Исправление ошибки доступа к namespace в ArgoCD ExternalSecret
devops
argocd-externalsecret-namespace-permission is a Claude Code skill that fixes the "namespace X is not permitted in project Y" error when deploying ExternalSecrets through ArgoCD. The issue occurs when an ExternalSecret is defined in a shared infrastructure ApplicationSet but targets a namespace owned by a different ArgoCD project, leaving the application stuck in OutOfSync status. The skill explains the root cause — mismatched project destination permissions — and provides a step-by-step resolution: move the ExternalSecret into the application's own directory (e.g., gorse), register it in kustomization.yaml, and apply environment-specific patches via overlays. Verification commands (`argocd app sync`, `kubectl get externalsecrets`, `kubectl get secrets`) and two alternatives — expanding project destinations or relying on ClusterSecretStore — are also covered. Aimed at platform and DevOps engineers working with apps-of-apps patterns and secrets management in Kubernetes.
- #argocd
- #externalsecret
- #kubernetes
- #namespace-permission
- #secrets-management