# Kubectl fail all commands - forbidden

**URL:** <https://discuss.kubernetes.io/t/kubectl-fail-all-commands-forbidden/8529>\
**Category:** General Discussions\
**Created:** [October 30, 2019, 8:58am UTC](https://discuss.kubernetes.io/t/kubectl-fail-all-commands-forbidden/8529 "2019-10-30T08:58:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Biam](https://avatars.discourse-cdn.com/v4/letter/b/f08c70/32.png) [@Biam](https://discuss.kubernetes.io/u/Biam)\
**Post date:** [October 30, 2019, 8:58am UTC](https://discuss.kubernetes.io/t/kubectl-fail-all-commands-forbidden/8529/1 "2019-10-30T08:58:21Z")

</div>

Hello everyone,

I want to start saying that I’m not an expert but i’m facing a big problem with a production environment.  
More people touched this system so I will explain just what I know.  
A few weeks ago we had a problem with all certificates expired.  
I know a colleague used the command kubeadm alpha certs to renew them and he solved the problem but, since then, all kubectl command fail with errors messages like:

- Error from server (Forbidden): services is forbidden: User “kubernetes-admin” cannot list services in the namespace “kube-system”  
OR
- Error from server (Forbidden): [clusterroles.rbac.authorization.k8s.io](http://clusterroles.rbac.authorization.k8s.io) is forbidden: User “kubernetes-admin” cannot ist [clusterroles.rbac.authorization.k8s.io](http://clusterroles.rbac.authorization.k8s.io) at the cluster scope  
OR
- configmaps “kubeadm-config” is forbidden: User “kubernetes-admin” cannot get configmaps in the namespace “kube-systm”

I think probably we have somes issue maybe with a role or something like that but without kubectl I can’t modify anything. The dashboard we have installed is an old version and it not permit to modify roles cluster or roles etc.  
The problem is probably something “stupid” that simply I can’t see. Anyone with patience to help me solve this problem please?

Thanks in advance.

### Cluster information:

Kubernetes version: v1.13  
Cloud being used: OVH  
Installation method: kubeadm  
Host OS: Ubuntu 16.04  
CNI and version: v1.13  
CRI and version: v1.13.

You can format your yaml by highlighting it and pressing Ctrl-Shift-C, it will make your output easier to read.

---

<div class="post-metadata">

**Author:** ![rata](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/rata/32/18244_2.png) [@rata](https://discuss.kubernetes.io/u/rata)\
**Post date:** [October 30, 2019, 11:48pm UTC](https://discuss.kubernetes.io/t/kubectl-fail-all-commands-forbidden/8529/2 "2019-10-30T23:48:20Z")

</div>

I’m not familiar with kubeadm, but have you tried using the kubeconfig files on the nodes (maybe the ones in the master are more powerful)?

I really don’t know what certs kubeadm uses for the controllers/workers, but that can’t hurt to try if you have more permissions with that.

---

<div class="post-metadata">

**Author:** ![Biam](https://avatars.discourse-cdn.com/v4/letter/b/f08c70/32.png) [@Biam](https://discuss.kubernetes.io/u/Biam)\
**Post date:** [October 31, 2019, 1:07pm UTC](https://discuss.kubernetes.io/t/kubectl-fail-all-commands-forbidden/8529/3 "2019-10-31T13:07:50Z")

</div>

Hello rata, first of all thx for answering.  
i suppose that somewhere (into roles o secret or whatever) there are configured the old certs and for this reason any kubectl command fail with the error message “forbidden”.  
Kubeadm is the way the cluster was installed at the beginning and the whole cluster worked fine until 1 year after, when certs expired and we had to renew all of them.  
But, since then, now all kubectl commands fails as I said before, this mean I can’t modify any configuration via the usual way, using kubectl.

---

<div class="post-metadata">

**Author:** ![rata](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/rata/32/18244_2.png) [@rata](https://discuss.kubernetes.io/u/rata)\
**Post date:** [November 3, 2019, 6:50pm UTC](https://discuss.kubernetes.io/t/kubectl-fail-all-commands-forbidden/8529/4 "2019-11-03T18:50:12Z")

</div>

Yes, I think I got the picture. Have you tried what I suggested in the previous message?
