argocd-login
ArgoCD CLI auth with SSO and gRPC-Web. Use when the user mentions ArgoCD login, argocd authentication, SSO auth, or accessing ArgoCD applications and clusters.
What this skill does
# ArgoCD CLI Login ArgoCD CLI authentication with SSO for the Data Portal cluster. ## When to Use This Skill | Use this skill when... | Use kubernetes-operations instead when... | |---|---| | Authenticating to ArgoCD CLI via SSO | Working directly with kubectl against the cluster | | Resolving ArgoCD CLI auth errors before running argocd commands | Inspecting Kubernetes workloads without going through ArgoCD | | Setting up gRPC-Web access to argocd.dataportal.fi | Using kubectl-debugging to debug a specific pod or node | ## When to Use Use this skill automatically when: - User requests ArgoCD login or authentication - User mentions accessing ArgoCD cluster or applications - User needs to interact with ArgoCD CLI tools - Authentication errors occur when using ArgoCD commands ## Authentication Command ```bash argocd login argocd.dataportal.fi --grpc-web --sso ``` ### Command Breakdown - `argocd.dataportal.fi` - Data Portal ArgoCD server endpoint - `--grpc-web` - Enable gRPC-Web protocol (required for web-based SSO) - `--sso` - Use Single Sign-On authentication (opens browser for OAuth2 flow) ## Usage Flow 1. **Detect authentication need:** - User explicitly requests login - ArgoCD command fails with authentication error - User mentions accessing ArgoCD cluster 2. **Execute login command:** ```bash argocd login argocd.dataportal.fi --grpc-web --sso ``` 3. **Guide user through SSO:** - Command will open browser automatically - User completes SSO authentication in browser - CLI receives token upon successful authentication - Session is stored in `~/.config/argocd/config` 4. **Verify authentication:** ```bash argocd account get-user-info ``` ## Common ArgoCD Operations (Post-Login) ### Application Management ```bash # List applications argocd app list # Get application details argocd app get <app-name> # Sync application argocd app sync <app-name> # View application resources argocd app resources <app-name> ``` ### Cluster Information ```bash # List clusters argocd cluster list # Get cluster info argocd cluster get <cluster-name> ``` ### Project Management ```bash # List projects argocd proj list # Get project details argocd proj get <project-name> ``` ## Authentication Session - **Session storage:** `~/.config/argocd/config` - **Session persistence:** Tokens have configurable expiration - **Re-authentication:** Run login command again when session expires ## Troubleshooting ### Browser doesn't open - Manually open the URL printed by the CLI - Complete authentication in browser - Token will be received by CLI ### gRPC-Web errors - Ensure `--grpc-web` flag is present - Check network connectivity to `argocd.dataportal.fi` - Verify firewall/proxy settings allow gRPC-Web traffic ### SSO failures - Verify SSO provider is accessible - Check browser for authentication prompts - Ensure popup blockers aren't interfering - Try incognito/private browsing mode ### Token expiration - Re-run login command: `argocd login argocd.dataportal.fi --grpc-web --sso` - Check token validity: `argocd account get-user-info` ## Integration with ArgoCD MCP This skill complements the ArgoCD MCP server tools: - MCP tools (`mcp__argocd-mcp__*`) require authenticated CLI session - Use this skill to establish authentication before MCP operations - Both use same configuration (`~/.config/argocd/config`) ## Security Considerations - **Token storage:** CLI tokens stored locally in config file - **Token scope:** Full ArgoCD access (read/write based on RBAC) - **Token rotation:** Re-authenticate periodically for security - **Shared sessions:** CLI and MCP share authentication state ## Example Interaction ``` User: "I need to check the status of my ArgoCD applications" Claude: I'll log you into ArgoCD first, then check the application status. [Executes: argocd login argocd.dataportal.fi --grpc-web --sso] Please complete the SSO authentication in the browser that just opened. Once authenticated, I'll retrieve your application list. [After