grpc/grpc-go · error

OutlierDetectionLoadBalancingConfig.max_ejection_percent =

Error message

OutlierDetectionLoadBalancingConfig.max_ejection_percent = %v; must be <= 100

What it means

Per gRFC A50, OutlierDetectionLoadBalancingConfig.max_ejection_percent must be <= 100. ParseConfig checks lbCfg.MaxEjectionPercent > 100 and rejects it (balancer.go:142-143). The field caps how many endpoints may be ejected at once; values over 100 make no sense.

Solutions

  1. Set max_ejection_percent to a value in [0, 100] (A50 default is 10).
  2. Validate the percentage range before constructing the config.

Example fix

// before
cfg.MaxEjectionPercent = 150
// after
cfg.MaxEjectionPercent = 10
Defensive patterns

Strategy: validation

Validate before calling

func validateMaxEjectionPercent(p uint32) error {
    if p > 100 { return fmt.Errorf("max_ejection_percent must be <= 100, got %d", p) }
    return nil
}

Prevention

When it happens

Trigger: lbCfg.MaxEjectionPercent > 100 after JSON unmarshaling (e.g. "max_ejection_percent": 150).

Common situations: Manual config with a percentage over 100; typo; control plane misconfiguration bypassing xdsclient validation.

Related errors


AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11). Data as JSON: /api/errors/0651a9a1232535fd. Report an issue: GitHub.

Appendix: source

Thrown at internal/xds/balancer/outlierdetection/balancer.go:143

	// google.protobuf.Duration documentation and they must have non-negative
	// values." - A50
	// Approximately 290 years is the maximum time that time.Duration (int64)
	// can represent. The restrictions on the protobuf.Duration field are to be
	// within +-10000 years. Thus, just check for negative values.
	case lbCfg.Interval < 0:
		return nil, fmt.Errorf("OutlierDetectionLoadBalancingConfig.interval = %s; must be >= 0", lbCfg.Interval)
	case lbCfg.BaseEjectionTime < 0:
		return nil, fmt.Errorf("OutlierDetectionLoadBalancingConfig.base_ejection_time = %s; must be >= 0", lbCfg.BaseEjectionTime)
	case lbCfg.MaxEjectionTime < 0:
		return nil, fmt.Errorf("OutlierDetectionLoadBalancingConfig.max_ejection_time = %s; must be >= 0", lbCfg.MaxEjectionTime)

	// "The fields max_ejection_percent,
	// success_rate_ejection.enforcement_percentage,
	// failure_percentage_ejection.threshold, and
	// failure_percentage.enforcement_percentage must have values less than or
	// equal to 100." - A50
	case lbCfg.MaxEjectionPercent > 100:
		return nil, fmt.Errorf("OutlierDetectionLoadBalancingConfig.max_ejection_percent = %v; must be <= 100", lbCfg.MaxEjectionPercent)
	case lbCfg.SuccessRateEjection != nil && lbCfg.SuccessRateEjection.EnforcementPercentage > 100:
		return nil, fmt.Errorf("OutlierDetectionLoadBalancingConfig.SuccessRateEjection.enforcement_percentage = %v; must be <= 100", lbCfg.SuccessRateEjection.EnforcementPercentage)
	case lbCfg.FailurePercentageEjection != nil && lbCfg.FailurePercentageEjection.Threshold > 100:
		return nil, fmt.Errorf("OutlierDetectionLoadBalancingConfig.FailurePercentageEjection.threshold = %v; must be <= 100", lbCfg.FailurePercentageEjection.Threshold)
	case lbCfg.FailurePercentageEjection != nil && lbCfg.FailurePercentageEjection.EnforcementPercentage > 100:
		return nil, fmt.Errorf("OutlierDetectionLoadBalancingConfig.FailurePercentageEjection.enforcement_percentage = %v; must be <= 100", lbCfg.FailurePercentageEjection.EnforcementPercentage)
	}
	return lbCfg, nil
}

func (bb) Name() string {
	return Name
}

// scUpdate wraps a subConn update to be sent to the child balancer.
type scUpdate struct {
	scw   *subConnWrapper
	state balancer.SubConnState

View on GitHub (pinned to 0c51461d27)