grpc/grpc-go · error

"allow_rules

Error message

"allow_rules" %v

What it means

Returned by translatePolicy (rbac_translator.go:394) wrapping a failure from parseRules(policy.AllowRules, policy.Name). Since allow_rules is mandatory and already non-empty (checked at line 372), this error indicates one of the allow rule entries is itself invalid (missing name or malformed request). The %v carries the index and the specific sub-error.

Solutions

  1. Read the wrapped %v to locate the offending allow rule (index + sub-cause) and fix it.
  2. Lint each allow rule for: non-empty unique name, valid headers (key + non-empty values + allowed header names), valid paths.
  3. Reload via the file watcher so the prior good policy remains active during the fix.

Example fix

// before
"allow_rules": [ { "request": { "paths": ["/"] } } ]
// error: "allow_rules" 0: "name" is not present

// after
"allow_rules": [ { "name": "allow_all", "request": { "paths": ["/"] } } ]
Defensive patterns

Strategy: validation

Validate before calling

for i, r := range allowRules {
    if r.Name == "" || !validRequest(r.Request) {
        return fmt.Errorf("allow_rules[%d]: invalid", i)
    }
}

Try / catch

interceptor, err := authz.NewStatic(policyJSON)
if err != nil {
    if strings.Contains(err.Error(), `"allow_rules"`) {
        // wrapped %v names the allow-rule index + cause; fix and reload
    }
}

Prevention

When it happens

Trigger: An allow_rules[] entry that lacks "name" or whose request.headers/paths are malformed, even though the allow_rules array itself is non-empty.

Common situations: Authoring allow rules and omitting a required sub-field on one of them; templating that produced a partial rule.

Related errors


AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11). Data as JSON: /api/errors/8b02a2de149f4444. Report an issue: GitHub.

Appendix: source

Thrown at authz/rbac_translator.go:394

	if err != nil {
		return nil, "", err
	}
	rbacs := make([]*v3rbacpb.RBAC, 0, 2)
	if len(policy.DenyRules) > 0 {
		denyPolicies, err := parseRules(policy.DenyRules, policy.Name)
		if err != nil {
			return nil, "", fmt.Errorf(`"deny_rules" %v`, err)
		}
		denyRBAC := &v3rbacpb.RBAC{
			Action:              v3rbacpb.RBAC_DENY,
			Policies:            denyPolicies,
			AuditLoggingOptions: denyLogger,
		}
		rbacs = append(rbacs, denyRBAC)
	}
	allowPolicies, err := parseRules(policy.AllowRules, policy.Name)
	if err != nil {
		return nil, "", fmt.Errorf(`"allow_rules" %v`, err)
	}
	allowRBAC := &v3rbacpb.RBAC{Action: v3rbacpb.RBAC_ALLOW, Policies: allowPolicies, AuditLoggingOptions: allowLogger}
	return append(rbacs, allowRBAC), policy.Name, nil
}

View on GitHub (pinned to 0c51461d27)