grpc/grpc-go · error
extauthz: failed to parse grpc_service
Error message
extauthz: failed to parse grpc_service: %v
What it means
The grpc_service field in the ExtAuthz config could not be parsed into a GRPCServiceConfig (ext_authz.go:105-107). Critically, in the current codebase the parseGRPCServiceConfig function is a placeholder that always returns 'parseGRPCServiceConfig not implemented' (ext_authz.go:48-50) — this means gRFC A102 support for client-side ext_authz is incomplete, and any non-empty grpc_service will trigger this error.
Solutions
- Do not enable GRPC_EXPERIMENTAL_XDS_EXT_AUTHZ_ON_CLIENT until gRFC A102 is fully implemented and parseGRPCServiceConfig is replaced with a real implementation
- Upgrade to a gRPC version where ext_authz grpc_service parsing is fully supported
- If you must test, override the parseGRPCServiceConfig variable (internal/test only) with a real parser
- Track the gRFC A102 implementation status in the grpc-go repository
Defensive patterns
Strategy: validation
Validate before calling
// Check implementation status before enabling the feature.
// parseGRPCServiceConfig is currently a stub that always returns 'not implemented'.
if envconfig.XDSClientExtAuthzEnabled {
log.Println("WARNING: client-side ext_authz grpc_service parsing is not fully implemented (gRFC A102 pending)")
} Try / catch
_, err := builder.ParseFilterConfig(anyCfg)
if err != nil && strings.Contains(err.Error(), "parseGRPCServiceConfig not implemented") {
log.Printf("ext_authz grpc_service parsing not yet supported in this gRPC version: %v", err)
} Prevention
- Do not enable GRPC_EXPERIMENTAL_XDS_EXT_AUTHZ_ON_CLIENT until gRFC A102 is fully implemented
- Track gRFC A102 implementation status before relying on client-side ext_authz
- Upgrade gRPC versions regularly to pick up ext_authz implementation progress
- Test the feature in a staging environment before production
When it happens
Trigger: parseGRPCServiceConfig(msg.GetGrpcService()) is called with a non-nil grpc_service. Since the current implementation always returns an error ('parseGRPCServiceConfig not implemented'), this error fires for every valid ExtAuthz config that includes a grpc_service.
Common situations: Using the experimental client-side ext_authz filter (GRPC_EXPERIMENTAL_XDS_EXT_AUTHZ_ON_CLIENT=true) with an xDS server that sends an ExtAuthz config containing grpc_service — the feature is not yet fully implemented (gRFC A102 pending).
Understand the failure class
- Parsing and encoding errors: unexpected token, malformed input — why parsers reject input and how to find the real culprit.
Related errors
- extauthz: empty grpc_service provided in config
- extauthz: error parsing config
- extauthz: error parsing override config
- extauthz: failed to unmarshal config
- extauthz: failed to unmarshal override config
AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11).
Data as JSON: /api/errors/23fefd2d090672fa.
Report an issue: GitHub.
Appendix: source
Thrown at internal/xds/httpfilter/ext_authz/ext_authz.go:107
return codes.Unknown
}
func (builder) ParseFilterConfig(cfg proto.Message) (httpfilter.FilterConfig, error) {
m, ok := cfg.(*anypb.Any)
if !ok {
return nil, fmt.Errorf("extauthz: error parsing config %v: unknown type %T, want *anypb.Any", cfg, cfg)
}
msg := new(v3extauthzpb.ExtAuthz)
if err := m.UnmarshalTo(msg); err != nil {
return nil, fmt.Errorf("extauthz: failed to unmarshal config: %v", err)
}
if msg.GetGrpcService() == nil {
return nil, fmt.Errorf("extauthz: empty grpc_service provided in config %v", cfg)
}
server, err := parseGRPCServiceConfig(msg.GetGrpcService())
if err != nil {
return nil, fmt.Errorf("extauthz: failed to parse grpc_service: %v", err)
}
filterEnabled, err := parseFilterEnabled(msg.GetFilterEnabled())
if err != nil {
return nil, err
}
var denyAtDisable bool
if denyAtDisableFlag := msg.GetDenyAtDisable(); denyAtDisableFlag != nil {
if denyAtDisableFlag.GetDefaultValue() == nil {
return nil, fmt.Errorf("extauthz: missing default_value in deny_at_disable")
}
denyAtDisable = denyAtDisableFlag.GetDefaultValue().GetValue()
}
httpStatus := int32(http.StatusForbidden)
if st := msg.GetStatusOnError().GetCode(); st != 0 {
httpStatus = int32(st)View on GitHub (pinned to 0c51461d27)