influxdata/influxdb · error · CatalogError

missing admin token, cannot update

Error message

missing admin token, cannot update

What it means

This error is returned when an operation tries to update an admin token but the admin token is missing from the catalog. Admin tokens are special bootstrap tokens; updating one requires it to exist, and its absence is an integrity problem. The catalog refuses the update rather than silently creating state.

Solutions

  1. Bootstrap/provision the admin token first (start the server so it initializes, or use the bootstrap flow)
  2. Verify the catalog contains the admin token before attempting updates
  3. If the catalog is corrupted, restore from a valid backup
  4. Use a normal (non-admin) token API for regular token rotation

Example fix

// before
catalog.update_admin_token(&new_hash)?; // fails if absent
// after
if catalog.admin_token().is_some() {
    catalog.update_admin_token(&new_hash)?;
} else {
    bootstrap_admin_token(&new_hash)?;
}
Defensive patterns

Strategy: validation

Validate before calling

fn admin_token_exists(catalog: &Catalog) -> bool {
    catalog.admin_token().is_some()
}

Try / catch

match update_admin_token(hash) {
    Err(CatalogError::MissingAdminTokenToUpdate) => bootstrap_admin_token(hash),
    r => r,
}

Prevention

When it happens

Trigger: Calling `update_admin_token` when the catalog has no admin token defined (e.g. catalog bootstrapped without one, or the admin token entry was removed/corrupted).

Common situations: Restoring a partial catalog backup that lacks the admin token row; running update flows on a fresh instance before the admin token was provisioned; manual deletion of the admin token.

Understand the failure class

Background: "Not found" and "does not exist" errors: why "Task not found", "No such folder", and "Can't find" fire when a lookup comes back empty — this error's family across 14 libraries.

Related errors


AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19). Data as JSON: /api/errors/b229fd121808b052. Report an issue: GitHub.

Appendix: source

Thrown at influxdb3_catalog/src/error.rs:288

    #[error("failed to parse trigger from {trigger_spec}{}", .context.as_ref().map(|context| format!(": {context}")).unwrap_or_default())]
    TriggerSpecificationParseError {
        trigger_spec: String,
        context: Option<String>,
    },

    #[error("invalid error behavior {0}")]
    InvalidErrorBehavior(String),

    #[error("cannot parse token permission, {0}")]
    CannotParsePermissionForToken(String),

    #[error("token name already exists, {0}")]
    TokenNameAlreadyExists(String),

    #[error("token hash already exists")]
    TokenHashAlreadyExists,

    #[error("missing admin token, cannot update")]
    MissingAdminTokenToUpdate,

    #[error("cannot delete internal db")]
    CannotDeleteInternalDatabase,

    #[error("cannot modify internal db")]
    CannotModifyInternalDatabase,

    #[error("tried to stop a node ({node_id}) that is already stopped")]
    NodeAlreadyStopped { node_id: Arc<str> },

    #[error(
        "node '{node_id}' is not fully stopped (current state: {current_state}); run \"stop node\" first"
    )]
    NodeNotFullyStopped {
        node_id: Arc<str>,
        current_state: &'static str,
    },

View on GitHub (pinned to 06200ef96b)