grpc/grpc-go · error
rbac: error parsing config
Error message
rbac: error parsing config %v: %v
What it means
ParseFilterConfig (rbac.go:194) type-asserted *anypb.Any but UnmarshalTo into rpb.RBAC failed. The wrapped bytes are not a valid rpb.RBAC: wrong type URL, corrupt payload, or schema mismatch.
Solutions
- Ensure the anypb.Any type_url is type.googleapis.com/envoy.extensions.filters.http.rbac.v3.RBAC (or the RBACPerRoute URL for overrides).
- Align go-control-plane versions between server and client.
- Log the wrapped error to distinguish type-URL mismatch from wire-format decode errors.
Example fix
// before
anyCfg := &anypb.Any{TypeUrl: "type.googleapis.com/envoy.extensions.filters.http.rbac.v3.RBACPerRoute", Value: rawRbacBytes}
// after
anyCfg := &anypb.Any{TypeUrl: "type.googleapis.com/envoy.extensions.filters.http.rbac.v3.RBAC", Value: rawRbacBytes} Defensive patterns
Strategy: validation
Validate before calling
if m, ok := cfg.(*anypb.Any); ok {
want := "type.googleapis.com/envoy.extensions.filters.http.rbac.v3.RBAC"
if m.TypeUrl != want {
return nil, fmt.Errorf("rbac: type_url %q != %q", m.TypeUrl, want)
}
} Try / catch
if err != nil && strings.Contains(err.Error(), "error parsing config") {
// inspect the wrapped error to distinguish type-URL mismatch from wire corruption
} Prevention
- Pin go-control-plane versions across server and client.
- Validate the Any.TypeUrl against builder.TypeURLs() before unmarshalling.
- Round-trip test rpb.RBAC through ParseFilterConfig.
When it happens
Trigger: anypb.Any with a mismatched type URL (e.g., the v2 URL or a different filter's URL), truncated/malformed bytes, or a go-control-plane version whose rpb.RBAC schema differs from the client's compiled proto.
Common situations: Version skew between control-plane and data-plane; corrupted config in transit; wrong filter config bound to the RBAC TypeURL.
Related errors
- error parsing custom audit logger config
- extproc: failed to unmarshal config
- extproc: failed to unmarshal override
- fault: error parsing config
- gcpauthn: failed to unmarshal filter config
AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11).
Data as JSON: /api/errors/8f3ea633cff22290.
Report an issue: GitHub.
Appendix: source
Thrown at internal/xds/httpfilter/rbac/rbac.go:195
return fmt.Errorf("rbac: header matcher for %q starts with %q", name, "grpc-")
}
if name == "host" {
header.Name = ":authority"
}
return nil
}
func (builder) ParseFilterConfig(cfg proto.Message) (httpfilter.FilterConfig, error) {
if cfg == nil {
return nil, fmt.Errorf("rbac: nil configuration message provided")
}
m, ok := cfg.(*anypb.Any)
if !ok {
return nil, fmt.Errorf("rbac: error parsing config %v: unknown type %T", cfg, cfg)
}
msg := new(rpb.RBAC)
if err := m.UnmarshalTo(msg); err != nil {
return nil, fmt.Errorf("rbac: error parsing config %v: %v", cfg, err)
}
return parseConfig(msg)
}
func (builder) ParseFilterConfigOverride(override proto.Message) (httpfilter.FilterConfig, error) {
if override == nil {
return nil, fmt.Errorf("rbac: nil configuration message provided")
}
m, ok := override.(*anypb.Any)
if !ok {
return nil, fmt.Errorf("rbac: error parsing override config %v: unknown type %T", override, override)
}
msg := new(rpb.RBACPerRoute)
if err := m.UnmarshalTo(msg); err != nil {
return nil, fmt.Errorf("rbac: error parsing override config %v: %v", override, err)
}
return parseConfig(msg.Rbac)
}View on GitHub (pinned to 0c51461d27)