Skip to content

invalid bearer token, service account token has been invalidated #124204

@tutorguai

Description

@tutorguai

What happened?

My K8s cluster kube apiserver has a large number of invalid bearer tokens, and the service account token has been invalidated
Phenomenon:

  1. All are concentrated on one kube apiserver node
  2. I did not find any functional damage in the cluster, including related business Pods
    image

What did you expect to happen?

How do I know where this part of the request comes from and how do I handle it

How can we reproduce it (as minimally and precisely as possible)?

no

Anything else we need to know?

No response

Kubernetes version

Details
$ kubectl version
# paste output here

Server Version: version.Info{Major:"1", Minor:"25", GitVersion:"v1.25.6", GitCommit:"ff2c119726cc1f8926fb0585c74b25921e866a28", GitTreeState:"clean", BuildDate:"2023-01-18T19:15:26Z", GoVersion:"go1.19.5", Compiler:"gc", Platform:"linux/amd64"}

Cloud provider

Details

OS version

Details
# On Linux:
$ cat /etc/os-release
# paste output here
$ uname -a
# paste output here

# On Windows:
C:\> wmic os get Caption, Version, BuildNumber, OSArchitecture
# paste output here

Linux 5.4.86-1.el7.elrepo.x86_64 #1 SMP Tue Dec 29 10:39:46 EST 2020 x86_64 x86_64 x86_64 GNU/Linux

Install tools

Details kubeasz

Container runtime (CRI) and version (if applicable)

Details containerd github.com/containerd/containerd v1.6.19

Related plugins (CNI, CSI, ...) and versions (if applicable)

Details

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind/bugCategorizes issue or PR as related to a bug.kind/supportCategorizes issue or PR as a support question.needs-triageIndicates an issue or PR lacks a `triage/foo` label and requires one.sig/authCategorizes an issue or PR as relevant to SIG Auth.

    Type

    No type

    Projects

    Status

    Closed / Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions