{"record":{"id":"b229fd121808b052","repo":"influxdata/influxdb","slug":"missing-admin-token-cannot-update","errorCode":null,"errorMessage":"missing admin token, cannot update","messagePattern":"missing admin token, cannot update","errorType":"error_code","errorClass":"CatalogError","httpStatus":null,"severity":"error","filePath":"influxdb3_catalog/src/error.rs","lineNumber":288,"sourceCode":"    #[error(\"failed to parse trigger from {trigger_spec}{}\", .context.as_ref().map(|context| format!(\": {context}\")).unwrap_or_default())]\n    TriggerSpecificationParseError {\n        trigger_spec: String,\n        context: Option<String>,\n    },\n\n    #[error(\"invalid error behavior {0}\")]\n    InvalidErrorBehavior(String),\n\n    #[error(\"cannot parse token permission, {0}\")]\n    CannotParsePermissionForToken(String),\n\n    #[error(\"token name already exists, {0}\")]\n    TokenNameAlreadyExists(String),\n\n    #[error(\"token hash already exists\")]\n    TokenHashAlreadyExists,\n\n    #[error(\"missing admin token, cannot update\")]\n    MissingAdminTokenToUpdate,\n\n    #[error(\"cannot delete internal db\")]\n    CannotDeleteInternalDatabase,\n\n    #[error(\"cannot modify internal db\")]\n    CannotModifyInternalDatabase,\n\n    #[error(\"tried to stop a node ({node_id}) that is already stopped\")]\n    NodeAlreadyStopped { node_id: Arc<str> },\n\n    #[error(\n        \"node '{node_id}' is not fully stopped (current state: {current_state}); run \\\"stop node\\\" first\"\n    )]\n    NodeNotFullyStopped {\n        node_id: Arc<str>,\n        current_state: &'static str,\n    },","sourceCodeStart":270,"sourceCodeEnd":306,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_catalog/src/error.rs#L270-L306","documentation":"This error is returned when an operation tries to update an admin token but the admin token is missing from the catalog. Admin tokens are special bootstrap tokens; updating one requires it to exist, and its absence is an integrity problem. The catalog refuses the update rather than silently creating state.","triggerScenarios":"Calling `update_admin_token` when the catalog has no admin token defined (e.g. catalog bootstrapped without one, or the admin token entry was removed/corrupted).","commonSituations":"Restoring a partial catalog backup that lacks the admin token row; running update flows on a fresh instance before the admin token was provisioned; manual deletion of the admin token.","solutions":["Bootstrap/provision the admin token first (start the server so it initializes, or use the bootstrap flow)","Verify the catalog contains the admin token before attempting updates","If the catalog is corrupted, restore from a valid backup","Use a normal (non-admin) token API for regular token rotation"],"exampleFix":"// before\ncatalog.update_admin_token(&new_hash)?; // fails if absent\n// after\nif catalog.admin_token().is_some() {\n    catalog.update_admin_token(&new_hash)?;\n} else {\n    bootstrap_admin_token(&new_hash)?;\n}","handlingStrategy":"validation","validationCode":"fn admin_token_exists(catalog: &Catalog) -> bool {\n    catalog.admin_token().is_some()\n}","typeGuard":null,"tryCatchPattern":"match update_admin_token(hash) {\n    Err(CatalogError::MissingAdminTokenToUpdate) => bootstrap_admin_token(hash),\n    r => r,\n}","preventionTips":["Ensure the instance is bootstrapped before token admin operations","Verify catalog backups include the admin token row","Restore from complete backups only"],"tags":["catalog","auth","tokens","admin"],"backgroundTag":"entity-not-found","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}