grpc/grpc-go · error

rbac: nil configuration message provided

Error message

rbac: nil configuration message provided

What it means

ParseFilterConfig (rbac.go:186) rejects a nil proto.Message up front. The RBAC filter requires a non-nil *anypb.Any wrapping an rpb.RBAC proto; nil indicates a programming or control-plane error. (Note: ParseFilterConfigOverride also returns this same message for a nil override.)

Solutions

  1. Provide a non-nil *anypb.Any wrapping an rpb.RBAC proto to ParseFilterConfig.
  2. Confirm the xDS Listener/Route contains the RBAC filter's typed_config with the correct type URL.
  3. If RBAC is not desired, remove the filter from the resource rather than sending nil.

Example fix

// before
cfg, err := rbacBuilder.ParseFilterConfig(nil)

// after
anyCfg, _ := anypb.New(&rpb.RBAC{Rules: &v3rbacpb.RBAC{Action: v3rbacpb.RBAC_ALLOW}})
cfg, err := rbacBuilder.ParseFilterConfig(anyCfg)
Defensive patterns

Strategy: validation

Validate before calling

if cfg == nil {
    return nil, errors.New("rbac: refusing to parse nil config")
}

Try / catch

fc, err := rbacBuilder.ParseFilterConfig(anyCfg)
if err != nil {
    if strings.Contains(err.Error(), "nil configuration message") {
        // populate typed_config in the xDS resource
    }
    return err
}

Prevention

When it happens

Trigger: ParseFilterConfig(nil) or ParseFilterConfigOverride(nil) is invoked, either directly or because the xDS resource contained a nil-typed config for the RBAC filter.

Common situations: xDS server emits an RBAC filter entry with an empty typed_config; programmatic registration with nil; test code that forgot to populate the config.

Related errors


AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11). Data as JSON: /api/errors/3cd421993a0c55fc. Report an issue: GitHub.

Appendix: source

Thrown at internal/xds/httpfilter/rbac/rbac.go:187

// normalizeHeaderMatcher rejects header matchers that A41 forbids (:scheme or a
// grpc- prefixed name) and rewrites a "host" matcher to ":authority".
func normalizeHeaderMatcher(header *v3routepb.HeaderMatcher) error {
	name := header.GetName()
	if name == ":scheme" {
		return fmt.Errorf("rbac: header matcher for %q is %q", name, ":scheme")
	}
	if strings.HasPrefix(name, "grpc-") {
		return fmt.Errorf("rbac: header matcher for %q starts with %q", name, "grpc-")
	}
	if name == "host" {
		header.Name = ":authority"
	}
	return nil
}

func (builder) ParseFilterConfig(cfg proto.Message) (httpfilter.FilterConfig, error) {
	if cfg == nil {
		return nil, fmt.Errorf("rbac: nil configuration message provided")
	}
	m, ok := cfg.(*anypb.Any)
	if !ok {
		return nil, fmt.Errorf("rbac: error parsing config %v: unknown type %T", cfg, cfg)
	}
	msg := new(rpb.RBAC)
	if err := m.UnmarshalTo(msg); err != nil {
		return nil, fmt.Errorf("rbac: error parsing config %v: %v", cfg, err)
	}
	return parseConfig(msg)
}

func (builder) ParseFilterConfigOverride(override proto.Message) (httpfilter.FilterConfig, error) {
	if override == nil {
		return nil, fmt.Errorf("rbac: nil configuration message provided")
	}
	m, ok := override.(*anypb.Any)
	if !ok {

View on GitHub (pinned to 0c51461d27)