grpc/grpc-go · error

extauthz: failed to parse grpc_service

Error message

extauthz: failed to parse grpc_service: %v

What it means

The grpc_service field in the ExtAuthz config could not be parsed into a GRPCServiceConfig (ext_authz.go:105-107). Critically, in the current codebase the parseGRPCServiceConfig function is a placeholder that always returns 'parseGRPCServiceConfig not implemented' (ext_authz.go:48-50) — this means gRFC A102 support for client-side ext_authz is incomplete, and any non-empty grpc_service will trigger this error.

Solutions

  1. Do not enable GRPC_EXPERIMENTAL_XDS_EXT_AUTHZ_ON_CLIENT until gRFC A102 is fully implemented and parseGRPCServiceConfig is replaced with a real implementation
  2. Upgrade to a gRPC version where ext_authz grpc_service parsing is fully supported
  3. If you must test, override the parseGRPCServiceConfig variable (internal/test only) with a real parser
  4. Track the gRFC A102 implementation status in the grpc-go repository
Defensive patterns

Strategy: validation

Validate before calling

// Check implementation status before enabling the feature.
// parseGRPCServiceConfig is currently a stub that always returns 'not implemented'.
if envconfig.XDSClientExtAuthzEnabled {
    log.Println("WARNING: client-side ext_authz grpc_service parsing is not fully implemented (gRFC A102 pending)")
}

Try / catch

_, err := builder.ParseFilterConfig(anyCfg)
if err != nil && strings.Contains(err.Error(), "parseGRPCServiceConfig not implemented") {
    log.Printf("ext_authz grpc_service parsing not yet supported in this gRPC version: %v", err)
}

Prevention

When it happens

Trigger: parseGRPCServiceConfig(msg.GetGrpcService()) is called with a non-nil grpc_service. Since the current implementation always returns an error ('parseGRPCServiceConfig not implemented'), this error fires for every valid ExtAuthz config that includes a grpc_service.

Common situations: Using the experimental client-side ext_authz filter (GRPC_EXPERIMENTAL_XDS_EXT_AUTHZ_ON_CLIENT=true) with an xDS server that sends an ExtAuthz config containing grpc_service — the feature is not yet fully implemented (gRFC A102 pending).

Understand the failure class

Related errors


AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11). Data as JSON: /api/errors/23fefd2d090672fa. Report an issue: GitHub.

Appendix: source

Thrown at internal/xds/httpfilter/ext_authz/ext_authz.go:107

	return codes.Unknown
}

func (builder) ParseFilterConfig(cfg proto.Message) (httpfilter.FilterConfig, error) {
	m, ok := cfg.(*anypb.Any)
	if !ok {
		return nil, fmt.Errorf("extauthz: error parsing config %v: unknown type %T, want *anypb.Any", cfg, cfg)
	}
	msg := new(v3extauthzpb.ExtAuthz)
	if err := m.UnmarshalTo(msg); err != nil {
		return nil, fmt.Errorf("extauthz: failed to unmarshal config: %v", err)
	}

	if msg.GetGrpcService() == nil {
		return nil, fmt.Errorf("extauthz: empty grpc_service provided in config %v", cfg)
	}
	server, err := parseGRPCServiceConfig(msg.GetGrpcService())
	if err != nil {
		return nil, fmt.Errorf("extauthz: failed to parse grpc_service: %v", err)
	}

	filterEnabled, err := parseFilterEnabled(msg.GetFilterEnabled())
	if err != nil {
		return nil, err
	}

	var denyAtDisable bool
	if denyAtDisableFlag := msg.GetDenyAtDisable(); denyAtDisableFlag != nil {
		if denyAtDisableFlag.GetDefaultValue() == nil {
			return nil, fmt.Errorf("extauthz: missing default_value in deny_at_disable")
		}
		denyAtDisable = denyAtDisableFlag.GetDefaultValue().GetValue()
	}

	httpStatus := int32(http.StatusForbidden)
	if st := msg.GetStatusOnError().GetCode(); st != 0 {
		httpStatus = int32(st)

View on GitHub (pinned to 0c51461d27)