grpc/grpc-go · error
gcpauthn: cache_config.cache_size must be greater than zero
Error message
gcpauthn: cache_config.cache_size must be greater than zero
What it means
ParseFilterConfig (gcp_authn_filter.go:74) validates that when cache_config.cache_size is explicitly set, it must be greater than zero. A value of zero is rejected because an LRU credentials cache of size zero cannot function.
Solutions
- Set cache_config.cache_size to a positive integer (e.g., 10 or higher).
- If unsure, omit the cache_size field entirely so the default of 10 is used.
- Audit Helm/YAML templates that coerce empty numeric inputs to 0.
Example fix
// before
cacheConfig: { cacheSize: { value: 0 } }
// after
cacheConfig: { cacheSize: { value: 10 } } Defensive patterns
Strategy: validation
Validate before calling
if cs := msg.GetCacheConfig().GetCacheSize(); cs != nil && cs.GetValue() == 0 {
return nil, errors.New("gcpauthn: cache_size must be > 0; fix the config before sending")
} Try / catch
if err != nil && strings.Contains(err.Error(), "cache_size must be greater than zero") {
// bump cache_size in the xDS config to a positive integer
} Prevention
- Omit cache_size to use the default of 10 when unsure.
- Audit templating that defaults numeric fields to zero.
When it happens
Trigger: GcpAuthnFilterConfig.cache_config.cache_size is set to a wrapperspb.UInt64Value with value 0. If the field is left unset, the default of 10 applies and this error is not raised.
Common situations: Operator explicitly sets cache_size: 0 (misunderstanding it as 'unlimited' or 'disabled'); automation templating that defaults numeric fields to zero.
Related errors
- gcpauthn: failed to unmarshal filter config
- gcpauthn: invalid filter config type %T
- cannot have a leading slash
- cannot have exclude and a '*' wildcard
- empty contains is not allowed in StringMatcher
AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11).
Data as JSON: /api/errors/0609eba5d13cbeed.
Report an issue: GitHub.
Appendix: source
Thrown at internal/xds/httpfilter/gcp_authn/gcp_authn_filter.go:75
func (builder) TypeURLs() []string {
return []string{"type.googleapis.com/envoy.extensions.filters.http.gcp_authn.v3.GcpAuthnFilterConfig"}
}
func (builder) ParseFilterConfig(cfg proto.Message) (httpfilter.FilterConfig, error) {
m, ok := cfg.(*anypb.Any)
if !ok {
return nil, fmt.Errorf("gcpauthn: invalid filter config type %T", cfg)
}
msg := &v3gcpauthnpb.GcpAuthnFilterConfig{}
if err := m.UnmarshalTo(msg); err != nil {
return nil, fmt.Errorf("gcpauthn: failed to unmarshal filter config: %v", err)
}
cacheSize := uint64(defaultCacheSize)
if cacheSizeConfig := msg.GetCacheConfig().GetCacheSize(); cacheSizeConfig != nil {
if cacheSize = cacheSizeConfig.GetValue(); cacheSize == 0 {
return nil, fmt.Errorf("gcpauthn: cache_config.cache_size must be greater than zero")
}
}
return config{cacheSize: cacheSize}, nil
}
// ParseFilterConfigOverride parses the provided override configuration.
//
// Note that we don't support overrides for this filter configuration,
// but still validate it as part of the normal resource validation.
func (b builder) ParseFilterConfigOverride(cfg proto.Message) (httpfilter.FilterConfig, error) {
return b.ParseFilterConfig(cfg)
}
func (builder) IsTerminal() bool {
return false
}
View on GitHub (pinned to 0c51461d27)