grpc/grpc-go · error

failed to push config to child policy

Error message

failed to push config to child policy: %v

What it means

Returned by updateChildConfig (line 309) when the child priority balancer's UpdateClientConnState rejects the config push. The CDS balancer calls b.childLB.UpdateClientConnState with the newly built endpoints, service config, attributes, and parsed child config (lines 301-308). If the priority balancer (or any balancer in its tree) returns an error, it is wrapped here.

Solutions

  1. Examine the wrapped %v to find the specific child balancer error that caused the rejection.
  2. Check the endpoints and child config for validity (endpoint addresses, locality weights, policy names).
  3. Enable gRPC verbose logging (GRPC_GO_LOG_SEVERITY=info) to trace the config through the balancer tree.
  4. If the error is from cluster_impl (e.g., security config issue), follow the remediation for that specific error.
Defensive patterns

Strategy: try-catch

Try / catch

// UpdateClientConnState error propagates to TRANSIENT_FAILURE.
// Unwrap to find the specific child policy rejection:
err := getChannelError(conn)
if err != nil {
    var childErr error
    if errors.As(err, &childErr) {
        log.Printf("child policy rejected config: %v", childErr)
        // inspect child balancer type in logs
    }
}

Prevention

When it happens

Trigger: After successfully building and parsing the child config, the CDS balancer pushes it to the priority child balancer. The priority balancer may reject it if its own validation fails — e.g., the cluster_impl or outlier-detection child within the priority tree encounters an issue with the endpoints or configuration.

Common situations: The priority balancer's child (cluster_impl, wrrlocality, etc.) fails to process the endpoints or config. An endpoint with invalid attributes or an unsupported configuration option in the child policy tree. A transient issue during balancer state transitions.

Related errors


AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11). Data as JSON: /api/errors/4127e8a35e28817a. Report an issue: GitHub.

Appendix: source

Thrown at internal/xds/balancer/cdsbalancer/cdsbalancer.go:309

		for j := range endpoints[i].Addresses {
			addr := endpoints[i].Addresses[j]
			addr.BalancerAttributes = endpoints[i].Attributes
			// BalancerAttributes are used for the following:
			// * Authority Override.
			// * grpc.lb.backend_service metric label propagation.
			// See https://github.com/grpc/grpc-go/issues/6472
			endpoints[i].Addresses[j] = addr
		}
	}
	if err := b.childLB.UpdateClientConnState(balancer.ClientConnState{
		ResolverState: resolver.State{
			Endpoints:     endpoints,
			ServiceConfig: b.serviceConfig,
			Attributes:    b.attributes,
		},
		BalancerConfig: childCfg,
	}); err != nil {
		return fmt.Errorf("failed to push config to child policy: %v", err)
	}
	return nil
}

// updatePriorityConfig updates the priority configuration for the specified EDS
// or DNS cluster, creating it if it does not already exist.
func (b *cdsBalancer) updatePriorityConfig(clusterName string, clusterConfig *xdsresource.ClusterConfig) *priorityConfig {
	name := hostName(clusterName, *clusterConfig.Cluster)
	pc, ok := b.priorityConfigs[name]
	if !ok {
		pc = &priorityConfig{
			childNameGen: newNameGenerator(b.childNameGeneratorSeqID),
		}
		b.priorityConfigs[name] = pc
		// Increment the seq ID for the next new cluster. This is done to make
		// sure that the child policy names generated for different clusters
		// don't conflict with each other.
		b.childNameGeneratorSeqID++

View on GitHub (pinned to 0c51461d27)