# Apm server secret\_token

**URL:** <https://discuss.elastic.co/t/apm-server-secret-token/262841>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [February 1, 2021, 1:16pm UTC](https://discuss.elastic.co/t/apm-server-secret-token/262841 "2021-02-01T13:16:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![aman26ps](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aman26ps/32/82604_2.png) [@aman26ps](https://discuss.elastic.co/u/aman26ps)\
**Post date:** [February 1, 2021, 1:16pm UTC](https://discuss.elastic.co/t/apm-server-secret-token/262841/1 "2021-02-01T13:16:39Z")

</div>

Hi Team,

i would like to change secret\_token of apm server config, i am using the following config, but the token is not getting reflected

```auto
secureSettings:
  - secretName: test-apm-token
  config:
    apm-server:
      ssl: 
       enabled: true
      secret_token: "${SECRET_TOKEN}"

```

PS: I am creating a secret before hand  
kubectl create secret generic apm-secret-token --from-literal=SECRET\_TOKEN=

---

<div class="post-metadata">

**Author:** ![michael.morello](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael.morello/32/47448_2.png) [@michael.morello](https://discuss.elastic.co/u/michael.morello)\
**Post date:** [February 2, 2021, 2:08pm UTC](https://discuss.elastic.co/t/apm-server-secret-token/262841/2 "2021-02-02T14:08:08Z")

</div>

Hi,

The APM token is stored in a dedicated Secret, you can find the relevant [documentation here](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-apm-connecting.html#k8s-apm-secret-token).

I'm wondering if this is not preventing your secure setting to be applied 🤔

Could you try to update the dedicated secret directly ?

---

<div class="post-metadata">

**Author:** ![aman26ps](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aman26ps/32/82604_2.png) [@aman26ps](https://discuss.elastic.co/u/aman26ps)\
**Post date:** [February 2, 2021, 2:55pm UTC](https://discuss.elastic.co/t/apm-server-secret-token/262841/3 "2021-02-02T14:55:52Z")

</div>

Hi Michael,

Thanks for your reply, i found out what the issue was:

1. the secret name should be created before i create apm custom resource with the specific format i.e. ${cluster-name}-apm-token
2. the key in the secret should be lower case as `secret-token` , if the above criteria is not met operator will delete the secret and create a new one.

so i made identical secret which operator doesn't delete and create a new one automatically.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:23am UTC](https://discuss.elastic.co/t/apm-server-secret-token/262841/4 "2022-11-04T08:23:02Z")

</div>


