gitops-tenant-onboarding skillA
gitops-tenant-onboarding is agent-read markdown (skill) from devantler-tech/agent-skills: Onboard a new tenant application onto a Flux-based GitOps platform: scaffold the tenant repo's deploy manifests, wire OpenBao/Vault secrets via External Secrets, fit the cluster's Kyverno/PodSecurity and default-deny network policies, expose the app through a shared Gateway API gateway, and register the tenant on the platform with signed-OCI Flux resources. Use when adding a new app/tenant to a multi-tenant Flux cluster, writing a tenant's deploy/ manifests, debugging why a tenant is unreachable.
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# GitOps Tenant Onboarding Onboarding a **tenant** — an application that runs on a shared, multi-tenant [Flux](https://fluxcd.io/) cluster from its **own repository** — follows the same recurring shape every time. The tenant repo builds a container image and publishes its Kubernetes manifests as a **signed OCI artifact**; the platform pulls that artifact with a Flux `OCIRepository` + `Kustomization` and runs it in a dedicated, locked-down namespace. This skill is the agent-facing companion to that pattern: the decisions, the conventions, and — most usefully — the **gotchas that make a fresh tenant fail** if you miss them. It is built around an opinionated but industry-standard stack — Flux, [External Secrets Operator](https://external-secrets.io/) backed by OpenBao/Vault, [Kyverno](https://kyverno.io/) + PodSecurity, Cilium / [Gateway API](https://gateway-api.sigs.k8s.io/), [cosign](https://www.sigstore.dev/) — so the steps transfer to any cluster wired the same way; adapt the resource names to your platform. ## The two halves Onboarding always spans **two repos**, and a tenant is not live until both land: …
Read the whole file at its exact version.
How to install
mdr add devantler-tech/agent-skills/gitops-tenant-onboarding@git:20260615.7099ba9mdr add devantler-tech/agent-skills/gitops-tenant-onboarding@sha256:2d6b9d6d2f04382ePin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_73rw77isq2x2ey2y)
0 badge views in 30 days
Versions
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (10939 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
devantler-tech/agent-skills · 3 stars · license Apache-2.0 · pushed 2026-09-24 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_73rw77isq2x2ey2y GET https://markdownregistry.com/api/v1/resolve?ref=devantler-tech/agent-skills/gitops-tenant-onboarding GET https://markdownregistry.com/api/v1/blob/2d6b9d6d2f04382e645d85c18365de05c51d331fcf2bb134f739a3936f7c806e
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.