influxdata/influxdb · error · CatalogError

cannot delete operator token

Error message

cannot delete operator token

What it means

Thrown when an attempt is made to delete the operator token from the catalog. The operator token is the bootstrap/admin credential required to administer the instance, so the catalog permanently protects it from deletion.

Solutions

  1. Skip the operator token in your deletion loop (filter by token name before calling delete).
  2. Delete only named, non-operator API tokens you created.
  3. If the operator token must be rotated, create a new operator token and follow the documented rotation path instead of deleting it.

Example fix

// before
for token in catalog.list_tokens()? {
    catalog.delete_token(&token.name)?;
}
// after
for token in catalog.list_tokens()? {
    if token.name != "operator" {
        catalog.delete_token(&token.name)?;
    }
}
Defensive patterns

Strategy: validation

Validate before calling

if token_name == OPERATOR_TOKEN_NAME {
    return Err("refusing to delete the operator token".into());
}

Try / catch

match result {
    Err(CatalogError::CannotDeleteOperatorToken) => {
        log::warn!("skipped operator token deletion");
    }
    other => other?,
}

Prevention

When it happens

Trigger: Calling the token deletion API (DELETE /api/v3/configure/token or catalog delete_token) with the token name/id of the operator token.

Common situations: Token cleanup scripts iterating over all tokens and deleting each; revoked-credential workflows accidentally targeting the admin token; multi-tenant cleanup jobs.

Related errors


AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19). Data as JSON: /api/errors/c6b7ef785aa05151. Report an issue: GitHub.

Appendix: source

Thrown at influxdb3_catalog/src/error.rs:326

    #[error("node '{node_id}' has compact mode and cannot be removed")]
    NodeModeNotRemovable { node_id: Arc<str> },

    #[error("invalid stop ack for node '{node_id}' (current state: {current_state})")]
    InvalidStopAck {
        node_id: Arc<str>,
        current_state: &'static str,
    },

    #[error("invalid unregister for node '{node_id}' (current state: {current_state})")]
    InvalidUnregister {
        node_id: Arc<str>,
        current_state: &'static str,
    },

    #[error("idempotent no-op")]
    IdempotentNoOp,

    #[error("cannot delete operator token")]
    CannotDeleteOperatorToken,

    #[error(
        "cannot change the configured generation duration for level {level}; \
        attempted to set to {attempted:#} but its already set to {existing:#}"
    )]
    CannotChangeGenerationDuration {
        level: u8,
        existing: Duration,
        attempted: Duration,
    },

    #[error("cannot add column {name} because it already exists with type {existing}")]
    DuplicateColumn {
        name: Arc<str>,
        existing: InfluxColumnType,
    },

View on GitHub (pinned to 06200ef96b)