grpc/grpc-go · error
extauthz: error parsing config
Error message
extauthz: error parsing config %v: unknown type %T, want *anypb.Any
What it means
ParseFilterConfig expected the configuration wrapped as *anypb.Any but received a different concrete proto type (ext_authz.go:93-95). xDS HTTP filter configs are always transported as Any-wrapped messages, so receiving a bare proto indicates an integration-layer error.
Solutions
- Ensure the httpfilter framework passes *anypb.Any to ParseFilterConfig
- Wrap the config proto with anypb.New() before calling the parser in test code
- Do not manually unwrap Any before dispatching to filter parsers
Example fix
// before — bare proto passed
cfg := &v3extauthzpb.ExtAuthz{GrpcService: gs}
fc, err := builder{}.ParseFilterConfig(cfg)
// after — wrap in Any first
anyCfg, _ := anypb.New(cfg)
fc, err := builder{}.ParseFilterConfig(anyCfg) Defensive patterns
Strategy: type-guard
Type guard
// Ensure the config is *anypb.Any before passing to the parser.
func isAnyProto(msg proto.Message) bool {
_, ok := msg.(*anypb.Any)
return ok
} Prevention
- Always pass *anypb.Any to httpfilter parsers — the framework handles unwrapping
- Use anypb.New() to wrap protos in test code before calling parser methods
- Do not manually unwrap Any messages before dispatching to filter parsers
When it happens
Trigger: The httpfilter framework calls ParseFilterConfig with a proto.Message whose concrete type is not *anypb.Any (e.g. an already-unwrapped ExtAuthz proto passed by custom integration or test code).
Common situations: Custom httpfilter integration that unwraps Any before dispatching to the filter parser; incorrect framework wiring; test code passing a bare ExtAuthz proto instead of wrapping it in anypb.New().
Related errors
- extauthz: error parsing override config
- extauthz: empty grpc_service provided in config
- extauthz: failed to parse grpc_service
- extauthz: failed to unmarshal config
- extauthz: failed to unmarshal override config
AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11).
Data as JSON: /api/errors/f9add31e63a98989.
Report an issue: GitHub.
Appendix: source
Thrown at internal/xds/httpfilter/ext_authz/ext_authz.go:95
}
// If the numerator exceeds the denominator, cap the fractional value at 100%.
num := min(fracPercent.GetNumerator(), den)
return fraction{numerator: num, denominator: den}, nil
}
// grpcStatusCode converts an HTTP status code to a gRPC status code.
func grpcStatusCode(httpStatus int32) codes.Code {
if code, ok := transport.HTTPStatusConvTab[int(httpStatus)]; ok {
return code
}
return codes.Unknown
}
func (builder) ParseFilterConfig(cfg proto.Message) (httpfilter.FilterConfig, error) {
m, ok := cfg.(*anypb.Any)
if !ok {
return nil, fmt.Errorf("extauthz: error parsing config %v: unknown type %T, want *anypb.Any", cfg, cfg)
}
msg := new(v3extauthzpb.ExtAuthz)
if err := m.UnmarshalTo(msg); err != nil {
return nil, fmt.Errorf("extauthz: failed to unmarshal config: %v", err)
}
if msg.GetGrpcService() == nil {
return nil, fmt.Errorf("extauthz: empty grpc_service provided in config %v", cfg)
}
server, err := parseGRPCServiceConfig(msg.GetGrpcService())
if err != nil {
return nil, fmt.Errorf("extauthz: failed to parse grpc_service: %v", err)
}
filterEnabled, err := parseFilterEnabled(msg.GetFilterEnabled())
if err != nil {
return nil, err
}View on GitHub (pinned to 0c51461d27)