", field, err)\n        }\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":"if _, err := bootstrap.NewConfigFromContents(data); err != nil {\n    if strings.Contains(err.Error(), \"failed to build credentials bundle\") {\n        // inspect underlying cause, fix cert paths/permissions, then retry bootstrap.\n    }\n}","preventionTips":["Mount TLS secrets via the same mechanism across environments.","Add a startup readiness probe that stat()s the cert files.","Document required file permissions for the runtime UID."],"tags":["grpc","xds","bootstrap","credentials","tls","config","go"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}