# Disable apm-token, or add custom annotations to it?

**URL:** <https://discuss.elastic.co/t/disable-apm-token-or-add-custom-annotations-to-it/301981>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [April 8, 2022, 2:39pm UTC](https://discuss.elastic.co/t/disable-apm-token-or-add-custom-annotations-to-it/301981 "2022-04-08T14:39:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![fzyzcjy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fzyzcjy/32/78628_2.png) [@fzyzcjy](https://discuss.elastic.co/u/fzyzcjy)\
**Post date:** [April 8, 2022, 2:39pm UTC](https://discuss.elastic.co/t/disable-apm-token-or-add-custom-annotations-to-it/301981/1 "2022-04-08T14:39:37Z")

</div>

Hi thanks for ECK! I have a elastic instance in namespace A, but have a spring app that uses elastic apm in namespace B. The problem is, k8s Secret cannot be shared across namespaces, but we need the apm-token Secret to be able to connect to elastic apm server.

Thus, can I disable the auto-generated apm-token mechanism? I am using internal network so it may be safe enough.

Or, can I add custom annotations to the auto-generated apm-token Secret? If so, I could use something like "kubernetes reflector" to reflect the Secret into another namespace. But this all requires the original Secret has some special annotations, that is why I ask whether I can add custom annotations to the apm-token Secret.

Thanks for any suggestions!

---

<div class="post-metadata">

**Author:** ![michael.morello](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael.morello/32/47448_2.png) [@michael.morello](https://discuss.elastic.co/u/michael.morello)\
**Post date:** [April 11, 2022, 7:17am UTC](https://discuss.elastic.co/t/disable-apm-token-or-add-custom-annotations-to-it/301981/2 "2022-04-11T07:17:45Z")

</div>

> [@fzyzcjy](#):
>
> But this all requires the original Secret has some special annotations, that is why I ask whether I can add custom annotations to the apm-token Secret.

Unfortunately there is no way to control to annotations set on a Secret for now, however there is a workaround explained [here](https://github.com/elastic/cloud-on-k8s/issues/5474#issuecomment-1072210112). You could also just annotate the Secret once it has been created by the operator, using `kubectl annotate`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 9, 2022, 7:18am UTC](https://discuss.elastic.co/t/disable-apm-token-or-add-custom-annotations-to-it/301981/3 "2022-05-09T07:18:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
