# Kube-apiserver stops accepting tokens, and secrets missing

**URL:** <https://discuss.kubernetes.io/t/kube-apiserver-stops-accepting-tokens-and-secrets-missing/12864>\
**Category:** General Discussions\
**Created:** [September 17, 2020, 9:23pm UTC](https://discuss.kubernetes.io/t/kube-apiserver-stops-accepting-tokens-and-secrets-missing/12864 "2020-09-17T21:23:28Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alec\_Kloss](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/alec_kloss/32/5884_2.png) [@Alec\_Kloss](https://discuss.kubernetes.io/u/Alec_Kloss)\
**Post date:** [September 17, 2020, 9:23pm UTC](https://discuss.kubernetes.io/t/kube-apiserver-stops-accepting-tokens-and-secrets-missing/12864/1 "2020-09-17T21:23:28Z")

</div>

We’ve had an odd incident occur in a 1.15.7 cluster two days in a row. We’re not exactly sure about causality/order, but two things occur:

- The kube-apiserver stops accepting tokens it has issued
- Many `Kind: Secret` resources in the cluster disappear

This creates a very big mess in the cluster. Among other things, kube-controller-manager’s processes can no longer authenticate to do their things, so replicasets can’t provision pods, etc. Calico also falls apart due to authentication failures, so it’s a fairly big process to reset the cluster to working state.

This also causes the kube-apiserver to get DOS’ed given the amount of unauthorized tokens.

Has anyone experienced anything like this?

### Cluster information:

Kubernetes version: 1.15.7  
Cloud being used: AWS  
Installation method: Kops  
Host OS: Debian GNU/Linux 9 (stretch)  
CNI and version: Calico 3.9.6  
CRI and version: Docker 18.09.3
