# ServiceAccount's token being continuously recreated

**URL:** <https://discuss.kubernetes.io/t/serviceaccounts-token-being-continuously-recreated/14382>\
**Category:** General Discussions\
**Created:** [January 6, 2021, 9:35pm UTC](https://discuss.kubernetes.io/t/serviceaccounts-token-being-continuously-recreated/14382 "2021-01-06T21:35:39Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ndemeshchenko](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/ndemeshchenko/32/6655_2.png) [@ndemeshchenko](https://discuss.kubernetes.io/u/ndemeshchenko)\
**Post date:** [January 6, 2021, 9:35pm UTC](https://discuss.kubernetes.io/t/serviceaccounts-token-being-continuously-recreated/14382/1 "2021-01-06T21:35:39Z")

</div>

Hiya all,  
I’m having a weird issue with my k8s cluster (1.15.11). All secrets of type `service-account-token` are being continuously recreated. And I can’t really find any traces in the logs. Has anyone seen anything similar or can point where to look at? Thanks

### Cluster information:

Kubernetes version: 1.15.11  
Cloud being used: VM on-prem  
Installation method: kubespray  
Host OS: Centos 7  
CNI and version: –  
CRI and version: –

---

<div class="post-metadata">

**Author:** ![icelynjennings](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/icelynjennings/32/2550_2.png) [@icelynjennings](https://discuss.kubernetes.io/u/icelynjennings)\
**Post date:** [January 8, 2021, 8:16pm UTC](https://discuss.kubernetes.io/t/serviceaccounts-token-being-continuously-recreated/14382/2 "2021-01-08T20:16:03Z")

</div>

Hi @ndemeshchenko,

A secret of type `service-account-token` that instantly reappears after manual deletion (e.g. via `kubectl delete secret <SECRET>`) is likely to be holding the API token corresponding to a `ServiceAccount` you created in your cluster. From the [docs](https://kubernetes.io/docs/reference/access-authn-authz/service-accounts-admin/#token-controller):

> A controller loop ensures a Secret with an API token exists for each ServiceAccount.

> TokenController runs as part of `kube-controller-manager` . It acts asynchronously. It:
> 
> - watches ServiceAccount creation and creates a corresponding ServiceAccount token Secret to allow API access.
> - watches ServiceAccount deletion and deletes all corresponding ServiceAccount token Secrets.
> - watches ServiceAccount token Secret addition, and ensures the referenced ServiceAccount exists, and adds a token to the Secret if needed.
> - watches Secret deletion and removes a reference from the corresponding ServiceAccount if needed.

Further reading:

- [Configure Service Accounts for Pods | Kubernetes](https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/)
- [Managing Service Accounts | Kubernetes](https://kubernetes.io/docs/reference/access-authn-authz/service-accounts-admin/)
