grpc/grpc-go · error
rbac: nil configuration message provided
Error message
rbac: nil configuration message provided
What it means
ParseFilterConfig (rbac.go:186) rejects a nil proto.Message up front. The RBAC filter requires a non-nil *anypb.Any wrapping an rpb.RBAC proto; nil indicates a programming or control-plane error. (Note: ParseFilterConfigOverride also returns this same message for a nil override.)
Solutions
- Provide a non-nil *anypb.Any wrapping an rpb.RBAC proto to ParseFilterConfig.
- Confirm the xDS Listener/Route contains the RBAC filter's typed_config with the correct type URL.
- If RBAC is not desired, remove the filter from the resource rather than sending nil.
Example fix
// before
cfg, err := rbacBuilder.ParseFilterConfig(nil)
// after
anyCfg, _ := anypb.New(&rpb.RBAC{Rules: &v3rbacpb.RBAC{Action: v3rbacpb.RBAC_ALLOW}})
cfg, err := rbacBuilder.ParseFilterConfig(anyCfg) Defensive patterns
Strategy: validation
Validate before calling
if cfg == nil {
return nil, errors.New("rbac: refusing to parse nil config")
} Try / catch
fc, err := rbacBuilder.ParseFilterConfig(anyCfg)
if err != nil {
if strings.Contains(err.Error(), "nil configuration message") {
// populate typed_config in the xDS resource
}
return err
} Prevention
- Populate the RBAC filter's typed_config in xDS.
- Reject nil configs at the control-plane.
- Unit-test registration paths with non-nil inputs.
When it happens
Trigger: ParseFilterConfig(nil) or ParseFilterConfigOverride(nil) is invoked, either directly or because the xDS resource contained a nil-typed config for the RBAC filter.
Common situations: xDS server emits an RBAC filter entry with an empty typed_config; programmatic registration with nil; test code that forgot to populate the config.
Related errors
- grpc: no transport security set (use…
- grpc: the connection is closing
- grpc: the connection is drained
- no SubConn is available
- rbac: error constructing matching engine
AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11).
Data as JSON: /api/errors/3cd421993a0c55fc.
Report an issue: GitHub.
Appendix: source
Thrown at internal/xds/httpfilter/rbac/rbac.go:187
// normalizeHeaderMatcher rejects header matchers that A41 forbids (:scheme or a
// grpc- prefixed name) and rewrites a "host" matcher to ":authority".
func normalizeHeaderMatcher(header *v3routepb.HeaderMatcher) error {
name := header.GetName()
if name == ":scheme" {
return fmt.Errorf("rbac: header matcher for %q is %q", name, ":scheme")
}
if strings.HasPrefix(name, "grpc-") {
return fmt.Errorf("rbac: header matcher for %q starts with %q", name, "grpc-")
}
if name == "host" {
header.Name = ":authority"
}
return nil
}
func (builder) ParseFilterConfig(cfg proto.Message) (httpfilter.FilterConfig, error) {
if cfg == nil {
return nil, fmt.Errorf("rbac: nil configuration message provided")
}
m, ok := cfg.(*anypb.Any)
if !ok {
return nil, fmt.Errorf("rbac: error parsing config %v: unknown type %T", cfg, cfg)
}
msg := new(rpb.RBAC)
if err := m.UnmarshalTo(msg); err != nil {
return nil, fmt.Errorf("rbac: error parsing config %v: %v", cfg, err)
}
return parseConfig(msg)
}
func (builder) ParseFilterConfigOverride(override proto.Message) (httpfilter.FilterConfig, error) {
if override == nil {
return nil, fmt.Errorf("rbac: nil configuration message provided")
}
m, ok := override.(*anypb.Any)
if !ok {View on GitHub (pinned to 0c51461d27)