Agent skill

Argocd Externalsecret Namespace Permission

by divinevideo in divinevideo/divine-mobile

Fix ArgoCD ExternalSecret deployment failing with "namespace X is not permitted in project Y".

MPL-2.0Auto-check passedDevOps & Cloud

Install Argocd Externalsecret Namespace Permission

skills CLI
$ npx skills add divinevideo/divine-mobile --skill argocd-externalsecret-namespace-permission -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install divinevideo/divine-mobile argocd-externalsecret-namespace-permission --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/divinevideo/divine-mobile.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/argocd-externalsecret-namespace-permission .claude/skills/argocd-externalsecret-namespace-permission && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
argocd-externalsecret-namespace-permission
GitHub stars
266
Token cost
~931 tokens
SKILL.md length
274 words
Files
1
Skills in repo
103
Repo updated
First seen
Licence
MPL-2.0

At a glance

Fix ArgoCD ExternalSecret deployment failing with "namespace X is not permitted in project Y".

  • Works in 4 steps: Create ExternalSecret in the application → Add to application kustomization → Add environment-specific patches in… → …
  • ExternalSecret shows OutOfSync in ArgoCD but wont sync
  • SKILL.md covers Problem, Context / Trigger Conditions, Root Cause and Solution, plus 3 more sections
  • Calls kubectl and argocd

What it does

Argocd Externalsecret Namespace Permission is an agent skill from divinevideo/divine-mobile. Fix ArgoCD ExternalSecret deployment failing with "namespace X is not permitted in project Y". Use when: (1) ExternalSecret shows OutOfSync in ArgoCD but won't sync, (2) ArgoCD application status shows "namespace X is not permitted in project 'infrastructure'", (3) ExternalSecret targets a namespace managed by a different ArgoCD project, (4) Using apps-of-apps pattern with separate infrastructure and application projects.

Its SKILL.md is about 930 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Container orchestration. It works with Argo CD and Kubernetes. The licence is MPL-2.0.

When your agent uses it

  • ExternalSecret shows OutOfSync in ArgoCD but wont sync
  • ArgoCD application status shows namespace X is not permitted in project infrastructure
  • ExternalSecret targets a namespace managed by a different ArgoCD project
  • Using apps-of-apps pattern with separate infrastructure and application projects

Example prompts

  • “namespace X is not permitted in project Y”
  • “t sync, (2) ArgoCD application status shows”
  • “infrastructure”
  • “/argocd-externalsecret-namespace-permission”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Create ExternalSecret in the application
  2. Add to application kustomization
  3. Add environment-specific patches in overlays
  4. Remove from external-secrets-resources

What it can do on your machine

Read from SKILL.md and the folder at commit a1a9a8a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • kubectl
    • argocd

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use kubectl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Argocd Externalsecret Namespace Permission loads about 931 tokens when it runs. Until then it costs about 117 tokens; SKILL.md has 274 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~117
When it runs · the whole SKILL.md, loaded when a task matches
~931

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from divinevideo/divine-mobile at commit a1a9a8a, republished under its MPL-2.0 licence (© divinevideo). 274 words, ~931 tokens.

Download SKILL.mdSave it as .claude/skills/argocd-externalsecret-namespace-permission/SKILL.md (or your agent's skills folder).
name
argocd-externalsecret-namespace-permission
description
Fix ArgoCD ExternalSecret deployment failing with "namespace X is not permitted in project Y". Use when: (1) ExternalSecret shows OutOfSync in ArgoCD but won't sync, (2) ArgoCD application status shows "namespace X is not permitted in project 'infrastructure'", (3) ExternalSecret targets a namespace managed by a different ArgoCD project, (4) Using apps-of-apps pattern with separate infrastructure and application projects.
author
Claude Code
version
1.0.0
date
2026-01-29

ArgoCD ExternalSecret Namespace Permission Error

Problem

ExternalSecrets defined in a shared "external-secrets-resources" ApplicationSet fail to deploy to namespaces that aren't in the ArgoCD project's allowed destinations. The sync shows OutOfSync but refuses to apply.

Context / Trigger Conditions

  • ArgoCD application shows OutOfSync status but doesn't sync
  • Checking application resources shows:
    message: namespace gorse is not permitted in project 'infrastructure'
  • ExternalSecret is in a shared ApplicationSet (e.g., external-secrets-resources)
  • Target namespace belongs to a different application (e.g., gorse app in default project)
  • Using apps-of-apps pattern with project-based isolation

Root Cause

ArgoCD projects define allowed destination namespaces. When ExternalSecrets are deployed via a centralized "infrastructure" project but target namespaces managed by application-specific projects, the infrastructure project doesn't have permission to deploy to those namespaces.

