grpc/grpc-go · error
extauthz: error parsing override config
Error message
extauthz: error parsing override config %v: unknown type %T, want *anypb.Any
What it means
ParseFilterConfigOverride expected the override configuration wrapped as *anypb.Any but received a different concrete proto type (ext_authz.go:170-172). Per-route filter override configs are transported as Any-wrapped messages in the xDS protocol.
Solutions
- Ensure the httpfilter framework passes *anypb.Any to ParseFilterConfigOverride
- Wrap the override config proto with anypb.New() before calling the parser in test code
- Do not manually unwrap Any before dispatching to filter override parsers
Example fix
// before — bare proto passed
override := &v3extauthzpb.ExtAuthzPerRoute{}
fc, err := builder{}.ParseFilterConfigOverride(override)
// after — wrap in Any first
anyOverride, _ := anypb.New(override)
fc, err := builder{}.ParseFilterConfigOverride(anyOverride) Defensive patterns
Strategy: type-guard
Type guard
// Ensure the override config is *anypb.Any before passing to the parser.
func isAnyProto(msg proto.Message) bool {
_, ok := msg.(*anypb.Any)
return ok
} Prevention
- Always pass *anypb.Any to httpfilter override parsers
- Use anypb.New() to wrap override protos in test code
- Do not manually unwrap Any messages before dispatching to filter override parsers
When it happens
Trigger: The httpfilter framework calls ParseFilterConfigOverride with a proto.Message whose concrete type is not *anypb.Any (e.g. a bare ExtAuthzPerRoute proto passed by custom integration or test code).
Common situations: Custom httpfilter integration that unwraps Any before dispatching to the override parser; incorrect framework wiring; test code passing a bare ExtAuthzPerRoute proto instead of wrapping it.
Related errors
- extauthz: error parsing config
- extauthz: failed to unmarshal override config
- extauthz: empty grpc_service provided in config
- extauthz: failed to parse grpc_service
- extauthz: failed to unmarshal config
AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11).
Data as JSON: /api/errors/d15ef9a637c96778.
Report an issue: GitHub.
Appendix: source
Thrown at internal/xds/httpfilter/ext_authz/ext_authz.go:172
failureModeAllowHeaderAdd: msg.GetFailureModeAllowHeaderAdd(),
statusOnError: statusOnError,
allowedHeaders: allowedHeaders,
disallowedHeaders: disallowedHeaders,
decoderHeaderMutationRules: mutationRules,
includePeerCertificate: msg.GetIncludePeerCertificate(),
}, nil
}
// ParseFilterConfigOverride parses the provided override configuration.
//
// Note that ExtAuthzPerRoute is unmarshaled to verify its syntax during xDS
// resource validation, no filter configuration object is returned. Per-route
// disabling is supported via the generic FilterConfig wrapper mechanism rather
// than the ExtAuthzPerRoute.disabled field directly.
func (builder) ParseFilterConfigOverride(overrideCfg proto.Message) (httpfilter.FilterConfig, error) {
m, ok := overrideCfg.(*anypb.Any)
if !ok {
return nil, fmt.Errorf("extauthz: error parsing override config %v: unknown type %T, want *anypb.Any", overrideCfg, overrideCfg)
}
msg := new(v3extauthzpb.ExtAuthzPerRoute)
if err := m.UnmarshalTo(msg); err != nil {
return nil, fmt.Errorf("extauthz: failed to unmarshal override config %v: %v", overrideCfg, err)
}
return nil, nil
}
func (builder) IsTerminal() bool {
return false
}
View on GitHub (pinned to 0c51461d27)