influxdata/influxdb · error · CatalogError
missing admin token, cannot update
Error message
missing admin token, cannot update
What it means
This error is returned when an operation tries to update an admin token but the admin token is missing from the catalog. Admin tokens are special bootstrap tokens; updating one requires it to exist, and its absence is an integrity problem. The catalog refuses the update rather than silently creating state.
Solutions
- Bootstrap/provision the admin token first (start the server so it initializes, or use the bootstrap flow)
- Verify the catalog contains the admin token before attempting updates
- If the catalog is corrupted, restore from a valid backup
- Use a normal (non-admin) token API for regular token rotation
Example fix
// before
catalog.update_admin_token(&new_hash)?; // fails if absent
// after
if catalog.admin_token().is_some() {
catalog.update_admin_token(&new_hash)?;
} else {
bootstrap_admin_token(&new_hash)?;
} Defensive patterns
Strategy: validation
Validate before calling
fn admin_token_exists(catalog: &Catalog) -> bool {
catalog.admin_token().is_some()
} Try / catch
match update_admin_token(hash) {
Err(CatalogError::MissingAdminTokenToUpdate) => bootstrap_admin_token(hash),
r => r,
} Prevention
- Ensure the instance is bootstrapped before token admin operations
- Verify catalog backups include the admin token row
- Restore from complete backups only
When it happens
Trigger: Calling `update_admin_token` when the catalog has no admin token defined (e.g. catalog bootstrapped without one, or the admin token entry was removed/corrupted).
Common situations: Restoring a partial catalog backup that lacks the admin token row; running update flows on a fresh instance before the admin token was provisioned; manual deletion of the admin token.
Understand the failure class
Background: "Not found" and "does not exist" errors: why "Task not found", "No such folder", and "Can't find" fire when a lookup comes back empty — this error's family across 14 libraries.
Related errors
- cannot delete operator token
- cannot parse token permission
- token hash already exists
- token name already exists
- Token error
AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19).
Data as JSON: /api/errors/b229fd121808b052.
Report an issue: GitHub.
Appendix: source
Thrown at influxdb3_catalog/src/error.rs:288
#[error("failed to parse trigger from {trigger_spec}{}", .context.as_ref().map(|context| format!(": {context}")).unwrap_or_default())]
TriggerSpecificationParseError {
trigger_spec: String,
context: Option<String>,
},
#[error("invalid error behavior {0}")]
InvalidErrorBehavior(String),
#[error("cannot parse token permission, {0}")]
CannotParsePermissionForToken(String),
#[error("token name already exists, {0}")]
TokenNameAlreadyExists(String),
#[error("token hash already exists")]
TokenHashAlreadyExists,
#[error("missing admin token, cannot update")]
MissingAdminTokenToUpdate,
#[error("cannot delete internal db")]
CannotDeleteInternalDatabase,
#[error("cannot modify internal db")]
CannotModifyInternalDatabase,
#[error("tried to stop a node ({node_id}) that is already stopped")]
NodeAlreadyStopped { node_id: Arc<str> },
#[error(
"node '{node_id}' is not fully stopped (current state: {current_state}); run \"stop node\" first"
)]
NodeNotFullyStopped {
node_id: Arc<str>,
current_state: &'static str,
},View on GitHub (pinned to 06200ef96b)