ClusterSkillSource
Group agentprimitives.authzed.com · Scope Cluster · Short names csksrc
ClusterSkillSource is a git repo that materializes cluster-scoped ClusterSkills. Auth is a direct Secret reference, because AgentIdentity is namespaced and so unavailable at cluster scope.
Cluster-scoped. Reconciled by pkg/controllers/clusterskillsource, which clones at spec.ref, discovers SKILL.md files under spec.subpath, caches each bundle by content digest, and owns the ClusterSkills it creates. It is the cluster-scoped mirror of pkg/controllers/skillsource.
Spec
| Field | Type | Description |
|---|---|---|
spec.auth | object | Auth references a Secret holding the clone token (e.g. a github PAT). |
spec.auth.namespace * | string | Namespace of the Secret (required — cluster scope has no implicit namespace). |
spec.auth.secretRef * | object | |
spec.auth.secretRef.key * | string | Key is the data key within the Secret holding the value. |
spec.auth.secretRef.name * | string | Name is the Secret's name, in the referring object's own namespace. |
spec.disableRepoInstructions | boolean | DisableRepoInstructions, when true, stops this source from discovering and attaching the repo-root agent-instructions file (AGENTS.md/CLAUDE.md) to the skills it materializes. Default (false) = enabled. |
spec.ref | string | |
spec.repoURL * | string | |
spec.subpath | string | |
spec.sync | object | SkillSourceSync controls the re-poll cadence. |
spec.sync.interval | string | Interval between re-polls. Zero → controller default (1h). |
Status
Status is controller-owned (observed state).
| Field | Type | Description |
|---|---|---|
status.conditions | []object | |
status.conditions[].lastTransitionTime * | string (date-time) | lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. |
status.conditions[].message * | string | message is a human readable message indicating details about the transition. This may be an empty string. |
status.conditions[].observedGeneration | integer (int64) | observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance. (min 0) |
status.conditions[].reason * | string | reason contains a programmatic identifier indicating the reason for the condition's last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty. |
status.conditions[].status * | string | status of the condition, one of True, False, Unknown. (enum: True | False | Unknown) |
status.conditions[].type * | string | type of condition in CamelCase or in foo.example.com/CamelCase. |
status.discoveredSkills | integer (int32) | DiscoveredSkills is the number of Skills materialized on the last sync. |
status.discoveryProblems | []string | DiscoveryProblems lists SKILL.md files found but skipped on the last sync (invalid frontmatter, name/dir mismatch, parse/bundle error) WITH the reason, so an operator can see why a skill did not materialize without reading operator logs. Capped (excess summarized). |
status.lastSyncTime | string (date-time) | |
status.observedGeneration | integer (int64) | ObservedGeneration is the spec generation this status reflects. |
status.resolvedSHA | string | ResolvedSHA is the commit the last successful sync pulled. |