Solution

Move the ExternalSecret from the shared external-secrets-resources to the application itself.

Step 1: Create ExternalSecret in the application
yaml
# k8s/applications/gorse/base/external-secret.yaml
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
  name: gorse-secrets
  namespace: gorse
spec:
  refreshInterval: 1h
  secretStoreRef:
    name: gcp-secret-manager
    kind: ClusterSecretStore
  target:
    name: gorse-secrets
    creationPolicy: Owner
  data:
    - secretKey: api_key
      remoteRef:
        key: gorse-api-key-ENVIRONMENT
Step 2: Add to application kustomization
yaml
# k8s/applications/gorse/base/kustomization.yaml
resources:
  - namespace.yaml
  - external-secret.yaml  # Add here
  - deployment.yaml
Step 3: Add environment-specific patches in overlays
yaml
# k8s/applications/gorse/overlays/staging/kustomization.yaml
patches:
  - target:
      kind: ExternalSecret
      name: gorse-secrets
    patch: |-
      - op: replace
        path: /spec/data/0/remoteRef/key
        value: gorse-api-key-staging
Step 4: Remove from external-secrets-resources

Remove the ExternalSecret from k8s/external-secrets/base/ and all overlay patches.

Verification

  1. Sync the application: argocd app sync gorse
  2. Check ExternalSecret status: kubectl get externalsecrets -n gorse
  3. Verify secret created: kubectl get secrets -n gorse

Alternative Solutions

Option 1: Expand project destinations

Add the namespace to the infrastructure project's allowed destinations in ArgoCD. Not recommended as it breaks project isolation.

Option 2: Use ClusterSecretStore

If using ClusterSecretStore, the secret can be referenced from any namespace. The ExternalSecret itself still needs to be in an allowed namespace.

Notes

  • This pattern is common when migrating from monolithic to modular ArgoCD setups
  • Each application should own its secret definitions for better isolation
  • ClusterSecretStore remains shared; only ExternalSecret moves
  • The "infrastructure" project typically manages cluster-wide resources, not app-specific secrets

© divinevideo, MPL-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/argocd-externalsecret-namespace-permission of divinevideo/divine-mobile.

Open the folder on GitHubat commit a1a9a8a

Compare with similar skills

Argocd Externalsecret Namespace Permission next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Argocd Externalsecret Namespace Permission compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Argocd Externalsecret Namespace Permission this skilldivinevideo/divine-mobile266—~931Automated safety check: PassMPL-2.0
Kubernetes SpecialistJeffallan/claude-skills12k1 repos~2.1kAutomated safety check: PassMIT
Kubernetes ArchitectCybereason-Public/owLSM2809 repos~2.6kAutomated safety check: PassGPL-2.0
GitOps with ArgoCD and Fluxwshobson/agents40k12 repos~1.5kAutomated safety check: PassMIT
Signozqjoly/GitOps112—~6.1kAutomated safety check: PassWTFPL
Ksaildevantler-tech/ksail165—~1.1kAutomated safety check: PassCustom licence

Similar skills

  • Kubernetes Specialist

    Jeffallan/claude-skills

    Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    DevOps & CloudAuto-check passed
  • Kubernetes Architect

    Cybereason-Public/owLSM

    Expert Kubernetes architect specializing in cloud-native infrastructure, advanced GitOps workflows (ArgoCD/Flux), and enterprise container orchestration.

    280 GitHub starsUsed in 9 repos~2.6k tokens
    DevOps & CloudAuto-check passed
  • Sets up GitOps continuous delivery for Kubernetes with ArgoCD or Flux, covering installation, repository layout, sync policies, progressive delivery and secrets.

    40k GitHub starsUsed in 12 repos~1.5k tokens
    DevOps & CloudAuto-check passed
  • Signoz

    qjoly/GitOps

    Manage the self-hosted SigNoz observability stack in this GitOps repo.

    112 GitHub stars~6.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Ksail

    devantler-tech/ksail

    Use the ksail CLI to spin up and manage Kubernetes clusters (Kind/K3d/Talos/vCluster/KWOK — local via Docker; EKS — cloud via AWS) and GitOps workloads declaratively.

    165 GitHub stars~1.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Release Cut And Demo Roll

    carverauto/serviceradar

    Cut a ServiceRadar release and roll the Kubernetes demo namespace to the resulting published semver image tag through the guarded ArgoCD release branch.

