grpc/grpc-go · error
grpc: the connection is drained
Error message
grpc: the connection is drained
What it means
Thrown by buildLogger in the RBAC audit logger converter when an RBAC_AuditLoggingOptions_AuditLoggerConfig has an AuditLogger whose TypedConfig field is nil. The TypedConfig (*anypb.Any) carries the concrete logger configuration; without it, the converter cannot determine which audit logger to instantiate or how to configure it. This is a hard validation failure — the audit logger config is structurally incomplete.
Solutions
- Ensure every logger_configs entry in the RBAC audit_logging_options has a non-nil audit_logger.typed_config (*anypb.Any).
- If using stdout audit logging, set typed_config to an Any wrapping envoy.extensions.rbac.audit_loggers.stream.v3.StdoutAuditLog.
- Remove the audit_logging_options or the specific logger_configs entry if audit logging is not actually needed for that policy.
Example fix
// before:
auditLoggingOptions:
loggerConfigs:
- auditLogger:
name: "envoy.rbac.audit_loggers.stdout"
// typed_config missing -> error
// after:
auditLoggingOptions:
loggerConfigs:
- auditLogger:
name: "envoy.rbac.audit_loggers.stdout"
typedConfig:
"@type": type.googleapis.com/envoy.extensions.rbac.audit_loggers.stream.v3.StdoutAuditLog
Defensive patterns
Strategy: validation
Validate before calling
// Validate audit logger configs before constructing the engine:
func validateAuditLoggerConfigs(rbac *v3rbacpb.RBAC) error {
for _, opt := range rbac.GetAuditLoggingOptions().GetLoggerConfigs() {
if opt.GetAuditLogger().GetTypedConfig() == nil {
return fmt.Errorf("audit logger config missing TypedConfig")
}
}
return nil
} Prevention
- Always populate typed_config in audit logger configurations.
- Use a control-plane policy validator that checks for non-nil typed_config on all audit logger entries.
- Omit audit_logging_options entirely rather than including partially-specified logger configs.
When it happens
Trigger: An xDS RBAC policy includes audit_logging_options with a logger_configs entry whose audit_logger.typed_config is absent. The control plane specified an audit logger by name but forgot to attach the typed configuration payload.
Common situations: A control plane (e.g., a custom security policy controller) that adds audit logging options but omits the inline typed config. An Istio AuthorizationPolicy with audit logging configured at the API layer but not fully translated to the xDS RBAC proto. Manual proto construction for testing that sets the logger name but not typed_config.
Related errors
- grpc: no transport security set (use…
- grpc: the connection is closing
- error parsing custom audit logger config
- failed to parse AuditCondition
- grpc: credentials.Bundle may not be used with individual…
AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11).
Data as JSON: /api/errors/71941429c67d7b53.
Report an issue: GitHub.
Appendix: source
Thrown at clientconn.go:72
_ "google.golang.org/grpc/internal/resolver/passthrough" // To register passthrough resolver.
_ "google.golang.org/grpc/internal/resolver/unix" // To register unix resolver.
_ "google.golang.org/grpc/resolver/dns" // To register dns resolver.
)
const (
// minimum time to give a connection to complete
minConnectTimeout = 20 * time.Second
)
var (
// ErrClientConnClosing indicates that the operation is illegal because
// the ClientConn is closing.
//
// Deprecated: this error should not be relied upon by users; use the status
// code of Canceled instead.
ErrClientConnClosing = status.Error(codes.Canceled, "grpc: the client connection is closing")
// errConnDrain indicates that the connection starts to be drained and does not accept any new RPCs.
errConnDrain = errors.New("grpc: the connection is drained")
// errConnClosing indicates that the connection is closing.
errConnClosing = errors.New("grpc: the connection is closing")
// errConnIdling indicates the connection is being closed as the channel
// is moving to an idle mode due to inactivity.
errConnIdling = errors.New("grpc: the connection is closing due to channel idleness")
// invalidDefaultServiceConfigErrPrefix is used to prefix the json parsing error for the default
// service config.
invalidDefaultServiceConfigErrPrefix = "grpc: the provided default service config is invalid"
// PickFirstBalancerName is the name of the pick_first balancer.
PickFirstBalancerName = pickfirst.Name
)
// The following errors are returned from Dial and DialContext
var (
// errNoTransportSecurity indicates that there is no transport security
// being set for ClientConn. Users should either set one or explicitly
// call WithInsecure DialOption to disable security.
errNoTransportSecurity = errors.New("grpc: no transport security set (use grpc.WithTransportCredentials(insecure.NewCredentials()) explicitly or set credentials)")View on GitHub (pinned to 0c51461d27)