We must assume that the control plane is authoritative (in order to enforce identity, policy, etc). When we initially scoped the fallback logic, it seemed to make sense that the the proxy should use fallback routing when the control plane reports no endpoints. In practice, it seems better for the proxy to rely on its load balancer as long as the control plane does not return a IllegalArgument error.