    921 GitHub stars~3.9k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from divinevideo/divine-mobile

All 103 skills in this repo
  • Art Direct

    divinevideo/divine-mobile

    Art direction for any content — reads text, PDF, Word, HTML, PPT, then proposes 2-3 creative directions with photography style, mood, and visual language.

    266 GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Async Await Null Race Condition

    divinevideo/divine-mobile

    Fix "Null check operator used on a null value" errors when an object is set to null during an async await.

    266 GitHub stars~881 tokensUpdated today
    Auto-check passed
  • AWS V4 Signing Custom Headers Gcs

    divinevideo/divine-mobile

    Add custom metadata headers (x-amz-meta-) to AWS v4 signed requests for GCS S3-compatible API.

    266 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Bash Herestring Newline Secrets

    divinevideo/divine-mobile

    Fix password/secret authentication failures caused by trailing newlines when creating Google Cloud secrets (or similar) with bash here-strings.

    266 GitHub stars~791 tokensUpdated today
    Auto-check passed
  • Fix silent video/media processing failures caused by URL extraction code that filters on file extensions (.mp4, .webm, .webp).

    266 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Certmanager Dns01 Gke Private Cluster

    divinevideo/divine-mobile

    Fix cert-manager DNS01 ACME challenges stuck in "pending" state with "DNS record not yet propagated" inside GKE private clusters, even when TXT records exist in Cloudflare DNS.

    266 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Argocd Externalsecret Namespace Permission

What does Argocd Externalsecret Namespace Permission do?

Fix ArgoCD ExternalSecret deployment failing with "namespace X is not permitted in project Y". Argocd Externalsecret Namespace Permission is an agent skill from divinevideo/divine-mobile. Fix ArgoCD ExternalSecret deployment failing with "namespace X is not permitted in project Y".

When should I use Argocd Externalsecret Namespace Permission?

Argocd Externalsecret Namespace Permission fits situations like: externalSecret shows OutOfSync in ArgoCD but wont sync; argoCD application status shows namespace X is not permitted in project infrastructure; externalSecret targets a namespace managed by a different ArgoCD project; using apps-of-apps pattern with separate infrastructure and application projects.

How do I install Argocd Externalsecret Namespace Permission in Claude Code?

Run `npx skills add divinevideo/divine-mobile --skill argocd-externalsecret-namespace-permission -a claude-code`. Or copy the skill folder (.agents/skills/argocd-externalsecret-namespace-permission in divinevideo/divine-mobile) into .claude/skills/argocd-externalsecret-namespace-permission in your project. Claude Code loads it when a task matches its description.

How do I install Argocd Externalsecret Namespace Permission in Codex?

Run `npx skills add divinevideo/divine-mobile --skill argocd-externalsecret-namespace-permission -a codex`. Or copy the skill folder (.agents/skills/argocd-externalsecret-namespace-permission in divinevideo/divine-mobile) into .agents/skills/argocd-externalsecret-namespace-permission in your project. Codex loads it when a task matches its description.

Can I use Argocd Externalsecret Namespace Permission in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add divinevideo/divine-mobile --skill argocd-externalsecret-namespace-permission -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/argocd-externalsecret-namespace-permission, .gemini/skills/argocd-externalsecret-namespace-permission, .github/skills/argocd-externalsecret-namespace-permission and .opencode/skills/argocd-externalsecret-namespace-permission in your project.

What does Argocd Externalsecret Namespace Permission need to run?

Going by SKILL.md and its folder, Argocd Externalsecret Namespace Permission needs the command-line tools its instructions call (kubectl and argocd).

Does Argocd Externalsecret Namespace Permission access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Argocd Externalsecret Namespace Permission safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Argocd Externalsecret Namespace Permission use?

Argocd Externalsecret Namespace Permission is published under the MPL-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Argocd Externalsecret Namespace Permission use?

About 931 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Argocd Externalsecret Namespace Permission?

Skills that share tags, products or a category with Argocd Externalsecret Namespace Permission: Kubernetes Specialist (Jeffallan/claude-skills, 12k stars), Kubernetes Architect (Cybereason-Public/owLSM, 280 stars), GitOps with ArgoCD and Flux (wshobson/agents, 40k stars) and Signoz (qjoly/GitOps, 112 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Argocd Externalsecret Namespace Permission?

divinevideo (a GitHub organization) maintains it in divinevideo/divine-mobile, which has 266 GitHub stars. The repository holds 103 skills in this directory. The repository was last updated on October 11, 2026.

Source: divinevideo/divine-mobile on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.