Files
root-at-skicandClaude Opus 5 a2200988b5 Add cluster-side connect operations to the ArgoCD skill
Fold the operational half of ArgoCD work into this skill, which until now
covered only authoring the Copier-templated repo. The two never overlapped:
authoring edits files in git, connecting applies objects to a cluster.

- Add references/connecting-a-repo.md: host-key trust, repository Secret
  registration with its project-scoping decision table, bootstrap apply
  ordering, SSO RBAC, prerequisites, and verification commands.
- Add references/connect-env-vars.md: layered .env loading, variable table,
  CLI flags, and SSH deploy-key rules.
- Add SKILL.md section 11 plus scope-routing rows, and state the split:
  sections 1-10 author, section 11 operates.
- Map the numbered cluster/0000-bootstrap layout onto the cluster/argocd
  layout, since the connect scripts reference those folder names directly.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-12 22:45:21 +03:00

3.2 KiB

Connect — Environment Variables and Flags

Configuration consumed by the .scripts/argo-cd/ connect operations (references/connecting-a-repo.md). These are tooling inputs: they configure the machine running the connect, and must never reach the deployed cluster/** manifests.


1. Layered loading

The base module loads three files in order, each overriding the previous:

.env  ->  .env-<environment>  ->  .env-<environment>-credentials
  • .env holds only the environment selector.
  • Connection configuration lives in the environment layer (.env-test).
  • With SSH auth there is no inline secret — the private key is a file referenced by path, so the credentials layer stays empty unless a future component needs it.
  • Every layer has a tracked sample: .sample.env, .sample.env-<env>, .sample.env-<env>-credentials. Adding a variable without adding it to the sample is how the next operator gets a missing-variable failure on a fresh clone.

Variable names narrow scope left to right: <PREFIX> -> <domain> -> <sub> -> <leaf>. The gondor family uses the HL_V1_ prefix; the names below are shown with it.

2. Variables

Variable Layer Required Purpose
HL_V1_ENVIRONMENT .env yes Selects which .env-<env> files load (e.g. test).
HL_V1_KUBE_CONFIG_PATH .env-<env> yes Path to the kubeconfig file. Supports ${HOME}.
HL_V1_KUBE_CONFIG_CONTEXT .env-<env> yes Context inside that kubeconfig to target.
HL_V1_ARGOCD_NAMESPACE .env-<env> yes Namespace ArgoCD runs in (e.g. argocd).
HL_V1_ARGOCD_TARGET_DIR .env-<env> yes Local path to the rendered repo holding the bootstrap manifests.
HL_V1_ARGOCD_GIT_REPO_URL .env-<env> yes Repo ArgoCD pulls from — SSH form git@host:owner/repo.git.
HL_V1_ARGOCD_PROJECT .env-<env> no AppProject name → project-scoped repo. Empty = global.
HL_V1_ARGOCD_REPOSITORY_SECRET .env-<env> when a Secret is created Name of the ArgoCD repository Secret.
HL_V1_ARGOCD_GIT_REPO_SSH_KEY_PATH .env-<env> private repo Path to the private SSH key. Empty = public repo.
HL_V1_ARGOCD_RBAC_DEFAULT_POLICY .env-<env> no policy.default for argocd-rbac-cm. Defaults to role:readonly.

The five required variables are checked up front, so a missing one fails before any cluster call rather than halfway through onboarding.

3. CLI flags

Parsed in lib/--env-vars-reader.sh; each overrides the corresponding environment value for a single run:

--kubeconfig      --kube-context      --namespace       --target-dir
--repo-url        --repo-ssh-key-path --repo-secret-name

Flags reach the script after --:

task argo-cd:0100-connect-one -- --repo-url="git@host:owner/repo.git"

4. SSH auth

The repo URL must be SSH form, and the public half of the key at HL_V1_ARGOCD_GIT_REPO_SSH_KEY_PATH must be registered as a read-only deploy key on the repository. The host key must also be trusted first — see references/connecting-a-repo.md §2.

Never commit the private key. It stays a local file referenced by path; only the path travels in configuration.