ClusterSkillSource

Group agentprimitives.authzed.com · Scope Cluster · Short names csksrc

ClusterSkillSource is a git repo that materializes cluster-scoped ClusterSkills. Auth is a direct Secret reference, because AgentIdentity is namespaced and so unavailable at cluster scope.

Cluster-scoped. Reconciled by pkg/controllers/clusterskillsource, which clones at spec.ref, discovers SKILL.md files under spec.subpath, caches each bundle by content digest, and owns the ClusterSkills it creates. It is the cluster-scoped mirror of pkg/controllers/skillsource.

Spec

FieldTypeDescription
spec.authobjectAuth references a Secret holding the clone token (e.g. a github PAT).
spec.auth.namespace *stringNamespace of the Secret (required — cluster scope has no implicit namespace).
spec.auth.secretRef *object
spec.auth.secretRef.key *stringKey is the data key within the Secret holding the value.
spec.auth.secretRef.name *stringName is the Secret's name, in the referring object's own namespace.
spec.disableRepoInstructionsbooleanDisableRepoInstructions, when true, stops this source from discovering and attaching the repo-root agent-instructions file (AGENTS.md/CLAUDE.md) to the skills it materializes. Default (false) = enabled.
spec.refstring
spec.repoURL *string
spec.subpathstring
spec.syncobjectSkillSourceSync controls the re-poll cadence.
spec.sync.intervalstringInterval between re-polls. Zero → controller default (1h).
* required

Status

Status is controller-owned (observed state).

FieldTypeDescription
status.conditions[]object
status.conditions[].lastTransitionTime *string (date-time)lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
status.conditions[].message *stringmessage is a human readable message indicating details about the transition. This may be an empty string.
status.conditions[].observedGenerationinteger (int64)observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance. (min 0)
status.conditions[].reason *stringreason contains a programmatic identifier indicating the reason for the condition's last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty.
status.conditions[].status *stringstatus of the condition, one of True, False, Unknown. (enum: True | False | Unknown)
status.conditions[].type *stringtype of condition in CamelCase or in foo.example.com/CamelCase.
status.discoveredSkillsinteger (int32)DiscoveredSkills is the number of Skills materialized on the last sync.
status.discoveryProblems[]stringDiscoveryProblems lists SKILL.md files found but skipped on the last sync (invalid frontmatter, name/dir mismatch, parse/bundle error) WITH the reason, so an operator can see why a skill did not materialize without reading operator logs. Capped (excess summarized).
status.lastSyncTimestring (date-time)
status.observedGenerationinteger (int64)ObservedGeneration is the spec generation this status reflects.
status.resolvedSHAstringResolvedSHA is the commit the last successful sync pulled.
* required