grpc/grpc-go · error

extproc: failed to parse grpc_service

Error message

extproc: failed to parse grpc_service %v

What it means

Returned by ParseFilterConfig when iextproc.ParseGRPCServiceConfig fails to turn the grpc_service proto into a usable xdsresource.GRPCServiceConfig. The inner error (wrapped as %v) typically indicates a missing/unsupported credential type, missing target, or an unrecognized grpc_service variant. Hit at ext_proc.go:130.

Solutions

  1. Read the wrapped %v error to identify the specific parse failure (credentials vs target vs plugin).
  2. Ensure grpc_service uses a target URI and credential combination grpc-go's ext_proc supports (typically mTLS/insecure from the bootstrap).
  3. If using envoy_grpc, confirm the cluster exists in the bootstrap cluster map.
  4. Simplify the grpc_service to a known-working config (insecure + target) and re-add complexity incrementally.

Example fix

# before
grpc_service:
  google_grpc:
    target_uri: ""
    ssl_credentials: { google_default: {} }
# after
grpc_service:
  envoy_grpc:
    cluster_name: ext-proc-cluster  # defined in bootstrap with mTLS
Defensive patterns

Strategy: validation

Validate before calling

// pre-check the grpc_service is one grpc-go can parse
if cfg.GetGrpcService() == nil { return fmt.Errorf("nil grpc_service") }
if cfg.GetGrpcService().GetEnvoyGrpc().GetClusterName() == "" &&
   cfg.GetGrpcService().GetGoogleGrpc().GetTargetUri() == "" {
  return fmt.Errorf("grpc_service missing target")
}

Prevention

When it happens

Trigger: An ExternalProcessor.grpc_service is present but malformed: uses a credential type grpc-go does not support (e.g. some google_grpc channel args), has an empty target URI, or specifies an envoy_grpc cluster that cannot be resolved by the bootstrap.

Common situations: Control plane emits google_grpc with call_credentials grpc-go does not implement; target_uri is blank; a custom security plugin is configured but not registered; bootstrap lacks the cluster referenced by envoy_grpc.

Understand the failure class

Related errors


AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11). Data as JSON: /api/errors/3800e7eb0554835b. Report an issue: GitHub.

Appendix: source

Thrown at internal/xds/httpfilter/extproc/ext_proc.go:130

		return nil, fmt.Errorf("extproc: error parsing config %v: unknown type %T, want *anypb.Any", cfg, cfg)
	}
	msg := new(v3procfilterpb.ExternalProcessor)
	if err := m.UnmarshalTo(msg); err != nil {
		return nil, fmt.Errorf("extproc: failed to unmarshal config %v: %v", cfg, err)
	}
	if msg.GetProcessingMode() == nil {
		return nil, fmt.Errorf("extproc: missing processing_mode in config %v", cfg)
	}
	if err := validateBodyProcessingMode(msg.GetProcessingMode()); err != nil {
		return nil, err
	}

	if msg.GetGrpcService() == nil {
		return nil, fmt.Errorf("extproc: empty grpc_service provided in config %v", cfg)
	}
	server, err := iextproc.ParseGRPCServiceConfig(msg.GetGrpcService())
	if err != nil {
		return nil, fmt.Errorf("extproc: failed to parse grpc_service %v", err)
	}

	mutationRules, err := httpfilter.HeaderMutationRulesFromProto(msg.GetMutationRules())
	if err != nil {
		return nil, err
	}

	var allowedHeaders, disallowedHeaders []matcher.StringMatcher
	if allowed := msg.GetForwardRules().GetAllowedHeaders(); allowed != nil {
		allowedHeaders, err = httpfilter.ConvertStringMatchers(allowed.GetPatterns())
		if err != nil {
			return nil, err
		}
	}

	if disallowed := msg.GetForwardRules().GetDisallowedHeaders(); disallowed != nil {
		disallowedHeaders, err = httpfilter.ConvertStringMatchers(disallowed.GetPatterns())
		if err != nil {

View on GitHub (pinned to 0c51461d27)