successful auth, executes: argocd app list] Here are your applications: ... ``` ## Related Skills - **Kubernetes Operations** - For kubectl operations on ArgoCD-managed resources - **GitHub Actions Inspection** - For CI/CD pipeline integration with ArgoCD - **Infrastructure Terraform** - For infrastructure managed by ArgoCD applications ## References - [ArgoCD CLI Documentation](https://argo-cd.readthedocs.io/en/stable/user-guide/commands/argocd/) - [ArgoCD SSO Configuration](https://argo-cd.readthedocs.io/en/stable/operator-manual/user-management/#sso) - [gRPC-Web Protocol](https://github.com/grpc/grpc-web)
Related in General
modeling-omnistudio-epc-catalog
IncludedSalesforce Industries CME EPC product-modeling skill for Product2-based catalog creation. Use when creating EPC products, configuring product attributes, building offer bundles with Product Child Items, or reviewing EPC DataPack JSON metadata for product catalog changes. TRIGGER when: user creates or updates Product2 EPC records, AttributeAssignment payloads, AttributeMetadata/AttributeDefaultValues, Offer bundles, or ProductChildItem relationships. DO NOT TRIGGER when: designing OmniScripts/FlexCards/Integration Procedures (use building-omnistudio-omniscript, building-omnistudio-flexcard, or building-omnistudio-integration-procedure), implementing Apex business logic (use generating-apex), or troubleshooting deployment pipelines (use deploying-metadata).
relationship-science-coach
IncludedUse this skill for direct, practical adult relationship coaching: couples conflict, repair, trust, marriage, dating, flirting, attachment patterns, emotional connection, sex, desire differences, eroticism, kink negotiation, affection, love languages, breakups, and long-term passion. Draw on Gottman, EFT and Hold Me Tight, attachment science, modern sex research, Perel, Nagoski, Kerner, Schnarch, Love and Stosny, and flexible love-language tools. Be concrete and low-hedge. Redirect only for imminent danger, abuse, coercive control, minors, non-consent, self-harm, stalking, or medical/legal/psychiatric decisions.
building-sf-integrations
IncludedSalesforce integration architecture and runtime plumbing with 120-point scoring. Use this skill to set up Named Credentials, External Credentials, External Services, REST/SOAP callout patterns, Platform Events, and Change Data Capture. TRIGGER when: user sets up Named Credentials, External Services, REST/SOAP callouts, Platform Events, CDC, or touches .namedCredential-meta.xml files. DO NOT TRIGGER when: Connected App/OAuth config (use configuring-connected-apps), Apex-only logic (use generating-apex), or data import/export (use handling-sf-data).
venue-templates
IncludedAccess comprehensive LaTeX templates, formatting requirements, and submission guidelines for major scientific publication venues (Nature, Science, PLOS, IEEE, ACM), academic conferences (NeurIPS, ICML, CVPR, CHI), research posters, and grant proposals (NSF, NIH, DOE, DARPA). This skill should be used when preparing manuscripts for journal submission, conference papers, research posters, or grant proposals and need venue-specific formatting requirements and templates.
let-fate-decide
IncludedDraws the 12 Houses of the Zodiac Tarot spread to inject entropy into planning when prompts are vague, ambiguous, or casually delegated. Interprets the spread to guide next steps. Use when the user says 'let fate decide', 'YOLO', 'whatever', 'idk', or other nonchalant phrases, makes Yu-Gi-Oh references, or when you are about to arbitrarily pick between multiple reasonable approaches. Prefer over ask-questions-if-underspecified when the user's tone is casual or playful rather than precision-seeking.
net-ops
IncludedCross-platform network troubleshooting (Windows, macOS, Linux) via local or remote shell. Use for: DNS broken, can't resolve hostnames, nslookup/dig works but apps fail, NRPT, WFP, scutil, /etc/resolver, systemd-resolved, /etc/resolv.conf, NetworkManager, VPN DNS leak residue (ProtonVPN/Mullvad/WireGuard/AnyConnect), AV/firewall blocking DNS or DoH, Tailscale DNS interaction, intermittent connectivity, remote diagnostics over SSH.