You must be logged in to the server ☸️ Kubernetes

error: You must be logged in to the server (Unauthorized)

The cluster rejected kubectl’s credentials — expired token, wrong kubeconfig user, or cloud IAM identity not allowed.

Seen on: Kubernetes

Meaning

Unlike Forbidden (known user, no permission), Unauthorized means the API server doesn’t accept who you are at all. Cloud clusters use short-lived tokens from aws/gcloud/az; expired SSO sessions, the wrong AWS profile, or an IAM role missing from EKS access cause it.

Common causes

  • Expired cloud SSO session or token
  • Wrong AWS profile/role for EKS (not in aws-auth / access entries)
  • Rotated certificates or revoked service account token
  • kubeconfig pointing at another cluster’s user

⚡ Quick fix

  1. Refresh credentials (aws sso login, gcloud auth login, az login) and regenerate kubeconfig
  2. Check which identity you use (aws sts get-caller-identity)
  3. Ensure that identity is mapped in the cluster

Detailed fix by platform

AWS

  1. bash
    aws sso login --profile prod
    aws eks update-kubeconfig --name my-cluster --profile prod
    kubectl get nodes

GCP

  1. gcloud container clusters get-credentials my-cluster --region us-central1

How to diagnose

  1. Context — kubectl config current-context
  2. Identity — Cloud caller identity
  3. Mapping — EKS access entry/aws-auth

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.