grpc/grpc-go · error
extauthz: failed to unmarshal override config
Error message
extauthz: failed to unmarshal override config %v: %v
What it means
The Any-wrapped override configuration could not be unmarshaled into an envoy.extensions.filters.http.ext_authz.v3.ExtAuthzPerRoute proto (ext_authz.go:175-176). The serialized payload does not match the ExtAuthzPerRoute schema or the TypeURL is incorrect.
Solutions
- Verify the TypeURL matches 'type.googleapis.com/envoy.extensions.filters.http.ext_authz.v3.ExtAuthzPerRoute'
- Ensure the xDS server and client use compatible go-control-plane / Envoy proto versions
- Use xDS config dump to inspect the raw override payload for corruption
- Check for go-control-plane version mismatches
Defensive patterns
Strategy: validation
Validate before calling
// Validate the override TypeURL before unmarshaling.
const extAuthzPerRouteTypeURL = "type.googleapis.com/envoy.extensions.filters.http.ext_authz.v3.ExtAuthzPerRoute"
if anyMsg.TypeUrl != extAuthzPerRouteTypeURL {
return fmt.Errorf("unexpected override TypeURL %q, want %q", anyMsg.TypeUrl, extAuthzPerRouteTypeURL)
} Try / catch
_, err := builder.ParseFilterConfigOverride(anyCfg)
if err != nil && strings.Contains(err.Error(), "failed to unmarshal override config") {
log.Printf("ExtAuthzPerRoute override unmarshal failed: %v — check TypeURL and proto version", err)
} Prevention
- Keep go-control-plane versions aligned between xDS server and client
- Validate override TypeURLs before dispatching to filter parsers
- Use xDS config dump to inspect raw override payloads for corruption
When it happens
Trigger: anypb.Any.UnmarshalTo(msg) fails where msg is *v3extauthzpb.ExtAuthzPerRoute, because the Any payload is corrupted, truncated, or the TypeURL does not match 'type.googleapis.com/envoy.extensions.filters.http.ext_authz.v3.ExtAuthzPerRoute'.
Common situations: xDS server proto version mismatch (different Envoy ext_authz per-route proto revision); wrong TypeURL in the Any; payload corruption; server sends a different override type under the ExtAuthzPerRoute URL.
Related errors
- extauthz: failed to unmarshal config
- extauthz: error parsing override config
- extauthz: empty grpc_service provided in config
- extauthz: error parsing config
- extauthz: failed to parse grpc_service
AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11).
Data as JSON: /api/errors/eec14aaff8ef0fe0.
Report an issue: GitHub.
Appendix: source
Thrown at internal/xds/httpfilter/ext_authz/ext_authz.go:176
decoderHeaderMutationRules: mutationRules,
includePeerCertificate: msg.GetIncludePeerCertificate(),
}, nil
}
// ParseFilterConfigOverride parses the provided override configuration.
//
// Note that ExtAuthzPerRoute is unmarshaled to verify its syntax during xDS
// resource validation, no filter configuration object is returned. Per-route
// disabling is supported via the generic FilterConfig wrapper mechanism rather
// than the ExtAuthzPerRoute.disabled field directly.
func (builder) ParseFilterConfigOverride(overrideCfg proto.Message) (httpfilter.FilterConfig, error) {
m, ok := overrideCfg.(*anypb.Any)
if !ok {
return nil, fmt.Errorf("extauthz: error parsing override config %v: unknown type %T, want *anypb.Any", overrideCfg, overrideCfg)
}
msg := new(v3extauthzpb.ExtAuthzPerRoute)
if err := m.UnmarshalTo(msg); err != nil {
return nil, fmt.Errorf("extauthz: failed to unmarshal override config %v: %v", overrideCfg, err)
}
return nil, nil
}
func (builder) IsTerminal() bool {
return false
}
View on GitHub (pinned to 0c51461d27)