grpc/grpc-go · error

extauthz: failed to unmarshal override config

Error message

extauthz: failed to unmarshal override config %v: %v

What it means

The Any-wrapped override configuration could not be unmarshaled into an envoy.extensions.filters.http.ext_authz.v3.ExtAuthzPerRoute proto (ext_authz.go:175-176). The serialized payload does not match the ExtAuthzPerRoute schema or the TypeURL is incorrect.

Solutions

  1. Verify the TypeURL matches 'type.googleapis.com/envoy.extensions.filters.http.ext_authz.v3.ExtAuthzPerRoute'
  2. Ensure the xDS server and client use compatible go-control-plane / Envoy proto versions
  3. Use xDS config dump to inspect the raw override payload for corruption
  4. Check for go-control-plane version mismatches
Defensive patterns

Strategy: validation

Validate before calling

// Validate the override TypeURL before unmarshaling.
const extAuthzPerRouteTypeURL = "type.googleapis.com/envoy.extensions.filters.http.ext_authz.v3.ExtAuthzPerRoute"
if anyMsg.TypeUrl != extAuthzPerRouteTypeURL {
    return fmt.Errorf("unexpected override TypeURL %q, want %q", anyMsg.TypeUrl, extAuthzPerRouteTypeURL)
}

Try / catch

_, err := builder.ParseFilterConfigOverride(anyCfg)
if err != nil && strings.Contains(err.Error(), "failed to unmarshal override config") {
    log.Printf("ExtAuthzPerRoute override unmarshal failed: %v — check TypeURL and proto version", err)
}

Prevention

When it happens

Trigger: anypb.Any.UnmarshalTo(msg) fails where msg is *v3extauthzpb.ExtAuthzPerRoute, because the Any payload is corrupted, truncated, or the TypeURL does not match 'type.googleapis.com/envoy.extensions.filters.http.ext_authz.v3.ExtAuthzPerRoute'.

Common situations: xDS server proto version mismatch (different Envoy ext_authz per-route proto revision); wrong TypeURL in the Any; payload corruption; server sends a different override type under the ExtAuthzPerRoute URL.

Related errors


AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11). Data as JSON: /api/errors/eec14aaff8ef0fe0. Report an issue: GitHub.

Appendix: source

Thrown at internal/xds/httpfilter/ext_authz/ext_authz.go:176

		decoderHeaderMutationRules: mutationRules,
		includePeerCertificate:     msg.GetIncludePeerCertificate(),
	}, nil
}

// ParseFilterConfigOverride parses the provided override configuration.
//
// Note that ExtAuthzPerRoute is unmarshaled to verify its syntax during xDS
// resource validation, no filter configuration object is returned. Per-route
// disabling is supported via the generic FilterConfig wrapper mechanism rather
// than the ExtAuthzPerRoute.disabled field directly.
func (builder) ParseFilterConfigOverride(overrideCfg proto.Message) (httpfilter.FilterConfig, error) {
	m, ok := overrideCfg.(*anypb.Any)
	if !ok {
		return nil, fmt.Errorf("extauthz: error parsing override config %v: unknown type %T, want *anypb.Any", overrideCfg, overrideCfg)
	}
	msg := new(v3extauthzpb.ExtAuthzPerRoute)
	if err := m.UnmarshalTo(msg); err != nil {
		return nil, fmt.Errorf("extauthz: failed to unmarshal override config %v: %v", overrideCfg, err)
	}
	return nil, nil
}

func (builder) IsTerminal() bool {
	return false
}

View on GitHub (pinned to 0c51461d27)