grpc/grpc-go · error

rls_csp: validation error from rls lb policy parsing

Error message

rls_csp: validation error from rls lb policy parsing: %v

What it means

The RLS LB policy's ConfigParser.ParseConfig rejected the constructed LB config JSON (rls.go:90-91). The route lookup config, child policy, or target field name in the JSON does not satisfy the RLS balancer's validation rules.

Solutions

  1. Review the wrapped error for the specific RLS LB policy validation failure message
  2. Ensure RouteLookupConfig has valid cache_size_bytes (> 0), grpc_keybuilders, and lookup_service fields
  3. Verify the child policy 'cds_experimental' is registered and configured correctly
  4. Check that childPolicyConfigTargetFieldName matches the expected 'cluster' value
Defensive patterns

Strategy: validation

Validate before calling

// Pre-validate RouteLookupConfig fields before relying on xDS parsing.
rlc := rlcs.GetRouteLookupConfig()
if rlc.GetCacheSizeBytes() == 0 {
    return fmt.Errorf("RouteLookupConfig cache_size_bytes must be > 0")
}
if len(rlc.GetGrpcKeybuilders()) == 0 {
    return fmt.Errorf("RouteLookupConfig must include at least one grpc_keybuilder")
}

Try / catch

_, err := plugin.ParseClusterSpecifierConfig(anyCfg)
if err != nil && strings.Contains(err.Error(), "validation error from rls lb policy parsing") {
    log.Printf("RLS LB config rejected: %v — check RouteLookupConfig fields", err)
}

Prevention

When it happens

Trigger: rlsBB.(balancer.ConfigParser).ParseConfig(rawJSON) returns an error because the constructed JSON (containing routeLookupConfig, childPolicy, and childPolicyConfigTargetFieldName) has fields that fail the RLS LB policy's semantic validation.

Common situations: RouteLookupConfig has an invalid cache size (zero or negative), missing grpc_keybuilders, an invalid lookup service target, or an empty target field; xDS server sends a structurally valid but semantically invalid RouteLookupConfig; child policy 'cds_experimental' not registered.

Related errors


AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11). Data as JSON: /api/errors/887d7bd8fb64890b. Report an issue: GitHub.

Appendix: source

Thrown at internal/xds/clusterspecifier/rls/rls.go:91

		ChildPolicy: []map[string]json.RawMessage{
			{
				"cds_experimental": json.RawMessage(`{"isDynamic":true}`),
			},
		},
		ChildPolicyConfigTargetFieldName: "cluster",
	}

	rawJSON, err := json.Marshal(lbCfgJSON)
	if err != nil {
		return nil, fmt.Errorf("rls_csp: error marshaling load balancing config %v: %v", lbCfgJSON, err)
	}

	rlsBB := balancer.Get(internal.RLSLoadBalancingPolicyName)
	if rlsBB == nil {
		return nil, fmt.Errorf("RLS LB policy not registered")
	}
	if _, err = rlsBB.(balancer.ConfigParser).ParseConfig(rawJSON); err != nil {
		return nil, fmt.Errorf("rls_csp: validation error from rls lb policy parsing: %v", err)
	}

	return clusterspecifier.BalancerConfig{{internal.RLSLoadBalancingPolicyName: lbCfgJSON}}, nil
}

View on GitHub (pinned to 0c51461d27)