google.api_core.exceptions.ServiceUnavailable: 503 failed to connect to all addresses (pubsub)
Fixes Pub/Sub gRPC connections failing to reach Google. Use when calls raise ServiceUnavailable 503 failed to connect. Not for 403/404 errors.
TL;DR: The gRPC channel cannot reach Google's Pub/Sub endpoints at all. This is network: a proxy that does not handle gRPC, a firewall, or DNS. Fix the network path (grpcproxy / noproxy settings) and it connects.
google.api_core.exceptions.ServiceUnavailable: 503 failed to connect to all addresses; last error: UNKNOWN: ipv4:[address]:443: Failed to connect to remote host: Connection refusedFix it
- Test plain HTTPS to Google: curl -sI https://pubsub.googleapis.com --max-time 10. Expected: HTTP 404 or 401 (reached). A hang/fail means general egress is broken.
- If you are behind a proxy, set grpcproxy (and noproxy for internal hosts); plain https_proxy alone does not cover gRPC. Expected: the client connects.
- Check firewall rules for egress to port 443. Expected: allowed.
- As a diagnostic only, try the REST transport instead of gRPC to isolate transport vs network.
When this applies
- ServiceUnavailable 503 failed to connect to all addresses on Pub/Sub calls.
When it doesn't
- 403/404: you reach Google; auth or naming is the problem.
- DeadlineExceeded on long pulls: normal streaming behavior; tune timeouts.
Compatibility
- google-cloud-pubsub any version (gRPC transport).
Why it happens
Pub/Sub uses gRPC over HTTP/2, which many corporate proxies mishandle or block outright while plain HTTPS works, producing this exact failure.
Edge cases
- Emulator users: set PUBSUBEMULATORHOST; without it the client dials real Google.
- MTU issues on VPNs can break HTTP/2 while HTTPS seems fine; test from outside the VPN.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.