grpc/grpc-go · error
"allow_rules" is not present
Error message
"allow_rules" is not present
What it means
Returned by translatePolicy (rbac_translator.go:373) when the policy has a name but len(AllowRules) == 0. allow_rules is mandatory because the SDK policy is an allow-list (default-deny); with no allow rules, no request could ever be authorized, which is treated as a misconfiguration rather than a valid deny-all policy.
Solutions
- Add at least one allow rule (e.g. an allow-all baseline {"name":"allow_all","request":{"paths":["/"]}}) and rely on deny_rules to restrict.
- Re-read the policy model: allow_rules is required; deny_rules is optional.
Example fix
// before
{ "name": "p", "deny_rules": [ {"name":"block","request":{"paths":["/admin"]}} ] }
// after
{
"name": "p",
"allow_rules": [ {"name":"base","request":{"paths":["/"]}} ],
"deny_rules": [ {"name":"block","request":{"paths":["/admin"]}} ]
} Defensive patterns
Strategy: validation
Validate before calling
if len(allowRules) == 0 {
return errors.New("at least one allow_rule is required")
} Try / catch
interceptor, err := authz.NewStatic(policyJSON)
if err != nil {
if err.Error() == `"allow_rules" is not present` {
// add at least one allow rule and reload
}
} Prevention
- Remember the SDK policy is allow-list based; allow_rules is mandatory.
- Add an allow-all baseline rule and use deny_rules to restrict.
When it happens
Trigger: Policy JSON with a name and possibly deny_rules, but no allow_rules array (or an empty one).
Common situations: Authoring a deny-first policy and forgetting the allow list; truncation during templating; intending deny-all but the SDK requires an explicit allow rule.
Related errors
AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11).
Data as JSON: /api/errors/6b709c8da98a8c2b.
Report an issue: GitHub.
Appendix: source
Thrown at authz/rbac_translator.go:373
}
}
// translatePolicy translates SDK authorization policy in JSON format to two
// Envoy RBAC polices (deny followed by allow policy) or only one Envoy RBAC
// allow policy. Also returns the overall policy name. If the input policy
// cannot be parsed or is invalid, an error will be returned.
func translatePolicy(policyStr string) ([]*v3rbacpb.RBAC, string, error) {
policy := &authorizationPolicy{}
d := json.NewDecoder(bytes.NewReader([]byte(policyStr)))
d.DisallowUnknownFields()
if err := d.Decode(policy); err != nil {
return nil, "", fmt.Errorf("failed to unmarshal policy: %v", err)
}
if policy.Name == "" {
return nil, "", fmt.Errorf(`"name" is not present`)
}
if len(policy.AllowRules) == 0 {
return nil, "", fmt.Errorf(`"allow_rules" is not present`)
}
allowLogger, denyLogger, err := policy.AuditLoggingOptions.toProtos()
if err != nil {
return nil, "", err
}
rbacs := make([]*v3rbacpb.RBAC, 0, 2)
if len(policy.DenyRules) > 0 {
denyPolicies, err := parseRules(policy.DenyRules, policy.Name)
if err != nil {
return nil, "", fmt.Errorf(`"deny_rules" %v`, err)
}
denyRBAC := &v3rbacpb.RBAC{
Action: v3rbacpb.RBAC_DENY,
Policies: denyPolicies,
AuditLoggingOptions: denyLogger,
}
rbacs = append(rbacs, denyRBAC)
}View on GitHub (pinned to 0c51461d27)