# Contact an APMServer from several namespaces

**URL:** <https://discuss.elastic.co/t/contact-an-apmserver-from-several-namespaces/233137>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [May 18, 2020, 3:21pm UTC](https://discuss.elastic.co/t/contact-an-apmserver-from-several-namespaces/233137 "2020-05-18T15:21:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sayrus](https://avatars.discourse-cdn.com/v4/letter/s/74df32/32.png) [@Sayrus](https://discuss.elastic.co/u/Sayrus)\
**Post date:** [May 18, 2020, 3:21pm UTC](https://discuss.elastic.co/t/contact-an-apmserver-from-several-namespaces/233137/1 "2020-05-18T15:21:07Z")

</div>

Hello,

I've recently been trying to deploy a single ApmServer for several namespace. Unfortunately, it means that I have to manually copy the `apm-token` to other namespace that might need it.  
It makes token rotations time-consuming and a bit risky (for instance, What if I forgot one token secret?)  
I thought about tasking the operator to create the secrets for me, however this would lead to an invalid ownerReferences as it is only possible to reference cluster-scoped resources or resources in the same namespace.

Which is why I thought it was a good idea to have one ApmServer per namespace. Unfortunately, this is currently not supported by the operator as the current documentation indicate:

```auto
Deploying the APM Server and Elasticsearch in two different namespaces is currently not supported.

```

How do you guys handle having agents in all namespaces? Do you manually copy the secret? Do you manually specify a secret to the operator so that you can handle rotations yourself? Do you disable authentication all-together?

Best regards,

---

<div class="post-metadata">

**Author:** ![sebgl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebgl/32/48702_2.png) [@sebgl](https://discuss.elastic.co/u/sebgl)\
**Post date:** [May 19, 2020, 9:36am UTC](https://discuss.elastic.co/t/contact-an-apmserver-from-several-namespaces/233137/2 "2020-05-19T09:36:19Z")

</div>

Hey @Sayrus,

> Deploying the APM Server and Elasticsearch in two different namespaces is currently not supported.

Oops, this isn't true anymore. We definitely support running Elasticsearch and APMServer in different namespaces, and we already supported it in 1.0. I'm fixing the docs to remove that warning.

When copying Secrets into other namespace you need to be extra careful about [this Kubernetes bug](https://github.com/elastic/cloud-on-k8s/issues/3037): you must make sure you don't copy the `metadata.ownerReferences` field.

This [issue in the cert-manager repo](https://github.com/jetstack/cert-manager/issues/494) contains some examples of CronJobs to deal with the synchronization of Secrets in multiple namespaces.  
I am not aware of a builtin solution or simple operator you could use for that purpose.

Simplifying secret management across namespaces is definitely something we (ECK team) are thinking about.

---

<div class="post-metadata">

**Author:** ![Sayrus](https://avatars.discourse-cdn.com/v4/letter/s/74df32/32.png) [@Sayrus](https://discuss.elastic.co/u/Sayrus)\
**Post date:** [May 19, 2020, 12:40pm UTC](https://discuss.elastic.co/t/contact-an-apmserver-from-several-namespaces/233137/3 "2020-05-19T12:40:11Z")

</div>

Thanks for this precise answer. This is great news, I'll be able to achieve what I wanted by having an APMServer in each namespace. As long as I am not using Agent Autoconfiguration, I don't even need secret synchronization because ECK will handle the ES required secrets and the APMServer has its own.

The issue you linked are indeed very serious and I'll be taking it into account even outside ECK.

I just tried deploying an APMServer in another namespace and it work like a charm.

Thanks again,

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 7:58am UTC](https://discuss.elastic.co/t/contact-an-apmserver-from-several-namespaces/233137/4 "2022-11-04T07:58:41Z")

</div>


