# APM on ECK overwriting kubernetes secret token

**URL:** <https://discuss.elastic.co/t/apm-on-eck-overwriting-kubernetes-secret-token/211729>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [December 12, 2019, 9:58pm UTC](https://discuss.elastic.co/t/apm-on-eck-overwriting-kubernetes-secret-token/211729 "2019-12-12T21:58:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andrew\_Nichols](https://avatars.discourse-cdn.com/v4/letter/a/ed655f/32.png) [@Andrew\_Nichols](https://discuss.elastic.co/u/Andrew_Nichols)\
**Post date:** [December 12, 2019, 9:58pm UTC](https://discuss.elastic.co/t/apm-on-eck-overwriting-kubernetes-secret-token/211729/1 "2019-12-12T21:58:00Z")

</div>

We recently added APM to our ECK cluster andrew we're running into an issue. If we remove APM and re-add it the operator will overwrite any existing apm-token set. I would assume it worked like the es-elastic-user secret and just use it if it exists and not overwrite the value.

Is this how it's supposed to work?

Thanks,  
Andrew

---

<div class="post-metadata">

**Author:** ![charith-elastic](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@charith-elastic](https://discuss.elastic.co/u/charith-elastic)\
**Post date:** [December 16, 2019, 9:04am UTC](https://discuss.elastic.co/t/apm-on-eck-overwriting-kubernetes-secret-token/211729/2 "2019-12-16T09:04:24Z")

</div>

I am assuming you manually created the token secret because `kubectl delete apmserver <name>` would have deleted the token secret that was created by the operator. In order to get the new APM server to re-use the existing secret, the following conditions must be satisfied:

- Secret must be named `myapm-apm-token` (assuming that the APM server is named `myapm`)
- The secret must have the following labels:
  - `apm.k8s.elastic.co/name=myapm`
  - `common.k8s.elastic.co/type=apm-server`

The sequence of commands would be:

```auto
APM_NAME=myapm
kubectl create secret generic ${APM_NAME}-apm-token --from-literal=secret-token=$TOKEN
kubectl label secret ${APM_NAME}-apm-token "apm.k8s.elastic.co/name=$APM_NAME" "common.k8s.elastic.co/type=apm-server"

```

---

<div class="post-metadata">

**Author:** ![Andrew\_Nichols](https://avatars.discourse-cdn.com/v4/letter/a/ed655f/32.png) [@Andrew\_Nichols](https://discuss.elastic.co/u/Andrew_Nichols)\
**Post date:** [December 16, 2019, 10:41pm UTC](https://discuss.elastic.co/t/apm-on-eck-overwriting-kubernetes-secret-token/211729/3 "2019-12-16T22:41:57Z")

</div>

Thank you! I didn't know about the labelling requirement for the secret.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 7:37am UTC](https://discuss.elastic.co/t/apm-on-eck-overwriting-kubernetes-secret-token/211729/4 "2022-11-04T07:37:18Z")

</div>


