grpc/grpc-go · error

missing required field: name in…

Error message

missing required field: name in audit_logging_options.audit_loggers[%v]

What it means

Returned by auditLoggingOptions.toProtos (rbac_translator.go:307) when iterating audit_logging_options.audit_loggers[] and an entry has an empty Name. Each audit logger is turned into a TypedExtensionConfig whose name is the logger name (and feeds the typeURL at line 313), so a missing name is rejected at the entry's index.

Solutions

  1. Add the registered audit logger "name" to the entry at the reported index.
  2. Confirm the name matches a logger registered via authz audit logger registration in your binary.

Example fix

// before
"audit_loggers": [ { "config": { }, "is_optional": true } ]

// after
"audit_loggers": [ { "name": "logger1", "config": { }, "is_optional": true } ]
Defensive patterns

Strategy: validation

Validate before calling

for i, l := range auditLoggers {
    if l.Name == "" {
        return fmt.Errorf("audit_loggers[%d]: name required", i)
    }
}

Try / catch

interceptor, err := authz.NewStatic(policyJSON)
if err != nil {
    if strings.Contains(err.Error(), "audit_loggers[") {
        // add the registered logger name to the flagged entry
    }
}

Prevention

When it happens

Trigger: Policy JSON with audit_logging_options.audit_loggers[] containing an entry without "name", e.g. {"config": {...}}.

Common situations: Authoring a custom audit logger block and omitting the registered logger name; refactoring that renamed 'name' to something else.

Related errors


AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11). Data as JSON: /api/errors/bbcffdcba327dcbe. Report an issue: GitHub.

Appendix: source

Thrown at authz/rbac_translator.go:307

// Parse auditLoggingOptions to the associated RBAC protos. The single
// auditLoggingOptions results in two different parsed protos, one for the allow
// policy and one for the deny policy
func (options *auditLoggingOptions) toProtos() (allow *v3rbacpb.RBAC_AuditLoggingOptions, deny *v3rbacpb.RBAC_AuditLoggingOptions, err error) {
	allow = &v3rbacpb.RBAC_AuditLoggingOptions{}
	deny = &v3rbacpb.RBAC_AuditLoggingOptions{}

	if options.AuditCondition != "" {
		rbacCondition, ok := v3rbacpb.RBAC_AuditLoggingOptions_AuditCondition_value[options.AuditCondition]
		if !ok {
			return nil, nil, fmt.Errorf("failed to parse AuditCondition %v. Allowed values {NONE, ON_DENY, ON_ALLOW, ON_DENY_AND_ALLOW}", options.AuditCondition)
		}
		allow.AuditCondition = v3rbacpb.RBAC_AuditLoggingOptions_AuditCondition(rbacCondition)
		deny.AuditCondition = toDenyCondition(v3rbacpb.RBAC_AuditLoggingOptions_AuditCondition(rbacCondition))
	}

	for i, config := range options.AuditLoggers {
		if config.Name == "" {
			return nil, nil, fmt.Errorf("missing required field: name in audit_logging_options.audit_loggers[%v]", i)
		}
		if config.Config == nil {
			config.Config = &structpb.Struct{}
		}
		typedStruct := &v1xdsudpatypepb.TypedStruct{
			TypeUrl: typeURLPrefix + config.Name,
			Value:   config.Config,
		}
		customConfig, err := anypb.New(typedStruct)
		if err != nil {
			return nil, nil, fmt.Errorf("error parsing custom audit logger config: %v", err)
		}

		logger := &v3corepb.TypedExtensionConfig{Name: config.Name, TypedConfig: customConfig}
		rbacConfig := v3rbacpb.RBAC_AuditLoggingOptions_AuditLoggerConfig{
			IsOptional:  config.IsOptional,
			AuditLogger: logger,
		}

View on GitHub (pinned to 0c51461d27)