argocd-login
ArgoCD CLI auth with SSO and gRPC-Web. Use when the user mentions ArgoCD login, argocd authentication, SSO auth, or accessing ArgoCD applications and clusters.
Works with
--- name: argocd-login description: ArgoCD CLI auth with SSO and gRPC-Web. Use when the user mentions ArgoCD login, argocd authentication, SSO auth, or accessing ArgoCD applications and clusters. license: MIT --- # ArgoCD CLI Login ArgoCD CLI authentication with SSO for the Data Portal cluster. ## When to Use This Skill | Use this skill when... | Use kubernetes-operations instead when... | |---|---| | Authenticating to ArgoCD CLI via SSO | Working directly with kubectl against the cluster | | Resolving ArgoCD CLI auth errors before running argocd commands | Inspecting Kubernetes workloads without going through ArgoCD | | Setting up gRPC-Web access to argocd.dataportal.fi | Using kubectl-debugging to debug a specific pod or node | ## When to Use Use this skill automatically when: - User requests ArgoCD login or authentication - User mentions accessing ArgoCD cluster or applications - User needs to interact with ArgoCD CLI tools - Authentication errors occur when using ArgoCD commands ## Authentication Command ```bash argocd login argocd.dataportal.fi --grpc-web --sso ``` ### Command Breakdown - `argocd.dataportal.fi` - Data Portal ArgoCD server endpoint - `--grpc-web` - Enable gRPC-Web protocol (required for web-based SSO) - `--sso` - Use Single Sign-On authentication (opens browser for OAuth2 flow) ## Usage Flow 1. **Detect authentication need:** - User explicitly requests login - ArgoCD command fails with authentication error - User mentions accessing ArgoCD cluster 2. **Execute login command:** ```bash argocd login argocd.dataportal.fi --grpc-web --sso ``` 3. **Guide user through SSO:** - Command will open browser automatically - User completes SSO authentication in browser - CLI receives token upon successful authentication - Session is stored in `~/.config/argocd/config` 4. **Verify authentication:** ```bash argocd account get-user-info ``` ## Common ArgoCD Operations (Post-Login) ### Application Management ```bash # List applications argocd app list # Get application details argocd app get <app-name> # Sync application argocd app sync <app-name> # View application resources argocd app resources <app-name> ``` ### Cluster Information ```bash # List clusters argocd cluster list # Get cluster info argocd cluster get <cluster-name> ``` ### Project Management ```bash # List projects argocd proj list # Get project details argocd proj get <project-name> ``` ## Authentication Session - **Session storage:** `~/.config/argocd/config` - **Session persistence:** Tokens have configurable expiration - **Re-authentication:** Run login command again when session expires ## Troubleshooting ### Browser doesn't open - Manually open the URL printed by the CLI - Complete authentication in browser - Token will be received by CLI ### gRPC-Web errors - Ensure `--grpc-web` flag is present - Check network connectivity to `argocd.dataportal.fi` - Verify firewall/proxy settings allow gRPC-Web traffic ### SSO failures - Verify SSO provider is accessible - Check browser for authentication prompts - Ensure popup blockers aren't interfering - Try incognito/private browsing mode ### Token expiration - Re-run login command: `argocd login argocd.dataportal.fi --grpc-web --sso` - Check token validity: `argocd account get-user-info` ## Integration with ArgoCD MCP This skill complements the ArgoCD MCP server tools: - MCP tools (`mcp__argocd-mcp__*`) require authenticated CLI session - Use this skill to establish authentication before MCP operations - Both use same configuration (`~/.config/argocd/config`) ## Security Considerations - **Token storage:** CLI tokens stored locally in config file - **Token scope:** Full ArgoCD access (read/write based on RBAC) - **Token rotation:** Re-authenticate periodically for security - **Shared sessions:** CLI and MCP share authentication state ## Example Interaction ``` User: "I need to check the status of my ArgoCD applications" Claude: I'll log you into ArgoCD first, then check the application status. [Executes: argocd login argocd.dataportal.fi --grpc-web --sso] Please complete the SSO authentication in the browser that just opened. Once authenticated, I'll retrieve your application list. [After successful auth, executes: argocd app list] Here are your applications: ... ``` ## Related Skills - **Kubernetes Operations** - For kubectl operations on ArgoCD-managed resources - **GitHub Actions Inspection** - For CI/CD pipeline integration with ArgoCD - **Infrastructure Terraform** - For infrastructure managed by ArgoCD applications ## References - [ArgoCD CLI Documentation](https://argo-cd.readthedocs.io/en/stable/user-guide/commands/argocd/) - [ArgoCD SSO Configuration](https://argo-cd.readthedocs.io/en/stable/operator-manual/user-management/#sso) - [gRPC-Web Protocol](https://github.com/grpc/grpc-web)
More API Design skills
lark-event
larksuite/cli
Lark/Feishu real-time event listening / subscribing / consuming: stream events as NDJSON via `lark-cli event consume <EventKey>` (covers IM messages/reactions/chat changes, Approval status changes, Task updates, VC meeting started/joined/ended, Minutes generated, Whiteboard updated, etc.). Use for Lark bots, real-time message processing, long-running subscribers, streaming webhook/push handlers. Supports `--max-events` / `--timeout` bounded runs and a stderr ready-marker contract — designed for AI agents running as subprocesses.
lark-contact
larksuite/cli
飞书 / Lark 通讯录:按姓名 / 邮箱解析成 open_id,或按 open_id 反查姓名 / 部门 / 邮箱 / 联系方式 / 个人状态 / 签名,以及按关键词搜索当前用户可见的机器人 / 智能体(agent)。当用户提到一个名字要下一步发消息 / 排日程,或拿到 open_id 想查具体信息时使用。不负责部门树遍历、按部门列员工、组织架构图,这类需求走原生 OpenAPI。
lark-openapi-explorer
larksuite/cli
飞书/Lark 原生 OpenAPI 探索:从官方文档库中挖掘未经 CLI 封装的原生 OpenAPI 接口。当用户的需求无法被现有 lark-* skill 或 lark-cli 已注册命令满足,需要查找并调用原生飞书 OpenAPI 时使用。

