grpc method call error: Failed to pick subchannel

Viewed 6838

gRpc Client: Python:3.8 grpcio: 1.38.1

gRpc Server: Dotnet core 5.0 LoadBalancer AKS: 1.19.7

I'm getting below error when my python client calls a method. Any help to resolve is really appreciated.

Python code snippet

with open('chain.pem', 'rb') as f:
        trusted_certs = f.read()

credentials = channel = grpc.ssl_channel_credentials(root certificates=trusted_certs)

# 10.200.3.24 is the K8S service IP with 3 replicas
channel = grpc.secure_channel('10.200.3.24:443', credentails, options=(('grpc.enable_http_proxy', 0),))

stub = query_pb2_grpc.QueryStub(channel)

empty = google_dot_protobuf_dot_empty__pb2.Empty()
data = stub.TestMethod(empty)

error

_InactiveRpcError: <_InactiveRpcError of RPC that terminated with:
    status = StatusCode.UNAVAILABLE
    details = "Empty update"
    debug_error_string = "{"created":"@1625180429.368158115","description":"Failed to pick subchannel","file":"src/core/ext/filters/client_channel/client_channel.cc","file_line":3008,"referenced_errors":[{"created":"@1625178894.878505214","description":"Empty update","file":"src/core/ext/filters/client_channel/lb_policy/pick_first/pick_first.cc","file_line":201,"grpc_status":14}]}"
>
1 Answers

This is resolved now. Updating if it helps anyone out there with similar issue. First enable gRpc trace using below two exports and then run your code see the error in detail.

export GRPC_TRACE=all
export GRPC_VERBOSITY=DEBUG

In my case, there was this below error

handshake failed: {"created":"@1582571630.967438000","description":"Peer 
name 10.200.3.24 is not in peer certificate", "file":
"src/core/lib/security/security_connector/ssl/ssl_security_connector.cc",
"file_line":55}

My server self-signed cert (subject:/C=US/ST=US/O=Self Signed/CN=10.100.3.250) did not have subjectAltName extension. After adding subjectAltName extension (IP.1=10.100.3.250), stuff started working fine.

Related