Fold the operational half of ArgoCD work into this skill, which until now covered only authoring the Copier-templated repo. The two never overlapped: authoring edits files in git, connecting applies objects to a cluster. - Add references/connecting-a-repo.md: host-key trust, repository Secret registration with its project-scoping decision table, bootstrap apply ordering, SSO RBAC, prerequisites, and verification commands. - Add references/connect-env-vars.md: layered .env loading, variable table, CLI flags, and SSH deploy-key rules. - Add SKILL.md section 11 plus scope-routing rows, and state the split: sections 1-10 author, section 11 operates. - Map the numbered cluster/0000-bootstrap layout onto the cluster/argocd layout, since the connect scripts reference those folder names directly. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
3.2 KiB
Connect — Environment Variables and Flags
Configuration consumed by the .scripts/argo-cd/ connect operations
(references/connecting-a-repo.md). These are tooling inputs: they configure the machine
running the connect, and must never reach the deployed cluster/** manifests.
1. Layered loading
The base module loads three files in order, each overriding the previous:
.env -> .env-<environment> -> .env-<environment>-credentials
.envholds only the environment selector.- Connection configuration lives in the environment layer (
.env-test). - With SSH auth there is no inline secret — the private key is a file referenced by path, so the credentials layer stays empty unless a future component needs it.
- Every layer has a tracked sample:
.sample.env,.sample.env-<env>,.sample.env-<env>-credentials. Adding a variable without adding it to the sample is how the next operator gets a missing-variable failure on a fresh clone.
Variable names narrow scope left to right: <PREFIX> -> <domain> -> <sub> -> <leaf>. The
gondor family uses the HL_V1_ prefix; the names below are shown with it.
2. Variables
| Variable | Layer | Required | Purpose |
|---|---|---|---|
HL_V1_ENVIRONMENT |
.env |
yes | Selects which .env-<env> files load (e.g. test). |
HL_V1_KUBE_CONFIG_PATH |
.env-<env> |
yes | Path to the kubeconfig file. Supports ${HOME}. |
HL_V1_KUBE_CONFIG_CONTEXT |
.env-<env> |
yes | Context inside that kubeconfig to target. |
HL_V1_ARGOCD_NAMESPACE |
.env-<env> |
yes | Namespace ArgoCD runs in (e.g. argocd). |
HL_V1_ARGOCD_TARGET_DIR |
.env-<env> |
yes | Local path to the rendered repo holding the bootstrap manifests. |
HL_V1_ARGOCD_GIT_REPO_URL |
.env-<env> |
yes | Repo ArgoCD pulls from — SSH form git@host:owner/repo.git. |
HL_V1_ARGOCD_PROJECT |
.env-<env> |
no | AppProject name → project-scoped repo. Empty = global. |
HL_V1_ARGOCD_REPOSITORY_SECRET |
.env-<env> |
when a Secret is created | Name of the ArgoCD repository Secret. |
HL_V1_ARGOCD_GIT_REPO_SSH_KEY_PATH |
.env-<env> |
private repo | Path to the private SSH key. Empty = public repo. |
HL_V1_ARGOCD_RBAC_DEFAULT_POLICY |
.env-<env> |
no | policy.default for argocd-rbac-cm. Defaults to role:readonly. |
The five required variables are checked up front, so a missing one fails before any cluster call rather than halfway through onboarding.
3. CLI flags
Parsed in lib/--env-vars-reader.sh; each overrides the corresponding environment value for
a single run:
--kubeconfig --kube-context --namespace --target-dir
--repo-url --repo-ssh-key-path --repo-secret-name
Flags reach the script after --:
task argo-cd:0100-connect-one -- --repo-url="git@host:owner/repo.git"
4. SSH auth
The repo URL must be SSH form, and the public half of the key at
HL_V1_ARGOCD_GIT_REPO_SSH_KEY_PATH must be registered as a read-only deploy key on the
repository. The host key must also be trusted first — see references/connecting-a-repo.md
§2.
Never commit the private key. It stays a local file referenced by path; only the path travels in configuration.