grpc/grpc-go · error
authority not found in the config for resource
Error message
authority %q not found in the config for resource %q
What it means
Reported via the watcher when the parsed resource name carries an authority that is not present in Config.Authorities and is not the top-level authority (clientimpl_watchers.go:79). The client cannot route the watch to any authority, so it reports the error and returns a no-op cancel.
Solutions
- Add the authority to Config.Authorities (with its server config and credentials) before constructing the XDSClient.
- Verify the resource name spelling - use xdsresource.ParseName to inspect scheme/authority/path.
- If the resource should use the top-level authority, drop the authority from the name (for old-style) or set scheme to non-federation form.
- Cross-check the bootstrap authorities section against the names being watched.
Example fix
// before
cfg := &xdsclient.Config{Authorities: map[string]*xdsclient.Authority{}}
c, _ := xdsclient.New(cfg)
c.WatchResource(typeURL, "xdstp://prod-authority/listener/foo", w) // error
// after
cfg := &xdsclient.Config{Authorities: map[string]*xdsclient.Authority{
"prod-authority": {Server: serverCfgForProd},
}}
c, _ := xdsclient.New(cfg)
c.WatchResource(typeURL, "xdstp://prod-authority/listener/foo", w) Defensive patterns
Strategy: validation
Validate before calling
func validateAuthority(cfg *xdsclient.Config, resourceName string) error {
n := xdsresource.ParseName(resourceName)
if n.Scheme == xdsresource.FederationScheme {
if _, ok := cfg.Authorities[n.Authority]; !ok {
return fmt.Errorf("authority %q not configured", n.Authority)
}
} else if n.Authority != "" {
if _, ok := cfg.Authorities[n.Authority]; !ok {
return fmt.Errorf("authority %q not configured", n.Authority)
}
}
return nil
} Try / catch
// WatchResource returns a no-op cancel on this error; the watcher's ResourceError receives it.
// Parse the resource name first to fail fast:
if n := xdsresource.ParseName(resourceName); n.Authority != "" && !authorityConfigured(cfg, n.Authority) {
// add the authority or rewrite the name Prevention
- Keep the Config.Authorities map in sync with every authority token used in resource names.
- Use xdsresource.ParseName to inspect names before watching.
- Add an integration test that watches one resource per configured authority.
When it happens
Trigger: WatchResource is called with a resource name like "xdstp://my-authority/cosmetic" but Config.Authorities has no entry for "my-authority" (and the name's scheme is the federation scheme, so the top-level authority is not used). Also triggered for old-style names whose authority is non-empty and absent from Authorities.
Common situations: Federated xDS (gRFC A47) is used but the authorities map in the bootstrap is incomplete; a typo in the authority token; resource name was constructed for a different environment; the top-level authority was expected but the name explicitly carries an authority that doesn't match.
Related errors
- no ResourceType implementation found for typeURL
- extauthz: empty grpc_service provided in config
- extauthz: missing default_value in deny_at_disable
- extauthz: missing default_value in filter_enabled
- grpctransport: config
AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11).
Data as JSON: /api/errors/e8945ceb93e148aa.
Report an issue: GitHub.
Appendix: source
Thrown at internal/xds/clients/xdsclient/clientimpl_watchers.go:79
ResourceWatcher: watcher,
nodeID: c.config.Node.ID,
}
rType, ok := c.config.ResourceTypes[typeURL]
if !ok {
logger.Warningf("ResourceType implementation for resource type url %q is not found", rType.TypeURL)
c.serializer.TrySchedule(func(context.Context) {
watcher.ResourceError(fmt.Errorf("no ResourceType implementation found for typeURL %q", rType.TypeURL), func() {})
})
return func() {}
}
n := xdsresource.ParseName(resourceName)
a := c.getAuthorityForResource(n)
if a == nil {
logger.Warningf("Watch registered for name %q of type %q, authority %q is not found", rType.TypeName, resourceName, n.Authority)
c.serializer.TrySchedule(func(context.Context) {
watcher.ResourceError(fmt.Errorf("authority %q not found in the config for resource %q", n.Authority, resourceName), func() {})
})
return func() {}
}
// The watchResource method on the authority is invoked with n.String()
// instead of resourceName because n.String() canonicalizes the given name.
// So, two resource names which don't differ in the query string, but only
// differ in the order of context params will result in the same resource
// being watched by the authority.
return a.watchResource(rType, n.String(), watcher)
}
// Gets the authority for the given resource name.
//
// See examples in this section of the gRFC:
// https://github.com/grpc/proposal/blob/master/A47-xds-federation.md#bootstrap-config-changes
func (c *XDSClient) getAuthorityForResource(name *xdsresource.Name) *authority {
// For new-style resource names, always lookup the authorities map. If the
// name does not specify an authority, we will end up looking for an entryView on GitHub (pinned to 0c51461d27)