grpc/grpc-go · error

"allow_rules" is not present

Error message

"allow_rules" is not present

What it means

Returned by translatePolicy (rbac_translator.go:373) when the policy has a name but len(AllowRules) == 0. allow_rules is mandatory because the SDK policy is an allow-list (default-deny); with no allow rules, no request could ever be authorized, which is treated as a misconfiguration rather than a valid deny-all policy.

Solutions

  1. Add at least one allow rule (e.g. an allow-all baseline {"name":"allow_all","request":{"paths":["/"]}}) and rely on deny_rules to restrict.
  2. Re-read the policy model: allow_rules is required; deny_rules is optional.

Example fix

// before
{ "name": "p", "deny_rules": [ {"name":"block","request":{"paths":["/admin"]}} ] }

// after
{
  "name": "p",
  "allow_rules": [ {"name":"base","request":{"paths":["/"]}} ],
  "deny_rules": [ {"name":"block","request":{"paths":["/admin"]}} ]
}
Defensive patterns

Strategy: validation

Validate before calling

if len(allowRules) == 0 {
    return errors.New("at least one allow_rule is required")
}

Try / catch

interceptor, err := authz.NewStatic(policyJSON)
if err != nil {
    if err.Error() == `"allow_rules" is not present` {
        // add at least one allow rule and reload
    }
}

Prevention

When it happens

Trigger: Policy JSON with a name and possibly deny_rules, but no allow_rules array (or an empty one).

Common situations: Authoring a deny-first policy and forgetting the allow list; truncation during templating; intending deny-all but the SDK requires an explicit allow rule.

Related errors


AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11). Data as JSON: /api/errors/6b709c8da98a8c2b. Report an issue: GitHub.

Appendix: source

Thrown at authz/rbac_translator.go:373

	}
}

// translatePolicy translates SDK authorization policy in JSON format to two
// Envoy RBAC polices (deny followed by allow policy) or only one Envoy RBAC
// allow policy. Also returns the overall policy name. If the input policy
// cannot be parsed or is invalid, an error will be returned.
func translatePolicy(policyStr string) ([]*v3rbacpb.RBAC, string, error) {
	policy := &authorizationPolicy{}
	d := json.NewDecoder(bytes.NewReader([]byte(policyStr)))
	d.DisallowUnknownFields()
	if err := d.Decode(policy); err != nil {
		return nil, "", fmt.Errorf("failed to unmarshal policy: %v", err)
	}
	if policy.Name == "" {
		return nil, "", fmt.Errorf(`"name" is not present`)
	}
	if len(policy.AllowRules) == 0 {
		return nil, "", fmt.Errorf(`"allow_rules" is not present`)
	}
	allowLogger, denyLogger, err := policy.AuditLoggingOptions.toProtos()
	if err != nil {
		return nil, "", err
	}
	rbacs := make([]*v3rbacpb.RBAC, 0, 2)
	if len(policy.DenyRules) > 0 {
		denyPolicies, err := parseRules(policy.DenyRules, policy.Name)
		if err != nil {
			return nil, "", fmt.Errorf(`"deny_rules" %v`, err)
		}
		denyRBAC := &v3rbacpb.RBAC{
			Action:              v3rbacpb.RBAC_DENY,
			Policies:            denyPolicies,
			AuditLoggingOptions: denyLogger,
		}
		rbacs = append(rbacs, denyRBAC)
	}

View on GitHub (pinned to 0c51461d27)